Check Point says ransomware activity in the second quarter of 2026 did not decline — it simply dispersed across more operators, making the threat harder to track and defend against. Data leak sites recorded 2,139 victims in Q2, essentially unchanged from Q1 but 33 percent higher year over year, showing that the ecosystem has settled into a consistently elevated baseline. The headline number remained stable, but the underlying dynamics shifted in ways that matter for defenders.
The most notable change was the spread of activity across a larger number of groups. In Q1, the top ten operators controlled 71 percent of all victims across 71 active groups. By Q2, their share dropped to 57.6 percent while the number of active groups climbed to a record 93. Cl0p, whose Oracle E‑Business Suite campaign drove much of Q1’s spike, nearly disappeared, allowing a broader mid‑tier to fill the gap. Qilin held the top spot for a fourth consecutive quarter with 279 victims, narrowly ahead of The Gentlemen, which grew 62 percent and overtook Qilin in June.
The Gentlemen’s rapid ascent was illuminated by a rare leak of its backend and chat history, giving researchers an inside view of how a top‑tier operation is built. The core team consisted of only nine people supported by a wider affiliate base operating on a 90/10 revenue split — the most generous in the market. The group’s admin, Zeta88, built its ransomware management panel in roughly three days using AI coding assistants. The chats show that while AI accelerated development, it still required an operator with enough expertise to guide and correct the output. The larger implication is that the barriers to building a serious ransomware enterprise have narrowed to the point where a small, skilled team can reach global prominence within months.
Payment rates continued their long decline, falling to about 23 percent, down from 85 percent in 2019. Improved backups have weakened encryption‑based extortion, pushing operators toward data theft, where restoring systems does nothing to prevent leaks. Despite lower payment rates, on‑chain ransomware payments still exceeded $820 million in 2025, underscoring the financial resilience of the ecosystem. Law enforcement focused on shared infrastructure rather than individual groups, dismantling laundering platforms, sanctioning exchanges, and disrupting malware‑signing and infostealer networks.
Check Point says the quarter’s data reinforces that initial access, exfiltration detection, and exposure reduction now carry equal urgency. Ransomware groups continue to rely on phishing, VPN scanning, brute forcing, and brokered credentials — the same pipeline The Gentlemen used — while AI‑assisted tooling accelerates exploitation timelines. The defensive challenge is no longer just stopping encryption; it is preventing access, detecting theft, and reducing exposure before extortion begins.











