Ransomware: Barriers to Entry Are Lowering, but the Threat Remains High

Check Point Software has released its «State of Ransomware Q2 2026» report. In the second quarter of 2026, 2,139 victims were listed on data leak websites worldwide—a 33 percent increase from the previous year. Particularly concerning: AI tools enable small teams to set up powerful ransomware operations within just a few months.

The Qilin ransomware group topped the list in Q2 2026 with the most victims. Source: Check Point.

The global ransomware threat remains at a high level. According to the latest «State of Ransomware Q2 2026» report from Check Point Software, 2,139 victims were recorded on data leak websites worldwide in the second quarter of 2026. Compared to the first quarter, the number remained largely stable; however, year-over-year, this represents a 33 percent increase. The threat ecosystem has thus consolidated at the elevated level it had reached by 2025.

More groups, a broader attack surface

What changed in the second quarter was the composition of the attackers. While the ten largest groups accounted for 71 percent of victims in the first quarter, that share dropped to 57.6 percent in the second quarter. At the same time, the number of active ransomware groups rose from 71 to 93—a new record high since records began. With 279 victims, the Qilin group took first place for the fourth consecutive time, just ahead of «The Gentlemen,» which grew by 62 percent. Cl0p, whose campaign targeting the Oracle E-Business Suite had accounted for a large portion of the figures in the first quarter, has since almost completely disappeared.

Sergey Shykevich, Director of Threat Intelligence at Check Point Software, comments on the findings: «The most important insight from this quarter is not the number of ransomware victims, but how dramatically the barriers to entry are falling. We now have evidence that a small team, supported by AI-powered tools and affiliate networks, can set up a high-profile ransomware operation within a few months.»

AI Accelerates the Setup of Ransomware Operations

A data leak from the ransomware group «The Gentlemen» provided security researchers with rare insights into how the group operates. The core team consisted of just nine people and practiced a 90/10 profit-sharing arrangement with a broader base of partners who handled the bulk of the hacking work. One detail is particularly revealing: The group’s administrator, known as Zeta88, developed the organization’s ransomware management panel using AI programming assistants in about three days. He himself acknowledged that the tools still require someone who understands the code well enough to guide and correct them. This demonstrates that AI accelerates the development of ransomware tools—even if human expertise remains necessary.

Payment Rates Are Falling, Data Theft Is on the Rise

The ransom payment rate has fallen for six consecutive years—from 85 percent in 2019 to about 23 percent today. Improved backup strategies have reduced the effectiveness of encryption attacks. However, backups do not help against data theft: If files have already been stolen and are about to be published, a system restore can no longer prevent data leaks. For this reason, ransomware operators are increasingly turning to «exfiltration-first extortion»—stealing data first, then extorting victims. Total payments remained correspondingly high: In 2025, more than $820 million in ransomware payments were still recorded via the blockchain.

The U.S. has the most ransomware victims worldwide. Source: Check Point

Law Enforcement: Friction Losses Instead of Break-Ins

In the second quarter, law enforcement agencies focused more on shared infrastructure than on individual groups. They dismantled a money-laundering platform, imposed sanctions on exchanges linked to ransomware actors, and shut down a malware signing service as well as large networks of infostealers. There has been no immediate decline in the number of victims so far, as seized infrastructure is typically rebuilt elsewhere. However, the increased costs of money laundering, signing, and obtaining credentials create friction losses that accumulate over the long term.

Ransomware most commonly targets business services (33%). Source: Check Point

Four Technologies for Protecting Against Ransomware

Check Point provides businesses with four different technologies to protect against ransomware. Workspace Security protects users in emails, browsers, SaaS applications, and on endpoints—using AI-powered detection to stop ransomware delivery before it executes and to contain lateral movement and data exfiltration following a compromise. Hybrid Mesh Network Security applies consistent, AI-driven controls at every connection point: from firewalls that block malicious files before they reach devices to CASB scans that intercept malware entering via SaaS platforms such as OneDrive and Slack. In the event of a compromise, zero-trust access via SASE Private Access limits the scope of the damage.

Exposure Management answers the question of which vulnerabilities ransomware groups can actually exploit. According to Check Point’s «2026 Exposure Gap Report,» vulnerabilities now account for 42.6 percent of critical security gaps—more than twice as many as in the previous year. Companies in the utilities sector that use the platform resolve 30 percent of their vulnerabilities within an hour. Finally, AI Security leverages the same technologies that ransomware groups are increasingly using: ThreatCloud AI ensures that protection keeps pace with AI-powered exploitation of vulnerabilities. AI Agent Security manages agent permissions, AI Red Teaming tests AI applications before deployment, and Workforce AI Security prevents login credentials from being leaked via AI tools.

Source: www.checkpoint.com/de

This article originally appeared on m-q.ch - https://www.m-q.ch/de/ransomware-einstiegshuerden-sinken-bedrohung-bleibt-hoch/

More articles on the topic