BlackFog Q2 Ransomware Report: Undisclosed Ransomware Attacks Surge 40% Year on Year
BlackFog Q2 Ransomware Report: Undisclosed Ransomware Attacks Surge 40% Year on Year
The highest ransom demand reaches $25M as services sector attacks surge by 221% from Q1 with new ransomware groups emerging at a rapid pace
SAN FRANCISCO--(BUSINESS WIRE)--BlackFog, the leader in ransomware prevention and anti data exfiltration (ADX), today revealed findings from its analysis of global ransomware activity from April - June 2026 covering both publicly disclosed and undisclosed attacks.
Publicly reported ransomware incidents represent only the tip of the iceberg. Through monitoring of ransomware leak sites on the dark web, the report highlights the gap between undisclosed incidents and publicly disclosed attacks. Although the overall number of undisclosed attacks fell 6% compared to last quarter, the volume has surged 40% year on year, with 2,027 attacks in Q2 2026, compared with 1,446 in Q2 2025.
Meanwhile, 306 publicly disclosed attacks were recorded, a 16% increase compared to the last quarter. With threats evolving and new groups emerging, the findings highlight that ransomware remains a persistent and highly active cyber threat.
Key findings
Q2 2026 reinforced that ransomware activity remains widespread. In terms of disclosed attacks for this period, the analysis reveals:
- The highest ransom demand was $25 million
- Disclosed attacks targeting the services sector rose by 221% compared to Q1 2026
- 97% of incidents involved data exfiltration, the highest rate ever recorded
- 57 ransomware variants were associated with disclosed attacks, a 21% increase from Q1 2026
- Healthcare was the most targeted sector, accounting for 81 attacks (26%)
- The services sector experienced 45 attacks (15%), followed by government at 30 attacks (10%)
- The USA remained the primary target, accounting for 169 disclosed attacks (55%) followed by Australia with 54 incidents (18%)
The Most Active Ransomware Groups
Ransomware activity remained highly fragmented. In terms of undisclosed attacks 28 new ransomware groups emerged during Q2, twice as many as in Q1. Qilin continues to lead with 285 attacks (14%), followed by The Gentlemen with 219 (11%) and Dragon Force with 137 (7%). In total, 93 ransomware groups were active, including 28 newly formed groups in Q2, twice as many as in Q1.
Among publicly disclosed attacks, Shiny Hunters was the most active, responsible for 28 attacks (9%). Qilin followed with 19 attacks (6%), and INC accounted for 13 attacks (4%).
The challenges of attribution are also revealed, with 30% of all publicly disclosed ransomware incidents not attributed to any known group.
Settra’s Rapid Rise Signals a New Ransomware Threat to Watch
Since it was first observed in June 2026, Settra has claimed 22 victims; more than any other newly identified group within this quarter. Settra arrived fully formed. Rather than gradually expanding its operations, the ransomware group launched attacks across seven countries; the USA, UK, France, Portugal, Taiwan, South Korea and Singapore within its first four days, suggesting a sophisticated operation with global ambitions from the outset.
The Emerging Threats Reshaping Data Exfiltration
The biggest weapon in today's ransomware attacks is stolen data. The exfiltration rate continued to stay notably high in Q2 at 97%. Also, the average volume of data stolen per undisclosed incident reached 508 GB, with victims given an average of 7 days to meet ransom demands.
Commenting on the findings, Dr. Darren Williams, Founder and CEO of BlackFog, said:
“The trends we’ve identified over the last quarter, underline not only the scale of the ransomware threat, but also how quickly new groups can emerge and establish themselves. This is a landscape shaped by persistent, well-organised and highly motivated threat actors.
“While the tactics used by these groups continue to evolve, one objective remains consistent: stealing data. Data exfiltration is at the heart of modern ransomware and will continue to be the primary goal of these attacks. The defining difference between organisations that recover quickly and those left facing significant financial, operational and reputational damage is their ability to prevent data from leaving the endpoint in the first place. Preventing data exfiltration is no longer just a part of the ransomware defence strategy - it is the strategy.”
For a detailed look into the findings, download: BlackFog’s 2026 Q2 State of Ransomware Report.
Methodology
This report was generated in part from data collected by the BlackFog Console over the specific report period April – June 2026. Our research combines publicly disclosed ransomware incidents with independent analysis to identify emerging trends, threat actors, industry targeting, and changes in attacker tactics. This broader methodology captures both publicly acknowledged attacks and those that remain undisclosed by victims providing a more comprehensive view of global ransomware activity and the growing role of data extortion in modern cybercrime.
The data presented in this report is compiled from a combination of publicly available sources, ransomware group leak sites, open-source intelligence, and BlackFog’s ongoing threat research.
About BlackFog
BlackFog is the category-defining vendor in anti-data exfiltration (ADX). Founded in 2015, the company invented ADX on the thesis that the endpoint is the only control point capable of stopping data from leaving an organization, an architectural bet that has now been validated across three exfiltration vectors: ransomware, shadow AI, and autonomous AI agents. BlackFog’s endpoint-native platform protects more than 500 enterprises, government agencies, and critical infrastructure operators worldwide.
The company is the publisher of the annual State of Ransomware report and the BlackFog/Sapio Shadow AI Research, the most-cited primary research in the category. BlackFog’s recognition includes the teiss Awards 2026, the AI Excellence Award 2026, the Cybersecurity Excellence Awards 2026, and the Cybersecurity Breakthrough Award. Headquartered in San Francisco with international operations in London and Belfast. Learn more at blackfog.com.
Contacts
Media contact:
Code Red Communications
BlackFog@CodeRedComms.com
