Ransomware Accelerated 60% in Six Months. The Exposure Outlived the Claim

Estimated reading time: 7 minutes

Ransomware had another worst year on record, which now reads less like a warning than a renewal notice.

Black Kite counted 7,551 publicly disclosed ransomware victims in the year to March 31, 2026. That runs 24.9% above the prior period. The annual figure hides the shape of the year. Disclosures tracked close to the prior pace through September 2025. Then they jumped. The second half outpaced the first by 60%. March 2026 closed with 861 victims. That is the highest month in four years of Black Kite tracking. The 2026 Ransomware Report also asks a question that lands on underwriting desks. Black Kite rescanned its victim population after disclosure. Surface hygiene improved. Ransomware-specific exposure got worse.

Ransomware cyber insurance graphic on navy with rising cyan bars and an amber line continuing upward past them. Text reads Black Kite 2026 Ransomware Report, 7,551 victims, plus 60% in six months, and exposure kept climbing.

The Second Half Set the Pace

The first half of the period produced 2,904 victims. That averaged 484 a month. The second half produced 4,647, or 775 a month. Every month from October 2025 through March 2026 stayed above 700 victims. Black Kite reads that as a new operating tempo rather than a single spike.

Post-period data supports the read. April through June 2026 averaged 743 victims a month. That sits below the March peak. It also sits well above the first-half baseline. Black Kite treats those months as supplementary context. It excludes them from year-over-year calculations.

Sixty-One New Groups Entered. Five Actors Took 43.6%.

The market expanded and concentrated at the same time. Sixty-one new groups appeared during the reporting period. That works out to more than one a week. Active groups rose from 96 to 127 by March 31, 2026. Black Kite’s post-period monitoring puts the trailing count at 146 by June.

The top five actors still claimed 43.6% of all victims. Qilin took 1,358 of them, a 443% year-over-year increase. It operated across more than 50 countries. Akira followed with 749 victims. INC Ransom took 436. Play took 422. SafePay took 324.

RansomHub tells the other side of the story. It led the prior reporting period with 736 victims. It recorded zero this year. The group disappeared in May 2025.

New entrants hunted differently from incumbents. Established groups aimed 53.4% of attacks at US targets. New groups sent 38.7% there. The remainder spread into Europe, Brazil, Thailand, and the UAE.

Revenue profile shifted too. Companies in the $50M to $100M band rose from 25.1% of victims to 29.3%. The $100M-plus band fell from 13.9% to 9.5%.

See also  The “Downtime Era” Redefines Business Interruption Risk - Absolute Security

Payment Rates Fell. The Amounts Held.

Black Kite does not measure payments directly. It cites external incident response and survey data. Coveware reported 26% of organizations paid in Q2 2025. Veeam reported 23% across all extortion scenarios in Q3. That figure fell to 19% for exfiltration-only incidents. Sophos reported a $1 million median payment among organizations that paid.

Those sources cover different populations. Black Kite presents them as directional signals rather than a single market rate.

Ekrem Selçuk Çelik is a cybersecurity researcher at Black Kite. He rejects the frequency-versus-severity framing that the payment data invites. “The strongest underwriting view combines potential loss severity with evidence of how reachable and attractive the organization is to ransomware operators,” he told Cyber Insurance News.

His argument rests on visibility. Black Kite found companies scoring 0.8 to 1.0 on its Ransomware Susceptibility Index appeared as victims at 291 times the rate of companies scoring below 0.2.

The Claim Closed. The Exposure Did Not.

Black Kite compared victim security posture at disclosure against the latest available scan. The results split.

Surface indicators improved. Average Cyber Rating rose 0.69 points. Botnet activity fell from 9.7 to 3.1. Roughly half of victims improved their overall rating.

The ransomware-specific layer moved the other way. Average Ransomware Susceptibility Index rose from 0.557 to 0.616. Software vulnerability exposure worsened for about two-thirds of victims. Stealer log exposure came in 175% higher.

Çelik draws the underwriting conclusion directly. “A prior claim should neither reset the clock nor automatically raise the premium. The deciding factor is what exposure remains after the incident.”

He argues a prior incident should trigger a deeper current-state review instead of an automatic rating move. A victim has already proven it was reachable and worth reaching. Access brokers and stolen credentials outlive the brand that used them.

Current-state data reinforces the point. Black Kite found 43.5% of victims still carrying critical patch vulnerabilities. KEV exposure appeared in 30.8%. Stealer log credentials showed up in 29.6%. Misconfigured DMARC records appeared in 58.9%.

One Vendor, Thirty-Two Banks

The year’s most consequential incidents moved through trusted platforms. Qilin compromised a single managed service provider. That breach reached 32 South Korean financial institutions.

The Salesloft Drift campaign compromised OAuth tokens tied to a third-party application. Attackers used them to reach Salesforce customer instances. Clop exploited a zero-day in Oracle E-Business Suite before a patch existed. ShinyHunters extended the pattern into Oracle PeopleSoft after the reporting period closed.

See also  Coalition Launches Private Equity Cyber Insurance

CINI has tracked this shape before. Black Kite’s European report found one Swedish HR vendor accounted for 34 of 64 supplier-driven incidents. Its financial services report found half the sector’s vendors carrying critical flaws. Its supply chain vulnerability research narrowed more than 48,000 CVEs to 58 that posed a genuine threat.

Çelik declined to say whether carriers price that exposure correctly. He was direct about how to frame it. The relevant question is no longer only how secure the insured organization is. “It is also how much of its attack surface and operational dependency is controlled by the same vendors used across the wider portfolio.”

AI Lowered the Cost of the Work

Black Kite concludes AI did not redefine ransomware during the period. It lowered the cost of the work around the attack. Reconnaissance moved faster. Phishing and vishing grew more convincing. Translation and extortion messaging got cheaper to produce.

The report cites two early signals. Researchers documented JADEPUFFER as a case of AI-assisted technical execution. TITAN AI markets automated stolen-data analysis and ransom calculation to affiliates.

Group lifespans shortened alongside the influx. New groups entering between April and September 2025 showed a median 4.9-month life. The comparable cohort a year earlier ran 12.8 months.

What Black Kite Recommends

The report closes with a defender checklist. Four items translate directly into underwriting questions.

Prioritize vulnerabilities known to be exploited in the wild. CVSS 9.0 or higher issues appeared in 43.5% of analyzed victims. KEV exposure appeared in 30.8%.

Extend third-party programs past questionnaires. Black Kite recommends connected app inventories, OAuth token review, and vendor-managed identity access checks.

Harden the human layer. Vishing, help desk impersonation, and vendor impersonation carried several of the year’s largest campaigns. Black Kite recommends tabletop testing against help desk reset workflows.

Treat post-incident exposure as an open workstream. The report suggests a structured 30, 60, and 90-day external review covering stealer logs, KEV status, and vendor-managed access.

Ferhat Dikbiyik is Black Kite’s Chief Research and Intelligence Officer. He puts the year in one line.

“The growth is human. AI just let more people show up at once.”

See also  SecurityScorecard Report Highlights Escalating Supply Chain Cyber Risks for Global 2000

Black Kite sells the Ransomware Susceptibility Index and FocusTag products cited in this report. The victim dataset covers publicly disclosed incidents only.

FAQ – Ransomware Cyber Insurance

What did Black Kite’s 2026 ransomware report find?

Black Kite identified 7,551 publicly disclosed ransomware victims between April 1, 2025 and March 31, 2026. That is 24.9% above the prior period. Disclosures accelerated 60% in the second half. March 2026 recorded 861 victims, the highest month in four years of tracking.

How many ransomware groups are active?

Black Kite counted 127 active groups at the close of the reporting period, up from 96 a year earlier. Sixty-one new groups entered during the period. Post-period monitoring put the trailing count at 146 by June 2026.

Did ransomware victims get safer after disclosure?

Only partly. Average Cyber Rating improved and botnet activity fell. Ransomware-specific exposure worsened. Average Ransomware Susceptibility Index rose from 0.557 to 0.616. Stealer log exposure came in 175% higher.

What is the Ransomware Susceptibility Index?

RSI is a Black Kite score running from 0.0 to 1.0. It combines technical signals with exploitability context. Black Kite reports that companies scoring above 0.8 appeared as victims at 291 times the rate of companies below 0.2.

How should carriers treat vendor concentration?

As accumulation risk. One managed service provider compromise reached 32 South Korean financial institutions. Salesforce, Oracle E-Business Suite, and OAuth integrations drove several of the year’s largest incidents. Questionnaire-based assessments do not measure shared platform dependency across a book.

Leave a Comment

×