Ransomware crews posted 5,984 organizations to their leak sites between January and June 2026. That's 1,555 more than the same six months of 2025, a rise of roughly a third, and the South Korean threat intelligence firm S2W says a large part of it came from crews that didn't exist when the year started.
The count comes from S2W TALON researchers HuiSeong Yang and SeungHo Lee, who track the extortion sites where ransomware groups publish the names of organizations they say they've hit. Their full report is here. One caveat applies to every figure in it, and to any leak site tally anyone publishes: these are unverified claims criminals make about their own work. A name on a leak site is an accusation, not a confirmed breach.
Forty four new brands in six months
S2W counted 119 groups running a leak site during the half, and 44 of them were new. February and April were the busiest months for launches with nine each, and February is also when the victim count spiked, roughly 72.9% above the same month in 2025. The firm attributes the surge to that wave of new entrants, continued output from the established crews, and the spread of the ransomware as a service model that lets someone run a campaign without building anything. IntelFusions has tracked smaller brands crowding onto the leak sites through the summer; what S2W's figures add is scale.
A top tier thirteen times the size of everyone else
The activity isn't spread evenly. The ten most active groups accounted for 54.3% of all claims, averaging 325 victim organizations each. The other 109 averaged about 25 apiece. Most of the brand names are noise; a handful of operations do most of the damage. S2W's own risk assessment puts Qilin, PLAY, LockBit, Interlock and INC in its top five for the half, and it reports that Qilin exploited two Check Point VPN flaws, CVE-2026-50751 and CVE-2026-50752, as zero days during the period. S2W publishes no exploitation detail for either, and the vendor's advisory is where that lives. Interlock turned up earlier this year using memory forensics tools against the machines it had broken into.
Big economies, and factories
The ten worst affected countries carried 71.7% of all victim organizations: five in Europe, three in the Americas, one in Asia, one in Oceania. The United States led and posted the largest year on year increase, while Monaco recorded the largest decrease. Manufacturing took the heaviest damage of any sector, which tracks: factories combine expensive downtime with flat networks and equipment that can't be patched on anybody else's schedule.
The sharpest regional move is in S2W's own back yard. South Korea appeared in 36 cases in the first half, more than 3.3 times its 2025 figure, and S2W argues that's a pattern setting in rather than a blip, with several groups now treating South Korean companies as standing targets. Our South Korea country profile carries the wider picture.
Watch the edge devices and the remote admin tools
S2W's advice aims at the parts of the chain that repeat whichever brand is on the ransom note. Monitor internet facing VPNs, firewalls and remote access appliances for abnormal authentication. Treat legitimate remote management software as suspicious wherever it has no business being, because AnyDesk, PsExec, TeamViewer, SimpleHelp, ScreenConnect and RustDesk all recur in these intrusions. Credential harvesting followed by network scanning is what S2W calls the key indicator of the pre deployment stage, and a security agent going quiet is an emergency in itself, since EDR killers like GentleKiller exist to buy the few minutes encryption needs. Then the familiar and still unfinished list: MFA on remote and administrator access, application control over management tools, least privilege, and backups kept offline or immutable.
The headline number will get quoted for the rest of the year, but 44 is the more useful one. A market that adds forty four sellers in six months isn't consolidating under law enforcement pressure; it's replacing what gets taken down faster than it's taken down. Each new brand starts with no reputation and no affiliate base, which tends to make the early claims noisier and the negotiations worse.
This briefing is provided by IntelFusions for informational and defensive purposes only. It is based on sources assessed to be reliable at the time of writing, and analytic judgments carry the confidence levels indicated. Indicators of compromise are defanged; re-arm them only in controlled environments. IntelFusions is not affiliated with the organizations named and makes no warranty as to completeness or accuracy.