August 14, 2025
Updated: September 2, 2026
A transparent Q2 2026 ranking of active ransomware groups, what changed since 2025, and the controls that reduce enterprise exposure.
Mohammed Khalil

By Q2 2026, the most active ransomware groups by publicly posted data-leak-site victims were Qilin (279), The Gentlemen (269), DragonForce (140), Akira (126), LockBit (105), and INC Ransom (92). These are claims published by criminal sites, not a count of every ransomware incident or proof that every listed organization was breached. Activity also does not equal impact: campaign-driven actors such as Cl0p can fall in quarterly rankings, then surge through one exploited platform. Defenders should prioritize exposed-system patching, phishing-resistant MFA, least privilege, segmentation, exfiltration detection, protected backups, and rehearsed response.
For broader volume, geography, cost, and payment trends, use DeepStrike’s 2026 ransomware statistics. This page is intentionally the comparison and threat-prioritization owner.
The ranking uses one consistent source: Check Point Research’s State of Ransomware Q2 2026 report. It recorded 2,139 organizations named across data leak sites during the quarter, 0.8% more than Q1 and 33% more than Q2 2025. The report counted 93 active groups and attributed 57.6% of posts to the top ten.
“Victim” in this dataset means an organization publicly named by an extortion group. It does not establish that the claim is true, that systems were encrypted, that data was stolen, or that money changed hands. Criminal sites can contain duplicates, re-posts, disputed claims, and organizations whose incident scope remains unknown.
The opposite limitation also matters. Some victims pay before publication, some incidents are handled privately, some groups do not operate a public leak site, and some data-theft cases are classified differently by different trackers. These counts are therefore a useful activity signal not a complete incident census.
| Rank | Group | Organizations named on leak sites | Quarter signal | What defenders should infer |
|---|---|---|---|---|
| 1 | Qilin | 279 | Down 17% from Q1, but first for a fourth straight quarter | Scale and affiliate diversity make one fixed malware profile unreliable. |
| 2 | The Gentlemen | 269 | Up 62%; first in June alone | A newer operation can scale quickly when access and affiliates are already available. |
| 3 | DragonForce | 140 | Up 39% | Shared or rebranded infrastructure can blur actor attribution. |
| 4 | Akira | 126 | Lower than Q1 but still high volume | Established operations remain relevant even when rank changes. |
| 5 | LockBit | 105 | Lower than its Q1 relaunch spike | Disruption can reduce capacity without permanently eliminating a brand. |
| 6 | INC Ransom | 92 | Lower than Q1 but still in the leading tier | Leak-site volume does not measure payment rate or case severity. |
The six groups accounted for 1,011 posts, or about 47.3% of the Q2 total. That concentration is operationally important, but it should not turn into a six-signature defense strategy. Affiliates, access brokers, tooling, infrastructure, and payloads can move between brands.
Qilin remained the most prolific operation for a fourth consecutive quarter with 279 posts, although its count fell 17% from Q1. Its narrow lead matters: a stable first-place label can hide a market in which another group was already ahead during the final month of the quarter.
For defenders, Qilin’s scale is less useful as a single indicator set than as evidence of a durable affiliate ecosystem. Controls should detect suspicious access, privilege changes, lateral movement, mass collection, unusual outbound transfer, and recovery tampering regardless of the final encryptor or extortion brand.
The Gentlemen recorded 269 posts, up 62% quarter over quarter, and posted 116 organizations in June compared with Qilin’s 72. The rise from a much smaller late-2025 footprint demonstrates how quickly a ransomware operation can become a global leader.
Rapid growth also weakens assumptions based on brand age. A newer name may still inherit experienced operators, compromised access, or mature tooling. Security teams should avoid using “new group” as a proxy for low capability.
DragonForce placed third with 140 posts, a 39% quarterly increase. Its position illustrates a wider shift toward flexible affiliate and branding models: the public name visible at the extortion stage may not identify every operator, tool, or initial-access path involved in the intrusion.
Attribution is valuable for intelligence and legal coordination, but containment cannot wait for perfect attribution. The operational questions come first: which identities were used, which systems were reached, whether data moved, and whether backup or security controls were altered.
Akira posted 126 organizations in Q2 and remained fourth despite a decline from Q1. Its continued volume shows why a lower quarter should not be interpreted as retirement or loss of capability.
A joint advisory updated in November 2025 described Akira activity involving exploited edge and backup systems, compromised credentials, remote-management tooling, data exfiltration, and attempts to impair defenses. The Akira ransomware advisory prioritizes known exploited vulnerability remediation, phishing-resistant MFA, offline backups, and restoration testing.
LockBit posted 105 organizations in Q2 after a larger Q1 relaunch spike. Its return to the leading tier does not erase the effect of earlier law-enforcement disruption, but it does demonstrate that infrastructure seizure and public identification do not guarantee immediate extinction.
DeepStrike’s LockBit ransomware guide covers the operation’s versions, disruption timeline, and defensive lessons in more depth. For this comparison, the key lesson is resilience: affiliates and tooling can persist, migrate, or reappear under altered infrastructure.
INC Ransom placed sixth with 92 posts. It is a useful example of why activity, revenue, payment, and impact should not be treated as one leaderboard. An actor with fewer public posts can still concentrate on larger organizations, receive more payments, or cause greater disruption than a higher-volume competitor.
Security leaders should therefore combine external activity tracking with their own exposure: sector, geography, critical vendors, remote-access products, identity architecture, recovery objectives, and the data an intruder could monetize.
Cl0p fell from 127 posts in Q1 to only 2 in Q2 after its Oracle E-Business Suite campaign ran its course. That drop is not evidence that the operation became harmless. It shows the burst pattern of a group that can exploit one widely deployed enterprise platform, name many organizations, and then go quiet between campaigns.
After the June 30 ranking cutoff, Cl0p claimed data theft from nearly 50 companies in a campaign linked by industry reporting to PTC Windchill and FlexPLM vulnerabilities. Reuters could not independently verify the group’s claims; some named companies confirmed investigation or a contained attempt, while others said they had found no evidence of customer or operational data compromise. That distinction is central to reading the August 2026 Cl0p reporting.
The practical lesson is to track both steady-volume operations and campaign-driven exploiters. DeepStrike’s Cl0p ransomware analysis provides the longer campaign history without turning unverified leak-site claims into confirmed facts.
Mass exploitation also rewards speed after disclosure. The earlier Oracle E-Business Suite vulnerability analysis illustrates why patching must be paired with compromise assessment: closing a flaw does not prove that an exposed system was clean before the fix.
The live 2025 article centered on Cl0p, Qilin, Akira, and RansomHub. By Q2 2026, only Qilin and Akira remained in the top four. The Gentlemen and DragonForce moved into second and third, LockBit returned to the top six, and RansomHub was no longer an active leader.
| Change | 2026 evidence | Defensive implication |
|---|---|---|
| RansomHub retired in 2025 | Affiliates redistributed to Qilin and other surviving operations | Losing one brand does not remove the operators or access behind it. |
| Qilin remained first | Four consecutive leading quarters, but a narrowing margin | High volume can coexist with rapid competitive change. |
| The Gentlemen scaled quickly | 269 Q2 posts and 62% quarterly growth | New names can inherit mature capability and access. |
| LockBit re-entered the leading tier | 163 Q1 posts and 105 Q2 posts | Disrupted groups can attempt recovery or relaunch. |
| Cl0p shifted between bursts | 127 Q1 posts, 2 Q2 posts, then a post-quarter campaign | Quarterly rank can understate platform-driven mass exploitation. |
| The active-group count expanded | 71 groups in Q1 and 93 in Q2 | The long tail increases naming and attribution noise. |
The durable pattern is ecosystem reuse. Operators move, affiliates change programs, access brokers serve multiple buyers, and tooling is copied or rebranded. A threat model tied too tightly to today’s logo will age faster than one tied to attack paths and business impact.
A ransomware-as-a-service operation may include developers, infrastructure operators, affiliates, initial-access brokers, negotiators, money-laundering services, and data-leak administrators. Not every incident uses every role, and one affiliate’s playbook can differ substantially from another’s under the same brand.
This separation explains why a group name is not a complete detection strategy. A stolen credential may be sold before a ransomware affiliate appears. A legitimate remote tool may be abused before an encryptor is deployed. Data theft may become the main pressure point even if encryption never occurs.
Common entry paths include exposed and unpatched systems, stolen credentials, social engineering, remote-access abuse, and compromised vendors. A risk-based patch management process should prioritize internet-facing known-exploited vulnerabilities, business-critical systems, and evidence of compromise not merely the largest raw CVE count.
Identity protection must cover sessions and recovery paths, not only passwords. DeepStrike’s password statistics and passkey guide explains why phishing-resistant authentication, unique credentials, and monitoring for session or enrollment abuse should be treated as one identity program.
Falling payment rates and improved recovery have pushed many actors toward data theft, public pressure, and multi-stage extortion. Organizations need visibility into unusual collection, archive creation, large outbound transfers, cloud storage use, and administrative changes that weaken logging.
An encryption-only tabletop exercise misses this risk. The response team should be able to answer what data may have left, which legal or contractual duties apply, and how to communicate while facts remain incomplete.
Backups should be separated from ordinary administrator paths, protected against deletion, monitored, and restored in realistic tests. A successful backup job is not proof that the organization can rebuild identity services, applications, dependencies, and clean infrastructure within its recovery objectives.
The direct expense is only part of the impact. DeepStrike’s analysis of ransomware recovery costs helps teams model investigation, downtime, restoration, notification, and post-incident improvement separately from the ransom demand.
The final 2026 NIST ransomware risk-management profile maps readiness across Govern, Identify, Protect, Detect, Respond, and Recover. The DeepStrike RANSOM framework below turns those outcomes into six evidence-oriented operating priorities; it is a practical mnemonic, not a replacement for NIST CSF 2.0.
| Letter | Priority | Core action | Evidence to require |
|---|---|---|---|
| R | Reduce exposed access | Inventory internet-facing assets and remediate exploitable paths by risk | Current asset owner, exposure record, patch or mitigation proof, compromise check |
| A | Authenticate strongly | Use phishing-resistant MFA and protect enrollment, recovery, and privileged sessions | MFA coverage, privileged-account review, session-revocation test |
| N | Narrow privilege and movement | Remove standing access and segment critical identity, backup, and management systems | Access review, segmentation test, denied-path evidence |
| S | Safeguard recovery | Maintain isolated or immutable copies and restore critical services on a clean path | Successful restore record, measured recovery time, protected deletion rights |
| O | Observe behavior and exfiltration | Correlate identity, endpoint, network, cloud, and data-movement signals | Tested alert, retained logs, triage owner, escalation timeline |
| M | Measure readiness | Exercise the incident plan and retest material attack paths after remediation | Tabletop record, attack-path findings, closed actions, validated retest |
The framework deliberately avoids a product checklist. Every priority ends with evidence, because a configured control can still fail through missing coverage, excessive privilege, poor integration, or an untested response dependency.
| Time | Priority actions | Owners | Completion evidence |
|---|---|---|---|
| Days 0–30 | Identify critical services and data; inventory exposed assets; enforce strong MFA on remote and privileged access; close urgent known-exploited paths; verify emergency contacts | Executive sponsor, IT, identity, vulnerability management | Approved critical-service list, exposure register, MFA coverage, remediation evidence |
| Days 31–60 | Reduce standing privilege; segment identity, management, and backup systems; centralize key logs; create exfiltration and recovery-tampering detections; test one critical restore | Security engineering, infrastructure, SOC, backup owner | Access review, segmentation result, alert test, restore time and integrity record |
| Days 61–90 | Run a ransomware and data-theft tabletop; simulate one realistic attack path under written rules; close findings; verify reporting, legal, insurance, and communications decisions | Incident lead, legal, communications, business owners, testing team | Exercise report, validated findings, decision log, remediation owners and deadlines |
The plan should be risk-ranked. A public VPN, exposed file-transfer platform, identity provider, hypervisor, backup console, or vendor connection may deserve attention before lower-impact internal findings. Record exceptions with an owner, rationale, compensating control, and expiration date.
Use a short, rehearsed incident response plan that the team can access when identity, email, or file systems are unavailable. Keep an offline contact list and define who can declare an incident, isolate systems, engage external support, and approve public statements.
The FBI does not support paying a ransom because payment does not guarantee data recovery and can encourage further crime. It asks victims to report incidents to a local field office or IC3; the current FBI ransomware guidance also provides baseline preparation and reporting steps.
Payment decisions can create legal and sanctions exposure in addition to operational, ethical, and insurance issues. Organizations should involve qualified counsel and relevant authorities; the U.S. Treasury’s ransomware payments advisory explains potential sanctions risk and factors OFAC may consider. This article is not legal advice and does not provide negotiation or payment instructions.
A tabletop exercise tests decisions, roles, communications, and dependencies. A restore test measures whether recovery works. Vulnerability management reduces known exposure. None of these alone proves that controls can stop or detect a multi-step intrusion.
A scoped red team engagement can test whether an authorized team can reach a defined business objective across identity, cloud, people, applications, and internal trust boundaries before defenders detect and contain it. The exercise needs explicit rules, safety controls, and success criteria.
A penetration test is better when the question is bounded: can specific internet-facing systems, applications, APIs, cloud resources, or infrastructure be exploited within an agreed scope? Neither engagement guarantees security, and both should end with remediation ownership and retesting.
Useful outcome measures include:
Qilin ranked first in Check Point Research’s Q2 2026 data with 279 organizations named on leak sites. The Gentlemen was close behind with 269 and ranked first during June alone. The answer depends on the period and tracker, so it should always be stated with the dataset and cutoff.
There is no defensible universal answer. “Dangerous” could mean victim volume, technical capability, payment success, business disruption, sector relevance, or ability to exploit one widely used platform. Qilin led Q2 public posts, while campaign-driven actors such as Cl0p demonstrate why a lower quarterly count can still create concentrated risk.
No. A leak-site post is a claim by a criminal actor. It may later be confirmed, partly confirmed, disputed, duplicated, or remain unverified. Leak-site datasets also miss incidents that are resolved privately, never published, or handled by groups without a monitored site.
Current quarterly research describes RansomHub as retired in 2025. Its disappearance did not eliminate the underlying threat because affiliates and access can move to other operations. A 2026 ranking should discuss RansomHub as an ecosystem transition, not as a current top group.
Backups reduce recovery risk, but they do not prevent credential theft, data exfiltration, operational disruption, or extortion. Backups also fail when attackers can delete them or when restoration has never been tested. Protect deletion rights, separate backup administration, monitor changes, and verify full-service recovery.
The FBI does not support payment, and paying does not guarantee recovery or non-disclosure. A payment may also create sanctions, legal, regulatory, ethical, and insurance issues. If an organization faces an extortion decision, it should involve qualified incident response, legal counsel, its insurer where applicable, and relevant authorities.
The most useful 2026 ransomware ranking is not a permanent blacklist. It is a time-bounded signal showing where public extortion activity is concentrated and how quickly the ecosystem can reorganize.
Use the names to inform intelligence, but build readiness around the attack paths that survive every rebrand: exposed systems, stolen identities, excessive privilege, weak segmentation, undetected data movement, recoverable evidence, and tested restoration. Then measure whether those controls work before an adversary makes the test real.
Mohammed Khalil is a Cybersecurity Architect at DeepStrike, specializing in advanced penetration testing and offensive security operations. With certifications including CISSP, OSCP, and OSWE, he has led numerous red team engagements for Fortune 500 companies, focusing on cloud security, application vulnerabilities, and adversary emulation. His work involves dissecting complex attack chains and developing resilient defense strategies for clients in the finance, healthcare, and technology sectors.

Stay secure with DeepStrike penetration testing services. Reach out for a quote or customized technical proposal today
Contact Us