-

GuidePoint Security Reports Record-High Ransomware Activity as Victims Rise 75% Year Over Year

New GRIT Report Shows Ransomware Operations Becoming More Widespread and Moving Faster, Even as Payment Rates Fall

RESTON, Va.--(BUSINESS WIRE)--GuidePoint Security, the cybersecurity advisor and services partner organizations rely on to protect what matters most, today released the GuidePoint Research and Intelligence Team’s (GRIT) Q3 2026 Ransomware and Cyber Threat Insights Report.

Tools, playbooks and infrastructure are readily available through the affiliate model, allowing new groups to emerge faster and more actors to launch repeatable campaigns without building capabilities from scratch.

Share

Even as ransom payment rates declined, GRIT tracked 2,760 ransomware victims in Q3 2026 — more than in any previous quarter — across more groups and more countries.

“The barrier to entry in ransomware keeps dropping,” said Nick Hyatt, Principal Threat Intelligence Consultant at GuidePoint Security. “Tools, playbooks and infrastructure are readily available through the affiliate model, allowing new groups to emerge faster and more actors to launch repeatable campaigns without building capabilities from scratch. That makes volume a viable strategy even when fewer victims pay.”

Key findings from the report include:

  • Ransomware victim volume reached a record high. GRIT recorded 2,760 victims in Q3 2026, up 21% from Q2 2026 and 75% from Q3 2025.
  • The number of threat groups continues to grow. Active ransomware groups numbered 112 in Q3 2026, a 23% quarter-over-quarter increase and a 47% year-over-year increase.
  • Payment rates fell, but average payments increased. Analysis of internal data found that ransomware payment rates fell by more than half year over year, while the average payment among organizations that paid rose 34% and ransomware case volume increased 61%.
  • The Gentlemen narrowly overtook Qilin as the most active threat group. The Gentlemen accounted for 12.9% of observed victims in Q3 2026, compared with 12.6% for Qilin. Together, the two groups claimed about one in four victims.
  • Ransomware targeting is broadening geographically. Victims spanned 115 countries, up from 108 in Q2 2026 and 90 in Q3 2025. The United States remained the most targeted country, accounting for 42% of victims.
  • Manufacturing remains the most impacted industry. Manufacturing continued to lead all industries in observed victim volume, followed by technology and healthcare. Banking and finance returned to the top 10 after dropping out in Q2 2026, driven in part by a sustained social-engineering campaign targeting private equity firms.

The report also examines the rise of ShinyHunters as a prominent data-extortion actor, a surge in vulnerability disclosures — including nearly 1,000 in a single September security update — and the growing use of AI agents in cybercrime.

“Our assessment is that AI is beginning to shorten the time between initial access and impact for some attackers,” Hyatt added. “The encouraging part is that these attacks succeed through familiar weaknesses, such as stolen credentials and unpatched software. Organizations that pair fast patching with strong identity controls and automated response can close that window.”

The GRIT Q3 2026 Ransomware and Cyber Threat Insights Report is based on data obtained from publicly available resources, vendor threat research, internal incident response case data and open-source intelligence collected from illicit forums and marketplaces.

For more information:

About GuidePoint Security

GuidePoint Security helps organizations overcome the most complex cybersecurity challenges, mature their security posture, minimize risk and ensure compliance. As a trusted cybersecurity advisor and partner, GuidePoint keeps people, data, and operations safe. We deliver tailored cybersecurity services and offerings that adapt and scale to safeguard the nation’s leading organizations today, while preparing them to confidently face tomorrow's cyber challenges. More than 5,900 organizations of all sizes and across every industry, as well as over half of U.S. cabinet-level agencies, rely on GuidePoint to strengthen their defenses and reduce risk. Stronger Together. Protecting What’s Next. Learn more at guidepointsecurity.com.

Contacts

Nicole Lavella
nicole.lavella@guidepointsecurity.com
703-403-7066

GuidePoint Security

Details
Headquarters: Reston, VA
CEO: Scott Rachford
Employees: 1300
Organization: PRI

Release Summary
GuidePoint Security tracks record-high ransomware activity as victims rise 75% year over year.
Release Versions

Contacts

Nicole Lavella
nicole.lavella@guidepointsecurity.com
703-403-7066

Social Media Profiles
More News From GuidePoint Security

GuidePoint Security Joins AWS Security Hub Extended as a Services Partner

RESTON, Va.--(BUSINESS WIRE)--GuidePoint Security has joined the AWS Security Hub Extended as a Services Partner....

GuidePoint Security Expands Identity and Access Management Practice With Three New Service Offerings

RESTON, Va.--(BUSINESS WIRE)--GuidePoint Security expands its Identity and Access Management Practice with new Agentic AI, Identity Verification and Non-human Identity offerings....

New IDC Research Sponsored by GuidePoint Security Finds AI Agents Are Outpacing Security Teams

RESTON, Va.--(BUSINESS WIRE)--New IDC Research sponsored by GuidePoint Security finds that AI agents are outpacing security teams....
Back to Newsroom