Did ransomware attacks really decline? Here are your business' 4 best defenses
Follow ZDNET: Add us as a preferred source on Google.

Follow ZDNET: Add us as a preferred source on Google.
If it looked like ransomware was on the decline last year, research from multiple cybersecurity firms sheds new light on that idea.
Previous reports suggested that ransomware extortion attempts declined in 2025 , replaced by techniques such as process injection, credential theft, and virtualization- or sandbox-evasion-based attacks. But more recent second-quarter 2026 reports suggest that vigilance against such extortion attempts remains as important as ever.
Before we dig deeper into the research data, let's review the nature of the threat.
Ransomware is a malicious software, aka malware, that can be spread across networks, computer systems, and endpoint devices. Once ransomware infiltrates your system, it can encrypt files and connected drives. Criminals behind a ransomware attack will demand payment in return for a decryption key -- which may or may not work.
Also: Why this fully agentic ransomware attack is giving researchers nightmares
In recent years, threat actors have turned to ransomware to target enterprises, often demanding millions of dollars and pressuring victims to pay to restore business operations. To further pile on the pressure, some cybercriminals will steal corporate data ahead of encryption and will threaten their victims with posting stolen information online unless payment is made.
Ransomware-as-a-Service (RaaS) has expanded the scope of these attacks, with some criminals developing and licensing ransomware tools that others use to target individuals and businesses alike.
According to NCC Group's second-quarter cyber threat intelligence report (.PDF), in Q2 2026, global ransomware attacks increased by 3% over the previous quarter. In total, NCC Group recorded 2,229 ransomware attacks, compared to 2,165 in Q1 2026, which in turn saw a 3% decrease (.PDF) from Q4 2005.
Qilin was the most active ransomware group for the 5th quarter in a row, accounting for 301 victims in Q2 2026 alone. This threat actor was followed by The Gentlemen, with 238 victims, and Dragonforce, with 145 victims. A new player also entered the ransomware cybercriminal top 10 list: RaaS service KryBi has been linked to 56 victims during Q2.
Let's compare this with Check Point data.
In Q1 2026 , Check Point researchers identified 2,122 new victims, a 12.2% decline from Q4 2025 and a 7.1% decline from 2,285 victims in Q1 2025 -- but there's more to come on this last statistic.
So, did ransomware rates really potentially drop, only to pick up again in 2026? When we consider the question, there is one major cybercriminal group we need to account for.
Source: ZDNet