Published Security3 min read
Ransomware's Victim Count Stalled. The Number of Crews Posting Victims Hit a Record.
Data leak sites logged 2,139 victims in Q2 2026, essentially flat quarter on quarter, while active groups climbed from 71 to 93.
Not a builder's beat, but builders have a standing stake in it.See today for builders
What happened
- Data leak sites recorded 2,139 ransomware victims in Q2 2026, essentially flat versus Q1 and up 33% year over year.
- The number of active ransomware groups jumped from 71 in Q1 2026 to 93 in Q2 2026, a new high.
- The top 10 groups controlled 71% of victims in Q1 2026 and 57.6% in Q2 2026.
- Top-10 share of victims fell by 13.4 percentage points between Q1 and Q2 2026.
- Cl0p, whose Oracle E-Business Suite campaign drove much of Q1 2026's victim numbers, nearly vanished in Q2, and a wider mid tier filled the gap.
Compiled by The WatchSomething wrong?How this is made
Why it matters
Data leak sites recorded 2,139 ransomware victims in the second quarter of 2026, essentially flat against Q1 and up 33% year over year, according to Check Point research [1]. The number of groups posting those victims rose from 71 to 93, the highest on record [2], which makes the denominator the story rather than the total.
Concentration loosened along with it. The top 10 groups controlled 71% of victims in Q1 and 57.6% in Q2 [3], a drop of 13.4 percentage points in three months [4]. Cl0p, whose Oracle E-Business Suite campaign drove much of Q1's volume, nearly disappeared, and a wider mid tier filled the space [5]. Qilin held first place for a fourth consecutive quarter with 279 victims, narrowly ahead of The Gentlemen, which grew 62% and out-posted Qilin in June [6]. Run the arithmetic on the concentration figure and the top 10 account for roughly 1,232 of the quarter's victims, leaving about 907 spread across 83 other groups, or roughly 11 each [7]. That is a long tail of small operations, not a cartel.
The Gentlemen leak explains how the tail got so long. Researchers obtained the group's backend and chat history [8]. The core team was nine people, running a 90/10 revenue split with an affiliate base that carried out most of the intrusion work, the highest cut advertised in the market [9]. The admin, Zeta88, built the operation's ransomware management panel in about three days using AI coding assistants, and said plainly that the tools still require someone who understands the code well enough to guide and correct it [10]. Check Point's own framing is worth keeping: the AI use here was about writing software faster, not running operations or selecting targets [11]. The relevant consequence is not autonomous crime. It is that one experienced operator with a small crew can now stand up a top tier extortion business in months.
The economics have shifted underneath that. Payment rates have fallen for six straight years, from 85% in 2019 to roughly 23% today, largely because backups neutralize encryption [12] - a 62 point decline [13]. Total dollars have not followed: on chain ransomware payments still exceeded $820 million in 2025 [14]. Backups do not stop a leak, which is why operators are moving to exfiltration-first extortion [15]. The Gentlemen's own intake ran on VPN scanning, brute forcing, and brokered credentials, the same route used across most of the ecosystem [16], and Check Point argues exfiltration detection now deserves the weight backup and recovery has traditionally received [17].
Law enforcement spent the quarter going after shared infrastructure rather than individual brands, dismantling a laundering platform, sanctioning exchanges tied to ransomware actors, and taking down a malware signing service and major infostealer networks; none of that registered as a drop in the Q2 victim count, and seized infrastructure tends to get rebuilt [18].
Watch whether the flat baseline holds. Check Point's monthly series counted 964 reported ransomware victims in July, up 49% from June and 87% year over year [19], roughly 35% above the average month inside Q2 [20]. The monthly and quarterly figures are drawn from different counts and are not strictly like-for-like, but the direction is not flat. Also watch mid-tier attribution: with 93 groups in play and affiliates taking 90% of the take, the brand on the leak site says progressively less about who actually broke in.
Claim ledger
Ranked by verification strength, evidence, and original report placement.
- [1]
Data leak sites recorded 2,139 ransomware victims in Q2 2026, essentially flat versus Q1 and up 33% year over year.
- [2]
The number of active ransomware groups jumped from 71 in Q1 2026 to 93 in Q2 2026, a new high.
- [3]
The top 10 groups controlled 71% of victims in Q1 2026 and 57.6% in Q2 2026.
- [5]
Cl0p, whose Oracle E-Business Suite campaign drove much of Q1 2026's victim numbers, nearly vanished in Q2, and a wider mid tier filled the gap.
- [6]
Qilin held the top spot for a fourth straight quarter with 279 victims, narrowly ahead of The Gentlemen, which grew 62% and outpaced Qilin in June.
- [8]
A leak exposed The Gentlemen ransomware operation's backend and chat history, giving researchers an inside view of a top tier operation.
Sources & coverage · 1 publisher
The reporting this story was synthesized from, earliest first. Every link goes to the original.
Additional citations
- Check Point Research
- Check Point Research, citing leaked Gentlemen chat logs



