The second quarter of 2026 confirmed that ransomware isn't in absolute decline but has accelerated a structural transformation. Data leak sites recorded 2,139 victims, virtually flat against the 2,122 in Q1 (+0.8%) but up 33% year-over-year, according to Check Point Research. The significant figure isn't the volume but the distribution: the number of active groups rose from 71 to 93, a new record, and the top-10 share fell from 71% to 57.6%.
This fragmentation coincides with two converging phenomena documented by the same sources. The ransom payment rate has dropped to roughly 23%, down from 85% in 2019, declining for six consecutive years. At the same time, on-chain ransomware payments exceeded $820 million in 2025, per Check Point Research analysis — an apparent contradiction explained by growing specialization between groups chasing high volumes and those targeting a handful of high-value victims.
- 2,139 victims on data leak sites in Q2 2026: flat quarter-over-quarter, +33% year-over-year; ransomware isn't slowing but spreading across more actors
- 93 active groups set a new record, with the top-10 falling to 57.6% of victims from 71% in Q1: democratization of the threat landscape
- The Gentlemen reached 269 victims (+62%), surpassing Qilin in June alone with a core team of roughly 9 people
- Payment rate crashed to 23%, pushing operators toward data-theft extortion and shrinking the exploitation window to hours from disclosure
The Payment Rate Collapse and Group Response
The structural decline in payments represents the single most impactful strategic factor. One in four organizations pays the ransom today, versus four in five six years ago. This contraction has made encryption-only extortion less profitable, forcing groups to recalibrate their economic model.
Check Point Research documents a "splitting" payment market: average ransoms are rising while the median falls. "Average payments are rising even as the median falls, a sign that large enterprises keep paying heavily while the mid market increasingly holds firm or settles small," the dedicated report states. The reading is that large enterprises continue paying significant sums, while the mid-market resists or negotiates reduced amounts. The data positions backups as an insufficient measure: even organizations that restore systems without paying remain exposed to publication of stolen data.
The shift from encryption-based extortion to data-theft extortion is irreversible by design. Once exfiltrated, data cannot be "recovered" by the target: the defender's only leverage becomes the ability to detect exfiltration before it completes, or to reduce the initial attack surface.
"The barriers to building a serious ransomware business have narrowed enough that one experienced operator can reach the top tier in months."
The Gentlemen: An AI-Compressed Organizational Model
Leaked chat logs from The Gentlemen offered rare visibility into a top-tier operation. The group grew from under 170 to 269 victims this quarter (+62%), surpassing Qilin in June with a core team of roughly 9 people. The operational structure features a 90/10 split with affiliates, described by Check Point Research as the "highest cut advertised in the market" for an operation of this size.
The technologically significant element is the construction of the ransomware management panel in roughly three days by administrator Zeta88, using AI coding assistants. The same source reports the operator's candid admission: the tools still require someone who understands the code well enough to guide and correct the output. AI doesn't replace expertise — it compresses it: reducing the headcount needed to reach a given level of sophistication.
Comparison with traditional RaaS operations like DarkSide or REvil highlights the contraction of the industrial model. Where a structured criminal organization required dozens of specialized operators, The Gentlemen demonstrates that an expert "solopreneur" with an AI assistant can build and scale a professional operation in months, not years. The initial access mechanism remains constant — VPN scanning, brute force, brokered credentials — but the weaponization speed for vulnerabilities has dropped drastically.
The Exploitation Window Is Measured in Hours
The dedicated research report documents that "the gap between disclosure and exploitation is now measured in hours." AI is cited as an accelerant in this process, not for operational autonomy but for the speed at which tooling and payloads can be adapted to new vulnerabilities. This temporal compression reduces the margin for patching and amplifies the value of behavioral detection over vulnerability management alone.
The geographic distribution of victims shows a partial shift. The U.S. share fell from 50% to 42% quarter-over-quarter, partly because The Gentlemen and Krybit target the American market less. The figure doesn't indicate an absolute contraction of attacks in the United States, but a geographic diversification that further widens the monitoring surface necessary for defenses.
Law enforcement actions in Q2 focused on shared infrastructure: money laundering platforms, sanctioned exchanges, malware signing services, infostealer networks. Check Point Research explicitly notes that "None of that shows up as a drop in Q2's victim count": investigative pressure has not translated into a documentable reduction in victims, at least within the observable timeframe.
What to Do Now
- Reallocate resources from post-encryption recovery to exfiltration detection: backups remain necessary but insufficient against data-theft extortion
- Reduce reliance on specific-group IOCs in favor of behavioral patterns: fragmentation makes targeted attribution less scalable
- Compress patching response times: with exploitation windows of hours, traditional weekly or monthly vulnerability management cycles create unacceptable exposure windows
- Assess visibility into outbound data traffic, not just inbound: exfiltration is the extortionists' new leverage point
The Real Risk Is Democratization, Not Automation
The primary reading of the Q2 2026 data is that the danger lies not in AI that "attacks on its own," but in AI that lowers the human capital required to build professional operations. More active groups mean more access vectors, more tooling variations, more unpredictability in the attack surface. For defensive organizations, the problem is no longer tracking a dozen known actors but managing a population of nearly a hundred groups with potentially short lifecycles.
The payment rate's decline to 23% suggests a growing portion of targets has developed the technical resilience to resist extortion. The question is whether this resilience extends to the ability to detect and contain exfiltration, or if the shift toward data-theft extortion will expose a new weak point in the dominant defensive model.
Information verified against cited sources and current as of publication.
Sources
- https://blog.checkpoint.com/security/ransomware-didnt-slow-down-in-q2-2026-it-just-spread-out/
- https://blog.checkpoint.com/security/ransomware-didnt-slow-down-in-q2-2026-it-just-spread-out/amp/
- https://research.checkpoint.com/2026/the-state-of-ransomware-q2-2026/
- https://blog.checkpoint.com/security/security-advisory-action-required-active-exploitation-of-check-point-smartconsole-authentication-bypass-cve-2026-16232/
- https://www.checkpoint.com/quantum/
- https://www.checkpoint.com/quantum/next-generation-firewall/
- https://www.checkpoint.com/ai/cloudprotect/
- https://www.checkpoint.com/quantum/next-generation-firewall/small-business-firewall/