Skip to content
AI Tech

AI Fuels Record Surge In Ransomware Attacks Q2 2026

Cybersecurity · AI Threats

Ransomware Hit a New Record in Q2 2026 — and AI Is Now Part of the Extortion Process

2,279 victims. 91 active groups. 108 countries. GuidePoint Security’s Q2 2026 threat report confirms ransomware is not plateauing — and that attackers are now using AI to increase pressure on victims once data has already been taken.

Published July 13, 2026 By Mr Wangdoo Sources verified July 13, 2026 9 min read

How this was reported: All statistics in this article are drawn directly from the GRIT Q2 2026 Ransomware and Cyber Threat Insights Report, published by GuidePoint Security on July 9, 2026 via Business Wire. All named quotes are reproduced verbatim from the official press release. A separate agentic ransomware case that broke the same week is referenced briefly for context only. No product is promoted here.

The Q2 2026 Numbers

GuidePoint Security’s Research and Intelligence Team — known as GRIT — published its Q2 2026 Ransomware and Cyber Threat Insights Report on July 9. Most people outside cybersecurity circles missed it. The headline figure: 2,279 organisations publicly claimed as ransomware victims in a single quarter. That’s up 43% on Q2 last year. Weekly postings never dropped below 150 — not once across the full three months.

SANS Institute: Stay Ahead of Ransomware — July 2026. Certified instructors Ryan Chapman and Mari DeGrazia on current attacker tactics and what defenders need to know. Independent production, not affiliated with Wangdoo.

GRIT collects this data from public leak sites — the dark web pages ransomware groups use to name and shame non-paying victims — as well as dark web forums, vendor threat intelligence, and direct incident response case data. The count is, by definition, a floor. Organisations that paid and were never listed publicly do not appear in these numbers.

2,279Ransomware victims claimed in Q2 2026 — never below 150 per week
+43%Year-on-year increase vs Q2 2025
91Active ransomware groups — the highest number ever recorded by GRIT
108Countries with confirmed ransomware operations this quarter

The 91 active groups figure is the one worth pausing on. Ransomware is not consolidating around a few dominant players — it is fragmenting. GRIT’s 91 is the highest number they have ever recorded across any reporting period. What that means in practice: even organisations that would not have been on a large group’s target list two years ago are now in scope for smaller, newer operations looking to build a track record.

What AI Is Actually Being Used For

The AI angle in this report is easy to misread. This is not primarily about AI autonomously compromising networks — that is a separate, narrower story. What GRIT documented is more routine and, from a risk management perspective, more immediately relevant: ransomware operators are using large language models to do their post-breach work faster.

Specifically, GRIT found three ways AI is being applied once data has already been taken:

  • Analysing exfiltrated data at scale. After a breach, attackers need to know which stolen files carry the most leverage — contracts, HR records, client lists, financial data. Doing this manually across thousands of documents takes days. An LLM can surface the highest-value material in minutes, giving operators a faster path to a credible threat.
  • Personalising ransom demands. A demand that references your specific executives, your specific contracts, or your specific regulatory exposure is harder to dismiss than a generic payment request. AI makes it practical to customise at scale rather than send identical messages to every victim.
  • Generating structured extortion documents. GRIT noted operators producing formatted tables — essentially a ledger of what was taken, its assessed value, and the consequences of non-payment. The presentation is deliberate: it is designed to make the threat feel processed and inevitable rather than opportunistic.
“AI is giving threat actors a faster path from stolen data to negotiation leverage. They can tailor their pressure on victims and professionalize negotiations without needing a major leap in capability. That changes how organizations need to prepare for extortion.” — Grayson North, Principal Threat Intelligence Consultant, GuidePoint Security (verbatim, GRIT Q2 2026 Report press release, July 9, 2026)

North’s phrase “without needing a major leap in capability” is worth holding onto. AI is not producing a new class of technically elite attacker. It is lowering the operational floor — making it practical for less sophisticated operations to run extortion campaigns that previously required experienced negotiators and manual research time.

Who Is Being Targeted

Manufacturing has sat at the top of GRIT’s most-targeted industry rankings for several consecutive years. Q2 2026 is no exception — nearly 15% of all claimed victims were manufacturers. The sector’s vulnerability comes from a combination of factors: legacy IT systems that are difficult to patch without operational disruption, high downtime costs that intensify pressure to resolve incidents quickly, and security budgets that have historically lagged behind finance and healthcare.

Top ransomware groups — Q2 2026

Qilin remained the most active group for the quarter. The Gentlemen continued its rapid ascent into second place — a relatively new group that has scaled quickly since mid-2025. DragonForce broke into the top three for the first time. Together, the five most prolific groups claimed more than 40% of all recorded attacks in Q2.

Why a Backup Is No Longer Enough on Its Own

For years, the standard ransomware defence advice has been: keep good, tested, offline backups, and you can recover without paying. That advice is still valid as far as it goes. The problem is that it no longer goes far enough.

The shift from encryption to extortion

Ransomware groups are increasingly stealing data before triggering any encryption. The ransom demand then carries two threats: you will not get your files back, and your data will be published publicly. A clean backup addresses the first threat. It does nothing about the second. GRIT’s Q2 report explicitly flags that data extortion is gaining ground over file encryption as the primary leverage mechanism — which means restoring from backup no longer removes the pressure.

North’s second quote from the report puts this directly: “attackers are finding leverage that a system restore cannot erase.” Pair that with the AI angle above — if operators can now identify and document your most sensitive data within hours of a breach — and the gap between a backup strategy and a complete incident response posture becomes clear.

Cloud, SaaS, and Supply Chains

Two further trends flagged in the Q2 report: supply chain attacks and SaaS integration attacks are both escalating. In both cases the approach is the same — rather than targeting a hardened enterprise directly, operators go through a vendor or third-party tool that already has authorised access to it. One security control gap in the supply chain becomes exposure for every customer downstream.

A newly identified group named FulcrumSec, focused specifically on cloud infrastructure, made its first appearance in the Q2 data. Most established ransomware operations have concentrated on on-premises environments where file encryption is more straightforward. FulcrumSec’s presence in the data indicates that operators are actively building techniques for cloud-hosted environments — organisations that moved workloads to the cloud partly for resilience reasons now need to account for this in their threat modelling.

My Take — Mr Wangdoo

I read a lot of quarterly threat reports. Most of them tell you roughly the same thing in different fonts. This one has two findings that I think genuinely change the practical picture for anyone responsible for security decisions.

The first is the AI-in-extortion development. Not because it is technically surprising — anyone who has spent time with a capable LLM can see how useful it would be for this kind of data triage — but because it compresses the timeline between breach and credible threat. The window that organisations have previously used to assess what was actually taken, and therefore how seriously to treat the demand, just got shorter. That is a concrete operational change, not a hypothetical one.

The second is the FulcrumSec cloud finding. The assumption that cloud migration reduces ransomware exposure has never been fully solid, but it has had some basis in the way traditional ransomware tooling works. A group specifically developing cloud-targeting techniques changes that calculus. Worth noting for anyone in the middle of a cloud migration who has been treating reduced ransomware exposure as a side benefit.

On the 2,279 number itself: take it as a direction indicator, not a precise count. It captures organisations publicly named by operators — those that paid quietly, or where the attacker chose not to publish, are not in there. The real volume is higher. What the number does reliably reflect is that Q2 2026 was worse than Q2 2025 by a substantial margin, and there is nothing in the data suggesting that changes in Q3.

Frequently Asked Questions

What is GRIT and how do they count ransomware victims?

GRIT is GuidePoint Security’s Research and Intelligence Team. They track ransomware activity by monitoring public leak sites — pages ransomware groups maintain to publish stolen data from non-paying victims — alongside dark web forums, vendor threat research, and internal incident response cases. Their victim count reflects organisations that have been publicly named. Companies that paid a ransom and were quietly removed from the attacker’s list do not appear in GRIT’s figures, so the published count is a minimum, not a total.

How exactly are ransomware operators using AI right now?

According to the Q2 2026 GRIT report, operators are using large language models for three tasks after a breach: rapidly sorting through stolen files to identify the highest-value material for leverage; crafting personalised ransom demands that reference specific company details rather than sending generic messages; and producing structured extortion documents that present the data theft formally, with itemised data categories and stated consequences. This is post-breach operational use, not AI-assisted network compromise.

Why does manufacturing keep topping the ransomware target list?

Three overlapping factors: legacy operational technology and IT environments that are hard to patch without halting production; very high downtime costs that put pressure on organisations to resolve incidents quickly; and historically lower cybersecurity investment than comparable sectors. Manufacturing accounted for nearly 15% of all Q2 2026 ransomware victims in GRIT’s data — a pattern consistent across multiple consecutive quarters.

If I have good backups, am I protected?

Backups protect you from the encryption side of a ransomware attack — they let you restore systems without paying for a decryption key. They do not protect you from the data-theft side. If operators exfiltrated data before encrypting, they can still threaten to publish it regardless of whether you restore from backup. GRIT’s Q2 report notes that data extortion is increasingly the primary leverage mechanism, which means backup strategy alone is an incomplete response to modern ransomware incidents.

What is FulcrumSec?

A newly identified ransomware group that appeared in GRIT’s Q2 2026 data for the first time. Unlike most established ransomware operations that focus on on-premises environments, FulcrumSec targets cloud infrastructure specifically. Its emergence suggests operators are actively developing techniques for organisations that have migrated workloads to cloud platforms.

Where can I read the full GRIT Q2 2026 report?

GuidePoint Security has made the full report available for download at guidepointsecurity.com. The official press release with key findings is also available via Business Wire.

Sources

Mr Wangdoo

Clayton Samuel (Mr Wangdoo), QFA

Founder and editor, Wangdoo.com. Qualified Financial Adviser with a background in electronics, web development, and cloud infrastructure. This article is based on GuidePoint Security’s official Q2 2026 GRIT report. No interviews were conducted. No product is promoted.