Ransomware has spent the past year looking like a closed shop, with a handful of dominant operations causing most of the damage. Check Point Research's State of Ransomware report for the second quarter of 2026 says the door is opening again. The team counted 93 active groups in the quarter, up from 71 in Q1 and the highest total for the period the report tracks.
The leaders are still winning, but by less. The top 10 groups accounted for 57.6% of all victims named on data leak sites, down from 71% in the first quarter. Overall volume barely moved: 2,139 victims were listed in Q2, up 0.8% on Q1 and 33% higher than the same quarter a year earlier, keeping the elevated baseline set through 2025.
Qilin and The Gentlemen
Qilin remained the most prolific single operation for a fourth straight quarter with 279 victims, although its count fell 17%. The Gentlemen surged 62% to 269 victims and actually outpaced Qilin during the month of June, an early sign of the handover we reported at the start of August.
The most unusual material in the report comes from an internal leak inside The Gentlemen. Chat logs and platform data exposed a core team of roughly nine operators supported by a broader affiliate base, and confirmed that the group used AI coding assistants to build its ransomware management panel in about three days. Check Point describes that as genuine first party evidence of AI accelerating malicious tooling development, rather than the inference the industry has usually had to settle for.
Fewer victims are paying
The payment picture keeps deteriorating for the crews. Check Point puts the ransom payment rate near 23%, a multi year low, continuing a decline from 85% in 2019. The money has not gone away: the report puts on chain ransomware payments above $820 million in 2025. What has changed is who pays. Average payments are rising while the median falls, which the report reads as a split market, with large enterprises still paying heavily while mid market victims increasingly hold firm or settle small.
Where the pressure is being applied
Law enforcement spent the quarter going after shared infrastructure rather than individual brands. Actions took down a cryptocurrency laundering platform used by multiple ransomware actors, prompted sanctions against major Iranian digital asset exchanges, dismantled a malware signing service abused by several ransomware-as-a-service operations, and disrupted large infostealer and VPN anonymization networks that many groups depend on. Breaking a service several crews share does more damage per action than seizing one leak site.
The geography shifted too. The United States accounted for 42% of victims, down from 50% quarter over quarter, largely because the quarter's fastest growing operations, including The Gentlemen and the newly active Krybit, target US organizations far less often than the ecosystem average. Check Point also notes the exploitation window continuing to narrow, with vulnerabilities weaponized within hours to days of disclosure and AI increasingly cited as the accelerant.
The full findings are in the original report from Check Point Research.
This briefing is provided by IntelFusions for informational and defensive purposes only. It is based on sources assessed to be reliable at the time of writing, and analytic judgments carry the confidence levels indicated. Indicators of compromise are defanged; re-arm them only in controlled environments. IntelFusions is not affiliated with the organizations named and makes no warranty as to completeness or accuracy.