GuidePoint Reports Rising Q2 Ransomware Activity

For practitioners, the report reinforces a defensive pattern: ransomware risk is increasingly concentrated among a small set of high-volume operations, while large language models can support data analysis and extortion communications. GuidePoint Security recorded 2,279 publicly reported ransomware victims in Q2 2026, up 7% from Q1 and 43% year over year. Its GRIT team observed 91 active ransomware groups across 108 countries, a record in its observed periods. GuidePoint found that the five most prolific groups claimed more than 40% of recorded attacks, led by Qilin, The Gentlemen, Akira, and DragonForce. The report describes AI use primarily as a productivity aid for analyzing exfiltrated data, tailoring negotiations, and applying psychological pressure, rather than as a source of catastrophic AI-native attacks.
A concentration problem, not just a volume problem
For practitioners, the most consequential finding is not simply higher ransomware volume. Industry context: when a relatively small group of operators accounts for a large share of incidents, intelligence teams can gain leverage by prioritizing tracking of those groups' tactics, infrastructure, leak-site activity, and affiliate ecosystems. At the same time, automation of extortion workflows can make post-compromise pressure more targeted without requiring a fundamentally new intrusion technique.
GuidePoint Security's GRIT team recorded 2,279 publicly reported ransomware victims in Q2 2026. According to GuidePoint, that total was 7% above Q1 2026 and 43% above Q2 2025, and weekly victim postings did not fall below 150 during the quarter. Public victim claims are a useful indicator of attacker activity, but they do not establish a complete count of all ransomware incidents.
GuidePoint observed 91 active ransomware groups operating across 108 countries, the highest count in its observed periods. Cybersecurity Dive reported that the United States accounted for 40% of publicly claimed victims and Germany for 32%, citing GuidePoint's research.
The leading groups account for more than 40% of claims
According to GuidePoint, the five most prolific ransomware groups collectively claimed more than 40% of recorded attacks in the quarter. Qilin remained the most active group and accounted for 13% of claims, while The Gentlemen rose to second place and DragonForce became the third most active group for the first time. GuidePoint and Cybersecurity Dive identify Qilin, The Gentlemen, Akira, and DragonForce as the principal high-volume cluster.
Cybersecurity Dive reported GuidePoint's assessment that several established ransomware-as-a-service operations could absorb affiliates displaced if another operation is disrupted. That is an assessment of the ecosystem's resilience, not evidence that any one specific group will gain affiliates after a future takedown.
Industry context
affiliate-based criminal ecosystems commonly complicate disruption because malware, access brokers, extortion infrastructure, and operational personnel can be distributed across organizations. Defensive programs therefore benefit from detection engineering focused on behaviors that survive brand changes, including credential abuse, remote-management-tool misuse, lateral movement, data staging, and exfiltration.
AI use is focused on extortion productivity
GuidePoint reported that threat actors are using large language models to analyze exfiltrated data, personalize ransom negotiations, and create psychological pressure. The firm characterized this as a productivity use case rather than evidence of a broad wave of catastrophic AI-native ransomware attacks.
For practitioners, this distinction matters operationally. Industry context: LLM-assisted analysis can increase the speed and specificity of extortion after data theft, so incident-response planning should treat data classification, exfiltration detection, and communications procedures as core ransomware controls, not only encryption recovery measures. The report does not identify a new AI-enabled malware technique or a specific model used by the groups.
Manufacturing remains the most reported target sector
GuidePoint identified manufacturing as the most affected industry, accounting for nearly 15% of reported ransomware victims in Q2. The firm noted that manufacturing has held the top position in its analysis for several years.
For practitioners in operational technology-adjacent environments, industry context
ransomware resilience depends on separating business-network recovery from production continuity, validating backup restoration under realistic constraints, and maintaining tested procedures for identity and network containment. These are general defensive implications of recurring ransomware activity, rather than claims about any individual victim's controls.
Key Points
- 1GuidePoint counted 2,279 public ransomware victim claims, making Q2 volume 43% higher year over year and sustaining elevated defensive pressure.
- 2Five groups claimed over 40% of incidents, so threat-intelligence prioritization can focus on durable affiliate and intrusion behaviors rather than group branding.
- 3GuidePoint found LLMs supporting data analysis and extortion communications, raising the importance of exfiltration detection and incident communications readiness.
Scoring Rationale
The report provides timely, quantified evidence of rising ransomware activity and concentration among leading operations. Its AI findings are operationally relevant to security teams, although it reports productivity use rather than a new AI-native attack capability.
Sources
Public references used for this report.
Practice interview problems based on real data
1,625 SQL & Python problems across 15 industry datasets — the exact type of data you work with.
Try 250 free problems


