IntelliOS Threat Intel Operating System
IntelliOSRolling Intelligence|AIRolling Coveware Intelligence Watch

Coveware Ransomware Rolling Intelligence Card

AI-generated, AI-updated weekly, AI quality-checked, and source-cited, this one-year Rolling Intelligence Card turns Coveware by Veeam’s first-hand ransomware casework into executive intelligence on payment decisions, threat-actor communications, access methods, extortion economics, victimology, decryption reliability, and recovery risk. Coveware controls Coveware-specific claims; peer incident-response research is retained only as clearly labeled supplemental context.

Coverage
Sep 13, 2025–Sep 12, 2026
Record Version
v12
Updated
Sep 7, 2026
AI Monitor
Weekly · Mon 1:00 PM ET
Evidence
9 Retained Sources
Product
Rolling Intelligence Card
Classification
TLP:CLEAR

Research Framing

Reporting-Period Statistics

Rolling 1-Year Intelligence Snapshot

At-a-glance measures from the retained evidence set. Citations identify the source controlling each statistic.

Period Coverage

Sep 13, 2025Sep 12, 2026

365 calendar days, inclusive. Records are included by their first-observed date inside this window; the period does not imply that every underlying incident began or was confirmed during it.

365-day windowWeekly on Monday at 1:00 PM ET

23%[5]

Q1 2026 payment rate

Cited in Coveware’s Q1 2026 quarterly ransomware report; Coveware-managed cases only.Evidence dated Apr 30, 2026

$680,081[5]

Q1 average payment

Cited in Coveware’s Q1 2026 quarterly ransomware report; up 15% from Q4 and skewed by large settlements.Evidence dated Apr 30, 2026

$300,750[5]

Q1 median payment

Cited in Coveware’s Q1 2026 quarterly ransomware report; down 7% from Q4.Evidence dated Apr 30, 2026

79%[5]

Q1 lateral movement

Cited in Coveware’s Q1 2026 quarterly ransomware report as its most frequently observed Q1 tactic.Evidence dated Apr 30, 2026

73%[5]

Q1 exfiltration

Cited in Coveware’s Q1 2026 quarterly ransomware report across encryption and extortion cases.Evidence dated Apr 30, 2026

[5]

SMB/mid-market concentration

Cited in Coveware’s Q1 2026 quarterly ransomware report for the 11–100 and 101–1,000 employee bands.Evidence dated Apr 30, 2026

Evidence-Prioritized Access Paths

Top Initial Access & Account-Takeover Vectors

Coveware’s Q3 2025, Q4 2025, and Q1 2026 quarterly ransomware reports do not publish a complete percentage table for every entry path in the rendered text. The order below is an evidence-ranked operational assessment, not a fabricated frequency ranking.

1

Primary observed class

Identity-backed remote access[1][4][5]First cited source Oct 24, 2025 · Latest cited source Apr 30, 2026

Dominant across Coveware’s Q3 2025, Q4 2025, and Q1 2026 quarterly reports

How it starts
Valid or replayed VPN, RDP, SaaS, SSO, token, API, connected-app, or administrative access.
Attacker outcome
Legitimate-looking persistence, privilege escalation, lateral movement, exfiltration, and impact.
What to monitor
New devices or geographies, stale accounts, impossible travel, unusual admin sessions, token use, delegated access, and dormant-account activation.
2

Human-enabled identity compromise

Help-desk and identity-recovery social engineering[1][4][5]First cited source Oct 24, 2025 · Latest cited source Apr 30, 2026

Coveware’s quarterly reports often absorb this into the eventual remote-access outcome

How it starts
Impersonation, vishing, MFA reset, password reset, new enrollment, or support-assisted access.
Attacker outcome
A provisioned or recovered account that appears legitimate.
What to monitor
Reset reason, caller validation, new MFA factor, privileged role change, unusual support tickets, and follow-on data access.
3

Lower-frequency, high-consequence

Software vulnerability exploitation[1][4][5]First cited source Oct 24, 2025 · Latest cited source Apr 30, 2026

Coveware’s three quarterly reports describe a slow upward drift across casework

How it starts
Exploitation of internet-facing appliances, management planes, enterprise applications, or residual migration exposure.
Attacker outcome
Fast access to data theft, lightweight encryption, or privileged control.
What to monitor
Externally reachable assets, patch lag, known exploitation, leftover accounts, incomplete migrations, and management-plane telemetry.
4

Cloud trust-path compromise

OAuth and connected-application abuse[4][5]First cited source Feb 3, 2026 · Latest cited source Apr 30, 2026

Included within modern remote access in Coveware’s Q4 2025 and Q1 2026 reports

How it starts
Malicious consent, stolen refresh token, delegated trust, or compromised integration.
Attacker outcome
Durable platform-native access with limited endpoint indicators.
What to monitor
New grants, scope expansion, rare application IDs, token replay, admin consent, and access after password reset.
5

Trusted relationship compromise

Third-party and inherited trust[4][5]First cited source Feb 3, 2026 · Latest cited source Apr 30, 2026

Recurring enabler in cloud and service workflows

How it starts
Compromised vendor identity, integration, service account, or shared administration path.
Attacker outcome
Access across organizational boundaries and downstream customer environments.
What to monitor
Vendor sessions, service-account changes, delegated privileges, cross-tenant access, and emergency access paths.

Intended Reader and Decision Context

Persona / Audience

Who this brief is written for, the geographic and organizational lens it uses, and how readers should apply the intelligence.

Audience fieldPrimary audienceAssessmentExecutives, boards, CISOs, CIOs, incident commanders, breach counsel, cyber insurers, finance leaders, recovery owners, and ransom-decision teams.
Audience fieldOrganization profileAssessmentU.S.-oriented but globally relevant; useful to SMB, mid-market, enterprise, healthcare, consumer services, professional services, financial services, public-sector, managed-service, and data-rich organizations.
Audience fieldDecision useAssessmentPreparedness, identity and remote-access control, patch prioritization, business-continuity design, threat-actor engagement, payment exception analysis, sanctions and legal coordination, decryption validation, and recovery planning.
Audience fieldReading standardAssessmentPlain English for executives, with enough technical specificity for responders. Statistics remain bounded to Coveware-managed cases and peer evidence is explicitly marked supplemental.

Chronology and Decision Milestones

Timeline of Notable Activity

Coveware publication dates, underlying case quarters, threat-actor communications, payment decisions, technical analyses, and recovery observations are separated. Peer reports remain supplemental and methodologically distinct.

  1. Q3 2025 quarterly ransomware report

    Q3 payment rates reach a record low

    Coveware’s Q3 2025 report, “Insider Threats Loom while Ransom Payment Rates Plummet,” reported a 23% overall payment rate and 19% for data-theft-only incidents. Average payment fell to $376,941, median to $140,000, and Akira represented 34% of Coveware-observed variants.[1]

  2. Coveware technical blog

    Obscura proves a valid decryptor may still be useless

    Coveware’s “Obscura Ransomware: A Case Study in Ransomware Data Loss” blog reported that Obscura fails to write required key material to files larger than 1 GB, making those files permanently unrecoverable even after payment.[2]

  3. Coveware technical blog

    Nitrogen’s ESXi flaw creates irreversible corruption

    Coveware’s “Nitrogen Ransomware: ESXi malware has a bug!” blog reported that the ESXi encryptor uses the wrong public key, so the actor cannot provide a working recovery key.[3]

  4. Q4 2025 quarterly ransomware report

    Q4 report finds mass data-extortion economics weakening

    Coveware’s Q4 2025 report, “Why Zero-Day Downstream Mass Data Extortion Campaigns are Losing Their Bite,” reported that large downstream campaigns produced little payment leverage, while average and median payments rose to $591,988 and $325,000 because isolated severe business-interruption cases skewed the distribution.[4]

  5. Supplemental market context

    GuidePoint reports elevated but stable ransomware volume

    GRIT reported roughly 150–200 victim posts per week in Q1 2026. This is supplemental public-ecosystem context, not Coveware casework.[6]

  6. Q1 2026 quarterly ransomware report

    Q1 report centers identity, business interruption, and compressed patch windows

    Coveware’s Q1 2026 report, “Patch management goes from hard, to ludicrous in the agentic AI era,” reported a 23% payment rate, $680,081 average payment, $300,750 median, remote-access and identity-backed entry, 79% lateral movement, 73% exfiltration, and a two-thirds concentration in organizations with 11–1,000 employees.[5]

  7. Supplemental market context

    GuidePoint Q2 confirms high external victim-post volume

    GRIT counted 2,279 reported ransomware victims in Q2 2026, up 7% quarter over quarter and 43% year over year. It is retained only as a supplemental external-volume comparator.[7]

  8. IntelliOS publication

    Coveware monitor consolidated into a weekly Rolling Intelligence Card

    The former quarterly email-only monitor was deprecated. Its subscriber identity was retained, while publication, weekly monitoring, change history, and Page Alerts now live on this rolling one-year product.[1][2][3][4][5]

Bottom Line Up Front

BLUF

Coverage periodSep 13, 2025Sep 12, 2026365 calendar days, inclusiveUpdated Sep 7, 2026
  • Nonpayment is now the baseline, not an exceptional outcome: Coveware’s Q3 2025 and Q1 2026 quarterly ransomware reports each reported a 23% overall payment rate, with data-theft-only payment rates structurally lower. Executives should treat payment as an exception requiring a documented, evidence-based business case.[1][5]First cited source Oct 24, 2025 · Latest cited source Apr 30, 2026

  • The average ransom payment is a poor stand-alone planning number: Coveware’s Q1 2026 quarterly ransomware report cited a $680,081 average and $300,750 median. The gap reflects a small number of large settlements and should not be used as a simple expected-loss assumption.[4][5]First cited source Feb 3, 2026 · Latest cited source Apr 30, 2026

  • Business interruption—not a promise to delete stolen data—still creates the strongest payment pressure: Coveware’s Q4 2025 and Q1 2026 quarterly ransomware reports say encryption-led groups convert more payments because outages create immediate operational leverage, while data-theft-only promises are unverifiable and vulnerable to re-extortion.[4][5]First cited source Feb 3, 2026 · Latest cited source Apr 30, 2026

  • Identity is the primary intrusion surface: Across Coveware’s Q3 2025, Q4 2025, and Q1 2026 quarterly reports, remote access includes SaaS administration, OAuth grants, SSO, connected apps, tokens, help-desk resets, VPN, RDP, and inherited trust—not merely a perimeter device.[1][4][5]First cited source Oct 24, 2025 · Latest cited source Apr 30, 2026

  • Payment cannot guarantee recovery: Coveware’s named Obscura and Nitrogen technical blogs demonstrate that defective ransomware can destroy data in ways no decryptor can reverse. Variant-aware validation must precede any recovery or payment decision.[2][3]First cited source Nov 19, 2025 · Latest cited source Feb 2, 2026

  • Coveware’s numbers are decision evidence, not global market totals: They describe Coveware-managed cases. IntelliOS uses GuidePoint only as supplemental external-volume context and does not blend the two methodologies.[1][4][5][6][7]First cited source Oct 24, 2025 · Latest cited source Jul 9, 2026

Decision Context

Executive Summary

Coverage periodSep 13, 2025Sep 12, 2026365 calendar days, inclusiveUpdated Sep 7, 2026

This Rolling Intelligence Card monitors Coveware because its public reports are based on first-hand ransomware and extortion cases, including threat-actor engagement, payment decisions, decryption, recovery, access, tactics, and victim characteristics. That makes the corpus especially valuable for management questions that leak-site counts alone cannot answer. It does not make the data a census of the full market; Coveware repeatedly limits its statistics to cases it handled.[1][4][5]First cited source Oct 24, 2025 · Latest cited source Apr 30, 2026

The central economic finding is a durable shift toward nonpayment. Coveware’s Q3 2025 quarterly ransomware report, “Insider Threats Loom while Ransom Payment Rates Plummet,” reported a historical-low 23% overall payment rate and 19% for data-theft-only cases. Its Q1 2026 quarterly report, “Patch management goes from hard, to ludicrous in the agentic AI era,” reported a 23% overall rate again. The implication is not that ransomware is harmless. It is that organizations increasingly resist payment when they can restore operations, understand what was taken, and accept that paying for an unverifiable deletion promise rarely eliminates notification, litigation, regulatory, or re-extortion risk.[1][4][5]First cited source Oct 24, 2025 · Latest cited source Apr 30, 2026

Payment amounts remain volatile. Coveware’s Q3 2025 report cited a $376,941 average and $140,000 median; its Q4 2025 report cited a $591,988 average and $325,000 median; and its Q1 2026 report cited a $680,081 average and $300,750 median. The rising average alongside a declining median in Q1 is a warning against simplistic budgeting: a handful of severe enterprise events can pull the average upward while the more typical paid case is materially lower.[1][4][5]First cited source Oct 24, 2025 · Latest cited source Apr 30, 2026

Threat actors are splitting between high-volume Ransomware-as-a-Service attacks against smaller and mid-market firms and more targeted, expensive operations against large enterprises. Coveware’s Q1 2026 quarterly ransomware report stated that the 11–100 and 101–1,000 employee bands accounted for two-thirds of attacks, while only 5% of victims had more than 100,000 employees. Ransomware therefore remains a broad operating risk, not a problem confined to globally prominent companies.[1][5]First cited source Oct 24, 2025 · Latest cited source Apr 30, 2026

Across Coveware’s Q3 2025, Q4 2025, and Q1 2026 quarterly ransomware reports, initial access is increasingly identity-backed. A modern “remote access compromise” can mean a valid VPN login, SaaS administrator session, OAuth grant, SSO token, connected application, delegated trust path, or help-desk-assisted reset. Phishing and social engineering still matter, but the successful outcome may be logged as remote access because the attacker ultimately operates through a legitimate identity and stays persistent.[1][4][5]First cited source Oct 24, 2025 · Latest cited source Apr 30, 2026

Coveware’s Q1 2026 quarterly ransomware report identified business interruption as the strongest payment pressure and cited lateral movement in 79% of cases, exfiltration in 73%, impact in 58%, command and control in 58%, and defense evasion in 52%. These are not abstract ATT&CK labels: together they describe an operator moving through legitimate administration paths, stealing data, disrupting operations, and degrading the evidence defenders need to make decisions.[5]Evidence dated Apr 30, 2026

Coveware’s “Obscura Ransomware: A Case Study in Ransomware Data Loss” and “Nitrogen Ransomware: ESXi malware has a bug!” technical blogs show why threat-actor assurances are not technical evidence. The Obscura analysis says the malware fails to preserve keys needed to decrypt files larger than 1 GB. The Nitrogen analysis says its ESXi encryptor used an incompatible key and could irreversibly corrupt virtual-machine data. A small “proof of life” file can therefore create false confidence; responders need variant-aware testing across representative file sizes, formats, workloads, and virtualization systems.[2][3]First cited source Nov 19, 2025 · Latest cited source Feb 2, 2026

The management response is a combination of identity governance, rapid patching of externally reachable and management-plane systems, resilient and tested recovery, fast containment of lateral movement, legal and insurer coordination, and a preapproved payment-exception process. Payment, if ever considered, should follow independent validation of recoverability and actor claims—not precede it.[1][2][3][4][5]First cited source Oct 24, 2025 · Latest cited source Apr 30, 2026

Executive Briefing Priorities

Top 10 Briefing Points

  1. 1

    Q1 2026 payment rate held at 23%Coveware’s Q1 2026 quarterly ransomware report cited a 23% payment rate, showing that low conversion persists even though ransomware remains operationally damaging.[5]Evidence dated Apr 30, 2026

  2. 2

    Q1 average rose while the median fellCoveware’s Q1 2026 quarterly ransomware report cited a $680,081 average versus a $300,750 median—a skewed distribution driven by large outliers.[5]Evidence dated Apr 30, 2026

  3. 3

    Identity-backed remote access dominatesCoveware’s Q4 2025 and Q1 2026 quarterly ransomware reports treat SaaS, OAuth, SSO, connected apps, admin sessions, tokens, VPN, and RDP as one converging access problem.[4][5]First cited source Feb 3, 2026 · Latest cited source Apr 30, 2026

  4. 4

    Lateral movement appeared in 79% of Q1 casesCoveware’s Q1 2026 quarterly ransomware report cited the 79% rate; containment speed and east-west visibility directly preserve recovery options.[5]Evidence dated Apr 30, 2026

  5. 5

    Exfiltration appeared in 73% of Q1 casesCoveware’s Q1 2026 quarterly ransomware report cited the 73% rate. Data theft remains an executive legal, regulatory, contractual, and reputational issue even when encryption is limited.[5]Evidence dated Apr 30, 2026

  6. 6

    Two-thirds of Q1 victims had 11–1,000 employeesCoveware’s Q1 2026 quarterly ransomware report cited this concentration, making the case mix directly relevant to SMB and mid-market organizations.[5]Evidence dated Apr 30, 2026

  7. 7

    Encryption-led groups retain stronger leverageCoveware’s Q4 2025 and Q1 2026 quarterly ransomware reports show that INC, Akira, and Qilin can create operational pressure that data-theft-only actors often cannot.[4][5]First cited source Feb 3, 2026 · Latest cited source Apr 30, 2026

  8. 8

    Mass downstream data extortion is converting poorlyCoveware’s Q4 2025 quarterly ransomware report cited sharply declining payment outcomes across MOVEit, Cleo, Oracle EBS, and similar campaigns.[4]Evidence dated Feb 3, 2026

  9. 9

    Decryption must be independently validatedCoveware’s Obscura and Nitrogen technical blogs show that even the attacker may be technically unable to restore data.[2][3]First cited source Nov 19, 2025 · Latest cited source Feb 2, 2026

  10. 10

    Peer leak-site volume remains elevatedGuidePoint GRIT’s Q2 2026 ransomware report provides supplemental evidence that low payment conversion does not equal low attack volume.[7]Evidence dated Jul 9, 2026

Source-Bound Exposure and Targeting

Victimology Matrix

This is not a raw victim list. Publicly named organizations are shown when reliable sources identify them, with confirmation and attribution boundaries preserved. Where no defensible name exists, IntelliOS uses the narrowest supported exposure population. Sector or geography matches remain scoping signals; they do not prove compromise.

Victim / exposure populationOrganizations with 11–100 employees[5]Evidence dated Apr 30, 2026SectorsCross-industryGeographyCoveware Q1 2026 quarterly-report case mix; not a global censusConfirmation statusCoveware’s Q1 2026 report says this tier, combined with the 101–1,000 tier, represented two-thirds of attacks.How companies should use itSmall organizations need tested recovery, identity controls, and ransom decision authority; they are not below attacker interest.
Victim / exposure populationOrganizations with 101–1,000 employees[5]Evidence dated Apr 30, 2026SectorsCross-industry mid-marketGeographyCoveware Q1 2026 quarterly-report case mixConfirmation statusCoveware’s Q1 2026 report places this tier inside the two-thirds concentration across organizations with 11–1,000 employees.How companies should use itPrioritize VPN/SaaS identity, remote administration, lateral-movement detection, backup isolation, and executive rehearsal.
Victim / exposure populationHealthcare[5]Evidence dated Apr 30, 2026SectorsHealthcareGeographyCoveware Q1 2026 quarterly-report case mixConfirmation statusCoveware’s Q1 2026 report cited 17.6% of impact, the largest named sector share.How companies should use itPlan for patient-care continuity, regulated-data exposure, high downtime pressure, and public-facing disruption.
Victim / exposure populationConsumer services[5]Evidence dated Apr 30, 2026SectorsConsumer servicesGeographyCoveware Q1 2026 quarterly-report case mixConfirmation statusCoveware’s Q1 2026 report cited 15.3% of impact.How companies should use itProtect customer data, identity and payment workflows, and high-volume operational services.
Victim / exposure populationProfessional and financial services[5]Evidence dated Apr 30, 2026SectorsProfessional services; financial servicesGeographyCoveware Q1 2026 quarterly-report case mixConfirmation statusCoveware’s Q1 2026 report cited 11.8% and 9.4% of impact respectively.How companies should use itTreat client records, financial statements, privileged files, and trusted SaaS access as extortion leverage.
Victim / exposure populationPublic-sector and must-operate organizations[5]Evidence dated Apr 30, 2026SectorsPublic sector and critical servicesGeographyCoveware Q1 2026 quarterly-report case mixConfirmation statusCoveware’s Q1 2026 report cited a 7.1% public-sector share; service interruption can create immediate public pressure.How companies should use itDefine shutdown, isolation, emergency communication, manual operation, and recovery authority before an incident.

Distinct Operational Records

Coveware-Observed Threat Actor Communications & Operations

High-volume Akira and Qilin RaaS operations

Coveware’s Q3 2025, Q4 2025, and Q1 2026 quarterly reports describe a volume-oriented model against mid-market organizations: lower demands, lower attacker cost, and comparatively higher payment propensity.[1][4][5]First cited source Oct 24, 2025 · Latest cited source Apr 30, 2026

CL0P downstream zero-day extortion

Coveware’s Q4 2025 quarterly ransomware report uses the Accellion, GoAnywhere, MOVEit, Cleo, and Oracle EBS sequence to show declining payment leverage as organizations improve scoping and reject unverifiable suppression promises.[4]Evidence dated Feb 3, 2026

ShinyHunters and Lone Wolf data-theft pressure

Coveware’s Q4 2025 and Q1 2026 quarterly reports say these labels represented meaningful case share, but data-theft-only models converted less reliably than encryption-led operations.[4][5]First cited source Feb 3, 2026 · Latest cited source Apr 30, 2026

Insider-recruitment and access-broker pressure

Coveware’s Q3 2025 quarterly ransomware report warned that lower actor profitability increases incentives to bribe or recruit insiders and exploit trusted workflows.[1]Evidence dated Oct 24, 2025

Source-Bound Actor Context

Threat Actors & Negotiation Behaviors

INC Ransom

Coveware’s Q1 2026 quarterly ransomware report placed INC Ransom in a tie for the largest case share at 13% and categorized it as encryption-focused, where business interruption can sustain payment leverage.[5]Evidence dated Apr 30, 2026

Akira

Coveware’s Q3 2025 report placed Akira at 34% of case share; its Q1 2026 report kept Akira among the top encryption-focused groups at 12%.[1][5]First cited source Oct 24, 2025 · Latest cited source Apr 30, 2026

Qilin

Coveware’s Q3 2025, Q4 2025, and Q1 2026 quarterly reports retained Qilin in the top tier and describe encryption plus exfiltration as compounding operational and data pressure.[1][4][5]First cited source Oct 24, 2025 · Latest cited source Apr 30, 2026

CL0P

Coveware’s Q4 2025 quarterly ransomware report describes CL0P as a downstream mass-data-theft specialist whose broad victim reach has not translated into durable payment conversion.[4]Evidence dated Feb 3, 2026

ShinyHunters

Coveware’s Q1 2026 quarterly ransomware report associated ShinyHunters with data-exfiltration-oriented campaigns and 8% of Coveware-observed cases; payment leverage remains weaker without operational disruption.[4][5]First cited source Feb 3, 2026 · Latest cited source Apr 30, 2026

Nitrogen and Obscura

Coveware’s named Nitrogen and Obscura technical blogs show that malware family and build quality can determine whether recovery is possible, independent of negotiation.[2][3]First cited source Nov 19, 2025 · Latest cited source Feb 2, 2026

Enterprise Exposure

Access Vectors, Malware & Recovery-Critical Technologies

SaaS, SSO, OAuth, APIs, and connected applications

Coveware’s Q4 2025 and Q1 2026 quarterly reports place these systems inside the remote-access attack surface, where they can provide durable identity-backed access with few endpoint signals.[4][5]First cited source Feb 3, 2026 · Latest cited source Apr 30, 2026

VPN, RDP, SSH, and administrative management paths

Coveware’s three quarterly reports retain legacy remote access as relevant, especially where stale credentials, incomplete migrations, or weak lifecycle controls persist.[1][4][5]First cited source Oct 24, 2025 · Latest cited source Apr 30, 2026

ESXi and virtualized workloads

Coveware’s Nitrogen technical blog shows that a defective encryptor can permanently corrupt this recovery-critical layer; its Q4 2025 report explains why virtualization concentrates business interruption.[3][4]First cited source Feb 2, 2026 · Latest cited source Feb 3, 2026

Internet-facing appliances and management planes

Coveware’s Q3 2025, Q4 2025, and Q1 2026 quarterly reports treat exploitation as less common than identity compromise but high consequence when patching, migration hygiene, or residual credentials fail.[1][4][5]First cited source Oct 24, 2025 · Latest cited source Apr 30, 2026

Large files, backups, and decryption tooling

Coveware’s Obscura and Nitrogen technical blogs show why representative validation must include large and critical file types; a small proof-of-life sample cannot establish recoverability.[2][3]First cited source Nov 19, 2025 · Latest cited source Feb 2, 2026

Current Carry-Forward Watchlist

Top 10 Specific Threats to Monitor

Prioritized Coveware-observed payment, actor-communication, identity, exploitation, recovery, victimology, and market signals that require a named monitoring owner.

1Threat / Category

Economics

Overall and data-theft-only payment rates[1][4][5]First cited source Oct 24, 2025 · Latest cited source Apr 30, 2026

Why it mattersCoveware’s Q3 2025, Q4 2025, and Q1 2026 quarterly reports show why payment propensity changes the actor economy and the defensibility of engagement advice.What to monitorEach new Coveware quarterly rate, impact scenario, historical revision, methodology, and denominator.IntelliOS coverage
2Threat / Category

Economics

Average and median payment divergence[1][4][5]First cited source Oct 24, 2025 · Latest cited source Apr 30, 2026

Why it mattersCoveware’s three quarterly reports show that large outliers can make the average unsuitable for budgets or expected-loss models.What to monitorAverage, median, quarter-over-quarter movement, paid-case mix, enterprise outliers, and business-interruption driver.IntelliOS coverage
3Threat / Category

Actor communications

Deletion promises, re-extortion, harassment, and deadlines[4][5]First cited source Feb 3, 2026 · Latest cited source Apr 30, 2026

Why it mattersCoveware’s Q4 2025 and Q1 2026 quarterly reports treat actor statements as negotiation pressure, not verified outcomes.What to monitorProof offered, contradictions, re-extortion, third-party contact, executive harassment, swatting threats, and data-release evidence.IntelliOS coverage
4Threat / Category

Identity

Remote access and support-assisted compromise[1][4][5]First cited source Oct 24, 2025 · Latest cited source Apr 30, 2026

Why it mattersCoveware’s three quarterly reports show that valid-looking access can persist after a password change.What to monitorOAuth grants, tokens, SSO, new MFA factors, help-desk resets, rare devices, VPN/RDP, connected apps, and service identities.IntelliOS coverage
5Threat / Category

Exploitation

Externally reachable appliances and management planes[1][4][5]First cited source Oct 24, 2025 · Latest cited source Apr 30, 2026

Why it mattersCoveware’s quarterly reporting shows that lower frequency does not mean lower consequence.What to monitorPatch latency, KEV status, exposure, residual accounts, partial migrations, admin interfaces, and exploit telemetry.IntelliOS coverage
6Threat / Category

Movement

Lateral movement and privileged administration[5]Evidence dated Apr 30, 2026

Why it mattersCoveware’s Q1 2026 quarterly ransomware report cited a 79% observation rate, making east-west containment a leading recovery control.What to monitorRDP, SSH, PsExec, admin shares, remote management, privilege changes, service creation, and cross-segment access.IntelliOS coverage
7Threat / Category

Recovery

Variant-specific encryption and decryptor reliability[2][3]First cited source Nov 19, 2025 · Latest cited source Feb 2, 2026

Why it mattersCoveware’s Obscura and Nitrogen technical blogs show that a payment decision is indefensible if the needed data cannot be technically restored.What to monitorMalware build, footer/key integrity, representative file sizes, ESXi impact, corrupted backups, and decryptor tests.IntelliOS coverage
8Threat / Category

Victimology

SMB and mid-market concentration[5]Evidence dated Apr 30, 2026

Why it mattersCoveware’s Q1 2026 quarterly ransomware report cited two-thirds of victims in the 11–1,000 employee bands.What to monitorCompany size, sector, downtime tolerance, identity maturity, backup independence, and decision authority.IntelliOS coverage
9Threat / Category

Market

Encryption-led versus data-theft-only group share[1][4][5]First cited source Oct 24, 2025 · Latest cited source Apr 30, 2026

Why it mattersCoveware’s Q3 2025, Q4 2025, and Q1 2026 reports distinguish pressure models that require different containment and decision priorities.What to monitorVariant ranking, encryption use, exfiltration, actor branding, affiliate behavior, and paid-case concentration.IntelliOS coverage
10Threat / Category

Supplemental

External victim-post volume[6][7]First cited source Apr 15, 2026 · Latest cited source Jul 9, 2026

Why it mattersGuidePoint GRIT’s Q1 and Q2 2026 reports show that public leak-site activity can remain high while Coveware-observed payment conversion falls.What to monitorGuidePoint quarterly victim posts, group count, sector shift, methodology, duplicates, and divergence from Coveware casework.IntelliOS coverage

Operational Standards from the Evidence

Best Practices and Lessons Learned

The practices below convert Coveware’s first-hand casework and technical analyses into repeatable ransomware preparedness, payment-decision, validation, containment, and recovery standards.

Coverage periodSep 13, 2025Sep 12, 2026365 calendar days, inclusiveUpdated Sep 7, 2026
  1. 1

    Best Practice

    Make nonpayment the prepared baseline[1][4][5]First cited source Oct 24, 2025 · Latest cited source Apr 30, 2026

    Lesson Learned

    Coveware’s Q3 2025, Q4 2025, and Q1 2026 quarterly reports show that low payment rates and weak data-deletion utility make payment a poor default incident plan.

    Minimum Operating Standard

    Require a documented exception approved by legal, executive, insurer, sanctions, recovery, and business owners after alternatives are independently tested.

  2. 2

    Best Practice

    Validate recoverability before negotiation economics[2][3]First cited source Nov 19, 2025 · Latest cited source Feb 2, 2026

    Lesson Learned

    Coveware’s Obscura and Nitrogen technical blogs show that the actor may be unable to restore data.

    Minimum Operating Standard

    Test representative file types, sizes, virtualization workloads, key/footer integrity, backups, and rebuild options with variant-aware expertise.

  3. 3

    Best Practice

    Treat identity as the control plane[1][4][5]First cited source Oct 24, 2025 · Latest cited source Apr 30, 2026

    Lesson Learned

    Coveware’s three quarterly reports show remote access spanning SaaS, OAuth, SSO, support workflows, tokens, VPN, RDP, and third-party trust.

    Minimum Operating Standard

    Maintain lifecycle governance, phishing-resistant MFA for privileged paths, token visibility, help-desk verification, connected-app review, and emergency revocation.

  4. 4

    Best Practice

    Contain lateral movement before impact[5]Evidence dated Apr 30, 2026

    Lesson Learned

    Coveware’s Q1 2026 quarterly ransomware report cited lateral movement in 79% of cases, a condition that determines whether the attacker reaches recovery-critical systems.

    Minimum Operating Standard

    Segment administration, detect east-west movement, restrict remote tooling, isolate quickly, and preauthorize disruptive containment.

  5. 5

    Best Practice

    Report averages with medians and denominators[1][4][5]First cited source Oct 24, 2025 · Latest cited source Apr 30, 2026

    Lesson Learned

    Coveware’s three quarterly reports demonstrate how averages can be dominated by a small number of extreme payments.

    Minimum Operating Standard

    Every executive statistic identifies the case population, quarter, mean, median, payment rate, impact scenario, and source methodology.

  6. 6

    Best Practice

    Preserve evidence through virtualization recovery[3][4][5]First cited source Feb 2, 2026 · Latest cited source Apr 30, 2026

    Lesson Learned

    Coveware’s Nitrogen technical blog and Q4 2025/Q1 2026 reports show how rebuilds and administrative lockouts can erase impact telemetry.

    Minimum Operating Standard

    Capture identity, hypervisor, network, EDR, cloud, backup, and management-plane evidence before destructive recovery where safety permits.

Automation Transparency

AI Agent Run Status

AgentCoveware Ransomware Rolling Intelligence Card Publisher
StatusActive · rolling one-year automation
CadenceWeekly on Monday at 1:00 PM ET
Previous run24 Jul 2026 · initial consolidation · Run coveware-activity-2026-07-24-initial
Previous resultPublished the initial one-year product and deprecated the separate quarterly email-only monitor.
What the previous run found
  • Retained both authoritative Coveware collection indexes and five in-window Coveware publications, including three quarterly reports.
  • Separated Coveware-managed case statistics from two supplemental GuidePoint market sources.
  • Added payout, payment-rate, actor-communication, access, victimology, malware-reliability, and recovery decision lanes.
  • Preserved the existing alert identity so current subscribers continue to follow the consolidated page.
Next run27 Jul 2026 · 1:00 PM ET
Sources monitored
  • Coveware Ransomware Recovery Blog — https://coveware.com/ransomware-blog/
  • Coveware Ransomware Quarterly Reports — https://coveware.com/category/quarterly-report/
  • Coveware by Veeam technical and incident-response publications
  • GuidePoint GRIT quarterly ransomware reports as supplemental context
  • Comparable negotiator, incident-response, and ransomware casework firms when materially relevant
  • PETRA report database query constrained to the active rolling one-year publication window; duplicate matches are reconciled to the direct publisher source
Publication and alert policyCheck weekly. Publish and alert only for a new Coveware report or a material source-backed change to threat-actor communications, payments, nonpayment, access, victimology, malware behavior, decryption, recovery, or executive decisions. Supplemental sources must remain labeled and no-change emails are suppressed.

Related Intelligence and CARDS Records

Other IntelliOS Products

Publication History

Version Change Log

Versionv5Date24 Jul 2026ChangeRewrote the narrative cards so the prose explicitly names the controlling Coveware publication and reporting quarter—Q3 2025, Q4 2025, Q1 2026, the Obscura technical blog, or the Nitrogen technical blog—rather than relying on numbered citations alone.MonitoringWeekly Monday material-change review; next run 27 Jul 2026 at 1:00 PM ET.
Versionv4Date24 Jul 2026ChangeAdded Coveware’s authoritative ransomware-blog and quarterly-report collection URLs as explicit retained corpus-index citations. Individual Coveware articles remain the controlling citations for factual claims, while the two indexes document how the complete first-party corpus is enumerated and monitored.MonitoringWeekly Monday material-change review; next run 27 Jul 2026 at 1:00 PM ET.
Versionv3Date24 Jul 2026ChangeAdded a PETRA report-database reconciliation to the one-year Tier 6 source audit and weekly monitor. PETRA returned two Coveware matches, both duplicates of direct Coveware publications already retained as sources 4 and 5; the database records are documented as candidate hits but not counted as independent evidence.MonitoringWeekly Monday material-change review; next run 27 Jul 2026 at 1:00 PM ET.
Versionv2Date24 Jul 2026ChangeRebuilt Research Framing source coverage as a complete Tier 0–Tier 8 audit, separating five controlling Coveware publications, two selected GuidePoint supplemental reports, and eight official, peer-research, and legacy-monitor sources checked but not used.MonitoringWeekly Monday material-change review; next run 27 Jul 2026 at 1:00 PM ET.
Versionv1Date24 Jul 2026ChangeCreated the Coveware one-year Rolling Intelligence Card; consolidated and deprecated the independent quarterly Coveware email agent; retained subscriber continuity; added Research Framing, Timeline, locked BLUF and Executive Summary, statistics, access vectors, victimology, actors, campaigns, technology, monitoring, practices, products, agent status, and citations.MonitoringWeekly Monday material-change review; next run 27 Jul 2026 at 1:00 PM ET.

Citations

Retained Sources and Claim Treatment

Source1PublisherCoveware by VeeamPublished2025-10-24Publication / evidenceSource indexincident responseWhy used / claim treatmentPrimary Coveware Q3 2025 casework report. Statistics describe Coveware-managed cases and are not a global incident census.SourceQ3 2025 Quarterly Ransomware Report — Insider Threats Loom while Ransom Payment Rates Plummet

https://coveware.com/2025/10/insider-threats-loom-while-ransom-payment-rates-plummet/

Source2PublisherCoveware by VeeamPublished2025-11-19Publication / evidenceSource indexincident responseWhy used / claim treatmentPrimary Coveware malware reverse-engineering and recovery analysis.SourceCoveware Technical Blog — Obscura Ransomware: A Case Study in Ransomware Data Loss

https://www.coveware.com/blog/2025/11/18/obscura-ransomware-data-loss-validation

Source3PublisherCoveware by VeeamPublished2026-02-02Publication / evidenceSource indexincident responseWhy used / claim treatmentPrimary Coveware technical analysis of an ESXi encryptor defect and recovery consequence.SourceCoveware Technical Blog — Nitrogen Ransomware: ESXi malware has a bug!

https://coveware.com/2026/02/nitrogen-ransomware-esxi-malware-has-a-bug/

Source4PublisherCoveware by VeeamPublished2026-02-03Publication / evidenceSource indexincident responseWhy used / claim treatmentPrimary Coveware Q4 2025 report and historical casework comparison. Statistics are limited to cases Coveware handled.SourceQ4 2025 Quarterly Ransomware Report — Why Zero-Day Downstream Mass Data Extortion Campaigns are Losing Their Bite

https://coveware.com/2026/02/why-zero-day-downstream-mass-data-extortion-campaigns-are-losing-their-bite/

Source5PublisherCoveware by VeeamPublished2026-04-30Publication / evidenceSource indexincident responseWhy used / claim treatmentPrimary Coveware Q1 2026 casework report plus forward-looking patch-management analysis. Observed statistics and forecasts remain separate.SourceQ1 2026 Quarterly Ransomware Report — Patch management goes from hard, to ludicrous in the agentic AI era

https://coveware.com/2026/04/patch-management-goes-from-hard-to-ludicrous-in-the-agentic-ai-era/

Source6PublisherGuidePoint Security GRITPublished2026-04-15Publication / evidenceSource indexprimary researchWhy used / claim treatmentSupplemental peer context using public, vendor, incident-response, OSINT, forum, and marketplace evidence. It does not control Coveware-specific claims.SourceRansomware Insights from Q1 2026

https://www.guidepointsecurity.com/blog/ransomware-insights-q1-2026/

Source7PublisherGuidePoint Security GRITPublished2026-07-09Publication / evidenceSource indexprimary researchWhy used / claim treatmentSupplemental external victim-post and ecosystem context. Leak-site reporting is not equivalent to confirmed incidents or Coveware-managed casework.SourceGRIT Q2 2026 Ransomware & Cyber Threat Insights Report

https://www.guidepointsecurity.com/resources/grit-q2-2026-ransomware-cyber-threat-insights-report/

Source8PublisherCoveware by VeeamPublishedNot availablePublication / evidenceSource indexecosystem monitorWhy used / claim treatmentAuthoritative first-party corpus index used to enumerate and monitor Coveware’s complete ransomware-blog publication stream. This index documents source coverage; individual articles remain the controlling citations for factual claims.SourceCoveware Ransomware Recovery Blog

https://coveware.com/ransomware-blog/

Source9PublisherCoveware by VeeamPublishedNot availablePublication / evidenceSource indexecosystem monitorWhy used / claim treatmentAuthoritative first-party quarterly-report index used to identify every in-window Coveware quarterly publication. This index documents source coverage; each quarterly report is cited separately for statistics and conclusions.SourceCoveware Ransomware Quarterly Reports

https://coveware.com/category/quarterly-report/