惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

D
Docker
博客园 - 三生石上(FineUI控件)
Cyber Security Advisories - MS-ISAC
Cyber Security Advisories - MS-ISAC
博客园_首页
Microsoft Azure Blog
Microsoft Azure Blog
GbyAI
GbyAI
腾讯CDC
酷 壳 – CoolShell
酷 壳 – CoolShell
M
MIT News - Artificial intelligence
Stack Overflow Blog
Stack Overflow Blog
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
Jina AI
Jina AI
爱范儿
爱范儿
博客园 - 【当耐特】
雷峰网
雷峰网
S
SegmentFault 最新的问题
美团技术团队
Blog — PlanetScale
Blog — PlanetScale
The GitHub Blog
The GitHub Blog
有赞技术团队
有赞技术团队
G
Google Developers Blog
大猫的无限游戏
大猫的无限游戏
Google DeepMind News
Google DeepMind News
J
Java Code Geeks

Check Point Blog

Reading the Signals in the OWASP LLM Top 10 2026 - Check Point Blog July 2026 Cyber Threats Surge: Ransomware Attacks Double Year over Year as GenAI Data Exposure Widens - Check Point Blog State Sponsored Hackers Use Fake Job Offers to Deliver New Zero Day Exploit - Check Point Blog Lazarus Hackers Exploit Windows Zero-Day in Fake Job Scam Native AI Security Comes to Claude: Why Anthropic's Inference Hooks Matter - Check Point Blog Claude AI Security: How Anthropic Inference Hooks Enable Real-Time Protection The Top Exposure Management Questions Security Leaders Ask (Part 1) - Check Point Blog Black Hat 2026: Check Point Research Takes the Stage - Check Point Blog Check Point Joins the Open Secure AI Alliance to Advance Open, Measurable and Enterprise-Ready AI Security - Check Point Blog Three AI security disclosures, fourteen days: what the warnings signs are telling us - Check Point Blog When Data Becomes Instructions: AI Agents Need a Chain of Custody for Context - Check Point Blog Your VLAN Isn’t an Air Gap: Six Hard Truths From the New CI Fortify Guidance - Check Point Blog Check Point Named a Visionary Leader in the 2026 Frost Radar™ for Enterprise Risk Mitigation and Management Platforms - Check Point Blog AI Escaped a Sandbox. That is Not What Should Worry You - Check Point Blog Introducing the Industry's First AI Network Firewall - Check Point Blog Attackers Are Turning Microsoft's Trusted Login System Into Their Latest Phishing Weapon - Check Point Blog AI Agent Security Just Had Its Catalyst Moment - Check Point Blog Your AI Governance Policy Should Survive Your Next Model Change - Check Point Blog The Branding and Attribution Behind Cybercrime - Check Point Blog Which Brands Are Impersonated Most? Inside the Q2 2026 Brand Phishing Report - Check Point Blog Security Advisory - Action Required - July 2026 Security Update - Check Point Blog What the 2026 Exposure Gap Report Reveals About Remediation - Check Point Blog Inline Email Security and Microsoft 365: A Practical View of Mail Routing, Risk, and Prevention - Check Point Blog The State of Hybrid SASE: Built-In vs. Bolted-On - Check Point Blog AI Appreciation Day: Let's Be Honest About What We're Appreciating - Check Point Blog AI Security Is Never Finished: Building the Continuous Red Teaming Loop  - Check Point Blog AI Security Threats in 2026: Annual Insights from Check Point Research - Check Point Blog AI Agents are Only As Effective as Their Harness - Check Point Blog Email Agent Hijacking: The Hidden Threat That Breaks Post-Delivery Security - Check Point Blog How Check Point Email Security Stopped a Student Job Scam Before It Reached the Inbox - Check Point Blog Redefining the CISO Contract: From Securing the Business to Securely Doing Business - Check Point Blog A New Ransomware Leader Emerges as June 2026 Attack Volumes Climb Worldwide
Ransomware Didn't Slow Down in Q2 2026. It Just Spread Ou...
Check Point Team · 2026-08-13 · via Check Point Blog

Ransomware kept its grip on organizations through the second quarter of 2026, and the headline number barely moved. What changed underneath that number is more interesting: new research gave us a rare look inside a top tier operation as it was being built, and it revealed just how little it now takes for a small and skilled group to reach the top of the field. Here’s what the quarter actually showed, and what it means for how you defend against it. 

Key takeaways 
  • Data leak sites recorded 2,139 ransomware victims in Q2 2026, essentially flat versus Q1 and up 33% year over year
  • The top 10 groups still controlled 57.6% of all victims, but the number of active groups jumped from 71 to 93, a new high
  • Leaked chats from The Gentlemen ransomware operation showed how a core team of roughly nine people, aided by AI coding tools, built a top three global operation in a matter of months
  • Ransom payment rates fell to about 23%, yet on chain ransomware payments still topped $820 million in 2025, pushing operators toward data theft over encryption
  • Defending against this shift means treating initial access, exfiltration, and exposure reduction as equally urgent
What actually happened in Q2 2026? 

Data leak sites, where ransomware groups publish victims who refuse to pay, logged 2,139 victims in Q2, essentially flat against Q1 and up 33% year over year. The ecosystem is holding at the elevated baseline it settled into through 2025. 

What shifted is who’s doing the attacking. In Q1, the top 10 groups controlled 71% of victims across just 71 active groups, a tight, top heavy market. By Q2, that eased to 57.6%, and active groups climbed to 93, the highest on record. Cl0p, whose Oracle E-Business Suite campaign drove much of Q1’s numbers, nearly vanished, and a wider mid tier filled the gap. Qilin held the top spot for a fourth straight quarter with 279 victims, narrowly ahead of The Gentlemen, which grew 62% and outpaced Qilin in June. 

Figure 1 – Total Number of Reported Ransomware Victims in data leakage websites, per month
(June 2024 – June 2026)

Figure 2 – Top-10 share and active group count, Q2 2026

What did the leaked Gentlemen chat logs actually reveal? 

A leak of The Gentlemen’s own backend and chat history, giving researchers a rare inside view of a top tier operation. The core team was just nine people, running a 90/10 split with a broader affiliate base that carried out most of the intrusion work, the highest cut advertised in the market. 

The detail worth remembering: the group’s admin, Zeta88, built the operation’s ransomware management panel in about three days using AI coding assistants, with a candid admission that the tools still require someone who understands the code well enough to guide and correct it. That’s genuine evidence AI is speeding up how ransomware tooling gets built, though its use here was about writing software faster, not running operations or picking targets. The bigger signal: the barriers to building a serious ransomware business have narrowed enough that one experienced operator can reach the top tier in months. 

Figure 3 – The Gentlemen monthly victim trajectory, Sep 2025 – Jun 2026

Why does data theft matter more than encryption right now? 

Payment rates have fallen for six straight years, from 85% in 2019 to roughly 23% today, largely because backups have gotten better at neutralizing encryption. Backups don’t help against data theft, though. If files are already stolen and about to be published, restoring systems doesn’t stop the leak, which is why operators are leaning into exfiltration first extortion. Total dollars paid haven’t followed payment rates down: on chain payments still exceeded $820 million in 2025. 

Law enforcement spent the quarter chasing shared infrastructure rather than individual groups, dismantling a laundering platform, sanctioning exchanges tied to ransomware actors, and taking down a malware signing service and major infostealer networks. None of that shows up as a drop in Q2’s victim count, and seized infrastructure tends to get rebuilt elsewhere, but raising the cost of laundering, signing, and credential harvesting adds friction that compounds over time. 

What should defenders actually prioritize? 

A few things fall out of the quarter’s data. Initial access remains the fight that matters most: The Gentlemen’s own pipeline ran on VPN scanning, brute forcing, and brokered credentials, the same route used across most of the ecosystem, so phishing and exposed remote access deserve defense in proportion to how often they’re the opening move. Exfiltration detection now deserves the same weight backup and recovery has traditionally received, and remediation speed matters more too, since the gap between disclosure and exploitation is now measured in hours. Defenses still running on a human review cycle are working against AI assisted tooling that no longer waits for one. 

How does Check Point address what this Ransomware quarter found? 

Most of what this report documents starts with a person, usually through phishing or stolen credentials feeding the same pipeline The Gentlemen relied on. Workspace Security protects users across email, browsers, SaaS applications, and endpoints, using AI driven detection to stop ransomware delivery before execution and limit lateral movement and exfiltration after a compromise. 

Hybrid Mesh Network Security applies consistent, AI driven controls at every connectivity point, from firewalls that block malicious files before they reach devices to CASB scanning that catches malware entering through SaaS platforms like OneDrive and Slack, a route access brokers increasingly favor. If a compromise happens anyway, Zero Trust access through SASE Private Access limits the blast radius so ransomware can only reach what the compromised user was authorized to touch. 

Exposure Management answers the harder question of which vulnerabilities ransomware groups can actually reach and use, not just which ones exist. Check Point’s 2026 Exposure Gap Report found vulnerabilities now make up 42.6% of critical exposures, more than double the year before, and that they can realistically be closed in under an hour, with utilities sector organizations using the platform resolving 30% of theirs within that window. 

AI Security addresses the same tooling ransomware groups are learning to use. ThreatCloud AI keeps protection moving on the same accelerated timeline as AI assisted exploitation, AI Agent Security governs the agent permissions that let an admin like Zeta88 build tooling in days, AI Red Teaming tests an organization’s own AI applications before deployment, and Workforce AI Security stops credentials and data from leaking through the AI tools employees already use. 

Want the full picture? Download the complete State of Ransomware Q2 2026 report here.