- How it starts
- A user interacts with a convincing email, link, impersonation, or AI-enhanced lure.
- Attacker outcome
- Credential theft, remote-session creation, data access, or first-stage execution before ransomware or extortion pressure.
- What to monitor
- URL clicks, phishing reports, suspicious downloads, new remote tools, mail-rule changes, impossible travel, and rapid access to sensitive data.
Global Ransomware Landscape Rolling Intelligence Card
This global rolling 90-day landscape card synthesizes ransomware research, public-disclosure datasets, operator activity, access methods, AI-enabled social engineering, identity exposure, cross-platform impact, and recovery implications across regions and organization sizes. It is the strategic ecosystem companion to the U.S. SMB card—not a second U.S. victim tracker. Source methodologies remain separate, its figures must not be added to the U.S. SMB claim population, and evidence leaves the card when it ages beyond the active window.
Research Framing
| Field | Value | |||||||||||||||||||||||||||||||||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| User Topic | Global ransomware activity that materially changes an organization’s likelihood of compromise, operational blast radius, or recovery requirements during the active rolling 90-day window—including operator momentum, initial access, identity abuse, virtualization and backup targeting, victimology, and third-party propagation. | |||||||||||||||||||||||||||||||||||||||||||||||||||||||
| Interpreted Questions | Which ransomware operators are gaining visible global momentum, and which source actually supports that judgment? Which sectors, regions, edge technologies, identities, virtualization systems, and trusted service-provider relationships deserve immediate attention? What evidence is likely to appear before encryption, which victim claims remain unverified, and what proof of containment and recoverability should executives demand now? How does this strategic landscape differ from the separately measured U.S. SMB claim population? | |||||||||||||||||||||||||||||||||||||||||||||||||||||||
| Initial Observations | Thirteen retained sources now show both the visible ransomware market and the intrusion paths behind it. Check Point’s June leak-site review placed The Gentlemen first at 17%, while BlackFog separately recorded 102 public disclosures. Black Kite’s same-day annual report adds a longer public-disclosure and exposed-posture baseline: 7,551 disclosed victims from April 2025 through March 2026, 146 active groups by June 2026, and material post-incident exposure remaining visible. Sophos and Proofpoint add current survey evidence that ransomware is increasingly reached through malicious email, phishing, compromised credentials, malicious links, AI-enabled impersonation, and identity trust failures. At-Bay, LevelBlue, Arete, and Unit 42 still provide the current operational detail on stolen identities, OAuth and API-key abuse, remote tools, BYOVD, edge credential harvesting, The Gentlemen, and identity-led SharePoint extortion. These are separate case, research, survey, leak-site, disclosure, and posture populations; the timeline uses each for the operational fact it can support instead of manufacturing one blended victim count.[1][2][3][4][5][6][7][8][9][10][11][12][13]First cited source May 13, 2026 · Latest cited source Jul 27, 2026 | |||||||||||||||||||||||||||||||||||||||||||||||||||||||
| Source Coverage |
Complete Tier 0–8 counts are shown here. The 13 retained sources and their claim treatment are identified in Citations. Planned integrations are not counted as checked or selected. |
Reporting-Period Statistics
Rolling 90-Day Intelligence Snapshot
At-a-glance measures from the retained evidence set. Citations identify the source controlling each statistic.
Period Coverage
Apr 30, 2026–Jul 28, 2026
90 calendar days, inclusive. Records are included by their first-observed date inside this window; the period does not imply that every underlying incident began or was confirmed during it.
17%[1]
Leading published share
The Gentlemen in Check Point's June data-leak-site datasetEvidence dated Jul 9, 2026
7,551[11]
Annual disclosed victims
Black Kite April 2025-March 2026 public-disclosure dataset; not a 90-day incident countEvidence dated Jul 27, 2026
146[11]
Active groups by June
Black Kite active ransomware-group count after its reporting-period cutoffEvidence dated Jul 27, 2026
79%[12]
Identity-led attacks
Sophos survey share of ransomware attacks beginning with an identity-based approachEvidence dated Jul 22, 2026
65%[13]
AI made attack more effective
Proofpoint survey share of affected organizations reporting significant or somewhat increased attacker effectivenessEvidence dated Jul 21, 2026
100
percent
Published ransomware activity share
Share of Check Point’s June data-leak-site dataset. These are public extortion listings, not independently confirmed intrusions.[1]Evidence dated Jul 9, 2026
Evidence-Prioritized Access Paths
Top Initial Access & Account-Takeover Vectors
Current retained evidence places initial access across four separable lanes: edge and remote-access exposure, people/email interaction, valid identity abuse, and trusted provider or SaaS integration compromise. The sources do not assign one vector to every leak-site post or survey response; use the vectors to drive exposure review and hunting.
- How it starts
- Credentials, sessions, tokens, or under-protected accounts provide valid access to SaaS, VPN, firewall admin, or legacy applications.
- Attacker outcome
- Trusted login, privilege escalation, lateral movement, data theft, and faster time to impact.
- What to monitor
- Dormant-account use, MFA changes, new tokens, device-code flows, service-account anomalies, and session revocation failures.
- How it starts
- A firewall, VPN, gateway, remote-support tool, or related edge system is exploited, misconfigured, deprecated, or accessed with exposed credentials.
- Attacker outcome
- Network foothold, credential theft, provider access, ransomware staging, or customer-environment reach.
- What to monitor
- KEV and critical exposure, unknown admin logins, appliance-originated connections, configuration theft, credential reuse, and post-remediation exposure scans.
- How it starts
- Stolen provider information, OAuth tokens, API keys, or connected-app credentials are reused against customer or SaaS environments.
- Attacker outcome
- Data theft or extortion can bypass several traditional network stages by entering through a trusted integration.
- What to monitor
- Connected-app changes, unusual API activity, customer data access, provider notices, Salesforce or SharePoint bulk access, and cross-tenant anomalies.
| Vector / Evidence | How It Starts | Attacker Outcome | What to Monitor |
|---|---|---|---|
| A user interacts with a convincing email, link, impersonation, or AI-enhanced lure. | Credential theft, remote-session creation, data access, or first-stage execution before ransomware or extortion pressure. | URL clicks, phishing reports, suspicious downloads, new remote tools, mail-rule changes, impossible travel, and rapid access to sensitive data. | |
| Credentials, sessions, tokens, or under-protected accounts provide valid access to SaaS, VPN, firewall admin, or legacy applications. | Trusted login, privilege escalation, lateral movement, data theft, and faster time to impact. | Dormant-account use, MFA changes, new tokens, device-code flows, service-account anomalies, and session revocation failures. | |
| A firewall, VPN, gateway, remote-support tool, or related edge system is exploited, misconfigured, deprecated, or accessed with exposed credentials. | Network foothold, credential theft, provider access, ransomware staging, or customer-environment reach. | KEV and critical exposure, unknown admin logins, appliance-originated connections, configuration theft, credential reuse, and post-remediation exposure scans. | |
| Stolen provider information, OAuth tokens, API keys, or connected-app credentials are reused against customer or SaaS environments. | Data theft or extortion can bypass several traditional network stages by entering through a trusted integration. | Connected-app changes, unusual API activity, customer data access, provider notices, Salesforce or SharePoint bulk access, and cross-tenant anomalies. |
Intended Reader and Decision Context
Persona / Audience
Who this brief is written for, the geographic and organizational lens it uses, and how readers should apply the intelligence.
| Audience Field | Assessment |
|---|---|
| Audience fieldPrimary audience | AssessmentExecutives, boards, CISOs, CIOs, security and IT leaders, incident-response owners, business-continuity leaders, and cyber-insurance stakeholders who need a decision-ready ransomware view. |
| Audience fieldOrganization profile | AssessmentA global, cross-industry ecosystem view for enterprises, managed service providers, healthcare, education, manufacturing, professional services, and organizations dependent on virtualization or shared service providers. U.S. SMB-specific claim concentration and firmographic limits belong in the companion U.S. SMB card. |
| Audience fieldDecision perspective | AssessmentUse the brief to decide which edge systems and identities require immediate review, when suspicious activity becomes an incident, whether recovery systems can withstand attack, and which third-party relationships expand the investigation. |
| Audience fieldEvidence posture | AssessmentLeak-site listings and actor claims are treated as directional intelligence. Local logs, forensic evidence, victim disclosure, or authoritative incident reporting are required before asserting that a specific organization was compromised. |
Chronology and Decision Milestones
Timeline of Notable Activity
Operator activity, access and victim patterns, data-collection periods, and publication dates are separated so a later trend report is not mistaken for the date an intrusion occurred.
Akira intrusion · initial access
A poisoned software search turned an MSP workflow into ransomware access
At-Bay’s case study traces an Akira intrusion to an MSP installing a trojanized AI tool found through a poisoned search result. The case is a concrete warning that administrator software sourcing, execution control, and MSP trust can bypass an otherwise ordinary perimeter.[4]
Akira intrusion · recovery impact
Akira encrypted 60 servers after destroying reachable backups
The same case records destructive impact across 60 servers, unavailable backups, a $10 million demand, containment in roughly two hours, and a $1.5 million settlement. Those are one organization’s outcomes—not a benchmark—but they show why backup isolation and rapid containment authority materially change leverage.[4]
The Gentlemen · operating model
The Gentlemen combined access brokerage with multi-platform ransomware
Check Point’s analysis describes affiliate recruitment, a stock of previously exploited FortiGate access, and Windows, Linux, and VMware ESXi encryption capability. The operation can therefore sell entry, support affiliates, steal data, and attack recovery infrastructure as one business model.[3]
The Gentlemen · third-party propagation
Stolen provider information supported a later attack on the provider’s client
Check Point documented a downstream-client scenario in the leaked material. Shared administration, support tooling, customer data, and provider credentials must be scoped together instead of treating the service provider and customer as unrelated incidents.[3]
The Gentlemen · scale and affiliate velocity
The Gentlemen’s public disclosures accelerated through Q1 and early Q2
LevelBlue counted 352 public claims through May 10 and found large batch-publication days in January, February, and April, consistent with multiple affiliates or coordinated disclosure. The figures measure public claims, while the velocity signals a scalable operation rather than a single crew working one victim at a time.[5]
The Gentlemen · pre-encryption behavior
Remote access, reconnaissance, defense tampering, and data theft preceded domain-wide deployment
LevelBlue maps exposed services and valid accounts to AnyDesk or SystemBC persistence, network and Active Directory discovery, WinSCP exfiltration, security-tool impairment, Group Policy or NETLOGON staging, and Windows, Linux, NAS, BSD, and ESXi impact. That sequence gives defenders observable decisions before encryption.[5]
Q2 incident response · extortion model
More intrusions stopped short of ransomware—or monetized through data theft instead
LevelBlue’s Q2 case population placed non-ransomware network intrusion second at 20% and attributed part of that position to earlier defensive interruption and extortion without encryption. Ransomware readiness therefore has to cover data theft and pressure even when no encryptor runs.[7]
Q2 incident response · trusted integration abuse
Stolen API credentials let the Klue compromise jump directly into connected Salesforce environments
LevelBlue reports that compromised integration credentials enabled automated access to Salesforce-connected services and affected hundreds of organizations. OAuth grants, API keys, service accounts, and connected-app activity are now part of ransomware and extortion scoping because a trusted integration can skip several traditional intrusion stages.[7]
Q2 incident response · edge exploitation
Eight of LevelBlue’s nine most-observed Q2 CVEs affected perimeter devices
The Q2 list concentrated on Ivanti, Fortinet, and Cisco edge or VPN technologies, many with authentication bypass or unauthenticated code execution. Emergency patching must be paired with management-interface restriction, credential review, and historical exploitation hunting.[7]
Q2 incident response · attack speed
Long-dwell cases fell while 3–10 day intrusions nearly doubled
LevelBlue reports that 31-plus-day cases fell from 38% to 23%, while cases resolved within 3–10 days rose from 23% to 42%. Faster detection contributed, but the source also observed attackers compressing the path to their objective; weekly review cycles can now be slower than the intrusion.[7]
June crimeware · actor mix
Akira led Arete’s June observations, but 17 groups kept the operating field distributed
Arete kept Akira, Qilin, and INC Ransom among the most active groups across a 17-group June population. The practical response is a behavior-led playbook for access, identity abuse, defense evasion, exfiltration, and recovery—not a plan built around one ransomware brand.[6]
June crimeware · defense evasion
Akira and DragonForce used vulnerable drivers to attack endpoint defenses
Arete observed bring-your-own-vulnerable-driver activity and described GentleKiller as a framework aimed at multiple security products. Unexpected driver loading, security-service changes, and tamper attempts should trigger rapid containment before lateral deployment.[6]
June victimology · public disclosures
Healthcare led BlackFog’s 102 disclosed attacks across 21 countries
BlackFog’s separate June dataset included 31 groups and placed healthcare ahead of services and education. It is a public-disclosure view, not a number to add to leak-site totals, but it identifies sectors where downtime and sensitive-data pressure remained visible.[2]
June extortion market · operator ranking
The Gentlemen displaced Qilin at the top of Check Point’s June leak-site dataset
Across 646 ransomware data-leak-site posts, The Gentlemen represented 17%, Qilin 11%, and LockBit 7%; North America accounted for 44% of the dataset. These are public extortion listings, but the leadership change shows how quickly affiliate volume can reorganize.[1]
The Gentlemen · cross-vendor confirmation
Unit 42 documented a durable RaaS operation under its own Scorpius taxonomy
Unit 42 connected The Gentlemen to RaaS behavior and related Scorpius activity clusters. The operational value is the repeated access, evasion, exfiltration, and encryption behavior; the original Unit 42 labels remain visible rather than being flattened into one universal attribution.[8]
FortiBleed · access-to-ransomware path
Harvested Fortinet credentials were linked to INC and Lynx operations
Arete reported evidence connecting the credential-harvesting campaign to INC and Lynx ransomware activity. Organizations with affected FortiGate history should rotate exposed credentials, review prior administrative sessions, and hunt for follow-on access even after patching.[9]
Helix · identity-led extortion
Helix used Microsoft 365 identity and SharePoint data instead of requiring endpoint encryption
Arete describes vishing, device-code phishing, MFA abuse, trusted-person impersonation, SharePoint discovery, and data theft. The campaign makes cloud sessions, OAuth activity, device codes, and bulk SaaS access part of the ransomware and extortion perimeter.[10]
Helix · attribution discipline
Operational overlap did not justify collapsing Helix into ShinyHunters or BlackFile
Arete noted similarities and possible shared ecosystems while leaving the relationship unresolved. Defenders can correlate identity, SaaS, and extortion behaviors without claiming a single actor identity that the evidence does not establish.[10]
AI-era ransomware survey
Proofpoint made malicious links and AI-assisted trust abuse a ransomware entry concern
Proofpoint's current survey reports malicious links as the leading entry vector, 65% of affected organizations saying AI made the attack more effective, 54% paying a ransom, 37% of payers facing a second demand, and 65% experiencing data theft. These are survey findings, not incident-response counts, but they materially shift monitoring toward people, identities, and trusted communications.[13]
Ransomware survey · identity and economics
Sophos reported identity-led entry, higher encryption incidence, and a widening small-organization outcome gap
Sophos reports malicious email and phishing together at half of surveyed root causes, identity-based approaches in 79% of attacks, 56% of attacks encrypting data, average recovery cost at $1.7 million, and only 34% of 100-250 employee organizations stopping attacks before encryption or extortion. The source is a survey cohort, not a leak-site dataset.[12]
Annual public-disclosure baseline
Black Kite added annual victim growth, active-group fragmentation, and post-incident exposure evidence
Black Kite tracked 7,551 publicly disclosed victims in its April 2025-March 2026 reporting period, 146 active groups by June 2026, and continued critical-vulnerability, KEV, and stealer-log exposure in post-disclosure posture checks. The annual findings strengthen the card's fragmentation and exposure-management conclusions without changing June leak-site or U.S. SMB tracker totals.[11]
Bottom Line Up Front
BLUF
The leading name changed quickly in the global June dataset: Check Point’s worldwide June leak-site dataset placed The Gentlemen first with 17% of published attacks, ahead of Qilin at 11%. The U.S. SMB card separately places Qilin first across a 90-day ransomware.live population. Both can be true because the geography, period, and collection methods differ; neither measure is a verified incident count.[1]Evidence dated Jul 9, 2026
The access problem starts at the edge: Check Point describes The Gentlemen using unpatched edge devices and purchased or stolen credentials, including access tied to exposed FortiGate systems. If your organization operates internet-facing VPN, firewall, or remote-access infrastructure, patch status alone is not enough; review historical logins and credential use.[3]Evidence dated May 13, 2026
Recovery infrastructure is part of the target: The Gentlemen supports Windows, Linux, and VMware ESXi encryption. Scope virtualization management, hypervisors, backup consoles, identity services, and privileged administration at the start of an investigation rather than after endpoint encryption is discovered.[1][3]First cited source May 13, 2026 · Latest cited source Jul 9, 2026
One provider compromise can reach a customer: Check Point documented stolen service-provider information being used to support a later attack against the provider’s client. MSPs and customers should treat shared credentials, support tooling, tenant access, and trust relationships as part of the same incident boundary.[3]Evidence dated May 13, 2026
Victim counts require discipline: Check Point and BlackFog collect different mixtures of leak-site posts, public disclosures, and qualified claims. Their figures describe momentum within each dataset and should not be combined into a larger headline number.[1][2]First cited source Jul 2, 2026 · Latest cited source Jul 9, 2026
People and identity are now first-order ransomware controls: Sophos found malicious email plus phishing at half of surveyed ransomware root causes and identity-based approaches at 79% of attacks. Proofpoint separately found malicious links leading its surveyed entry vectors and AI making many attacks more effective. Ransomware readiness now has to cover email, user interaction, identity, MFA coverage gaps, and trusted communications before malware appears.[12][13]First cited source Jul 21, 2026 · Latest cited source Jul 22, 2026
Recovery does not equal exposure closure: Black Kite’s current-state rescan of disclosed victims found critical vulnerabilities and KEV exposure still visible after incidents. Treat post-incident closure as an exposure-management program: verify patched edge systems, credential rotation, stealer-log exposure, and third-party attack-surface cleanup after operations resume.[11]Evidence dated Jul 27, 2026
Executive decision: Require evidence that internet-facing access paths are owned and reviewed, privileged credentials are protected, email and malicious-link controls are measured, ESXi and backups are isolated, and responders can investigate identity, cloud, virtualization, staging, and third-party activity before attackers reach encryption.[1][2][3][11][12][13]First cited source May 13, 2026 · Latest cited source Jul 27, 2026
Decision Context
Executive Summary
Ransomware risk in the current window is defined less by one stable leader than by how quickly affiliates, access inventory, and extortion brands can reorganize. Check Point’s worldwide June data placed The Gentlemen at 17% of published attacks, Qilin at 11%, and LockBit at 7%. Those percentages come from ransomware data-leak sites, so they indicate public extortion activity rather than independently confirmed compromise totals. The result does not conflict with Qilin leading the companion U.S. SMB card’s separate 90-day U.S. dataset.[1]Evidence dated Jul 9, 2026
The Gentlemen matters because the operation combines a ransomware-as-a-service model with access brokerage. Check Point describes a self-service stock of previously exploited FortiGate devices, affiliate recruitment, and Windows, Linux, and VMware ESXi lockers. For a company, that means one neglected edge appliance can become the bridge from internet exposure to identity abuse, lateral movement, data theft, and attacks on recovery infrastructure.[1][3]First cited source May 13, 2026 · Latest cited source Jul 9, 2026
BlackFog provides a different but complementary view: 102 publicly disclosed attacks across 21 countries and 31 groups, with healthcare leading its June sector count. The figures should not be added to Check Point’s totals because the source methods differ. The useful conclusion is directional—ransomware remains distributed across many operators and sectors, even while a few brands gain visible momentum.[1][2]First cited source Jul 2, 2026 · Latest cited source Jul 9, 2026
Regional data should shape preparation without creating false comfort. Check Point placed North America at 44% of reported ransomware incidents, APAC at 23%, and Europe at 22%. A U.S. organization should therefore prioritize readiness, but location alone cannot rule risk in or out; affiliates often select victims based on available access rather than a fixed geographic plan.[1]Evidence dated Jul 9, 2026
The operational lesson is to hunt before encryption. Edge authentication anomalies, new privileged sessions, credential reuse, remote administration, security-tool interference, large data staging, hypervisor access, and backup changes are more useful early-warning signals than waiting for a ransom note. Service providers and their customers should also review shared administration paths because stolen provider information can create downstream risk.[3]Evidence dated May 13, 2026
The newest annual and survey evidence broadens the initial-access story. Sophos reports malicious email plus phishing as half of surveyed ransomware root causes and identity-based approaches in 79% of attacks; Proofpoint reports malicious links as the leading surveyed entry vector and says AI made attacks more effective for many affected organizations. These survey results should not be mixed with leak-site or IR counts, but they materially change control prioritization toward people, identities, MFA coverage, malicious-link handling, and trusted-communication verification.[12][13]First cited source Jul 21, 2026 · Latest cited source Jul 22, 2026
Black Kite adds a post-incident exposure warning: in its April 2025-March 2026 public-disclosure cohort, the active-group count reached 146 by June 2026, Qilin scaled sharply in that dataset, and many disclosed victims still showed critical vulnerability or KEV exposure when rescanned. The practical lesson is that closing the ticket after restoration is not enough; organizations must prove the exploitable conditions, credentials, third-party paths, and stealer-log exposure that attackers can still see are closed.[11]Evidence dated Jul 27, 2026
Executives should ask for proof of resilience, not a list of security products: an owned inventory of exposed access systems, phishing-resistant authentication for privileged roles, measured email and malicious-link defenses, segmented and recoverable identity and virtualization services, immutable backups with tested restore times, and an incident plan that includes legal, communications, insurer, provider, and customer decisions before business operations stop.[1][2][3][11][12][13]First cited source May 13, 2026 · Latest cited source Jul 27, 2026
Executive Briefing Priorities
Top 10 Briefing Points
- 1
The Gentlemen moved to the top of Check Point's June ranking — Check Point attributed 17% of published attacks in its June dataset to The Gentlemen, ahead of Qilin at 11%; these are data-leak-site disclosures, not confirmed incident totals.[1]Evidence dated Jul 9, 2026
- 2
Publicly visible ransomware activity increased — BlackFog counted 102 publicly disclosed attacks across 21 countries and 31 groups in June, while explicitly separating public disclosure from unverified actor attribution.[2]Evidence dated Jul 2, 2026
- 3
Healthcare, services, and education remained prominent — BlackFog's June dataset recorded healthcare as its leading sector, followed by services and education, supporting continued scoping attention for sensitive-data and operational-disruption exposure.[2]Evidence dated Jul 2, 2026
- 4
Dataset definitions cannot be combined into one victim count — Check Point reports published attacks, while BlackFog mixes public disclosures and qualified claims. Use each source for direction within its own methodology rather than adding the totals together.[1][2]First cited source Jul 2, 2026 · Latest cited source Jul 9, 2026
- 5
RaaS leadership can shift quickly — The Gentlemen's rise from a mid-2025 entrant to a leading published-activity position shows how affiliate movement and access inventory can change the operating landscape within months.[1][3]First cited source May 13, 2026 · Latest cited source Jul 9, 2026
- 6
Edge access and valid credentials remain briefing priorities — Research into The Gentlemen describes access through unpatched edge devices and purchased credentials, including FortiGate exposure, making edge logs and identity evidence central to early scoping.[3]Evidence dated May 13, 2026
- 7
Cross-platform impact should be assumed during scoping — The Gentlemen maintains Windows, Linux, and VMware ESXi capability, so responders should include virtualization and backup infrastructure rather than limiting collection to Windows endpoints.[1][3]First cited source May 13, 2026 · Latest cited source Jul 9, 2026
- 8
Regional concentration should shape readiness without narrowing scope — Check Point's retained dataset placed North America at 44% of reported ransomware incidents, followed by APAC at 23% and Europe at 22%. Use the distribution to inform readiness and third-party monitoring, not to rule out organizations in other regions.[1]Evidence dated Jul 9, 2026
- 9
The ransomware investigation must extend beyond endpoints — The Gentlemen’s Windows, Linux, and VMware ESXi capability means responders should collect from identity, edge devices, hypervisors, backup systems, privileged administration, and data-staging locations before recovery work destroys evidence.[3]Evidence dated May 13, 2026
- 10
One compromise can create downstream client risk — Check Point documented The Gentlemen using information stolen from a service provider to support a later attack against the provider's client, reinforcing third-party scoping obligations.[3]Evidence dated May 13, 2026
- 11
Annual disclosures show a larger and more fragmented market — Black Kite tracked 7,551 disclosed victims in its April 2025-March 2026 period and 146 active groups by June 2026. Those are annual public-disclosure and posture metrics, not current 90-day confirmed incident counts.[11]Evidence dated Jul 27, 2026
- 12
Identity-led entry is now a ransomware control baseline — Sophos reports identity-based approaches in 79% of surveyed ransomware attacks, while malicious email and phishing together account for half of reported root causes. MFA must cover VPNs, firewall admin consoles, legacy apps, SaaS, and privileged roles, not only common user accounts.[12]Evidence dated Jul 22, 2026
- 13
AI and malicious links raise the user-interaction risk — Proofpoint's current survey placed malicious links first among entry vectors and reported that AI made attacks more effective for many affected organizations. User training alone is too weak unless paired with URL isolation, reporting, identity telemetry, and rapid session revocation.[13]Evidence dated Jul 21, 2026
- 14
Post-incident posture remains a live attack surface — Black Kite's rescan findings mean incident closure should include external exposure validation, KEV and critical vulnerability remediation, credential and stealer-log checks, and third-party risk review after business operations resume.[11]Evidence dated Jul 27, 2026
Company Exposure and Exploitability
Exploitable Technologies for Companies
Specific products and control interfaces elevated by the retained government record. Each row explains the exploitable condition, which companies should care, the business consequence, and the evidence a defender should monitor.
| Technology and exploitable condition | Company exposure and business risk | Monitoring and IntelliOS coverage |
|---|---|---|
| Technology Internet-facing firewalls, VPNs, and edge appliances[3][9][11][12]First cited source May 13, 2026 · Latest cited source Jul 27, 2026 Exploitable conditionUnpatched exposure, deprecated access modes, vulnerable configurations, or stolen credentials provide a foothold or privileged network position. | Which companies should care Edge devices are high-leverage access paths for ransomware affiliates and appear across Check Point, Sophos, Arete, and Black Kite evidence. Business riskCredential theft, lateral movement, data theft, seven-figure demands, and persistent exposure after apparent recovery. | What to monitor Unsupported or exposed devices, admin login anomalies, stale sessions, VPN policy changes, credential reuse, KEV status, and external posture after remediation. IntelliOS coverageNo dedicated product yet |
| Technology Email, malicious links, and collaboration identity[7][10][12][13]First cited source Jul 17, 2026 · Latest cited source Jul 23, 2026 Exploitable conditionUsers interact with convincing lures, malicious links, impersonation, device-code or OAuth workflows, or compromised trusted communications. | Which companies should care Sophos and Proofpoint make people and identity a first-order ransomware surface; Arete's Helix and LevelBlue's Klue/Salesforce context show SaaS and identity abuse in extortion workflows. Business riskAccount takeover, data theft, unauthorized SaaS access, repeat extortion, and delayed detection before malware is visible. | What to monitor URL clicks, new tokens, MFA changes, device-code flows, OAuth grants, mail-forwarding rules, impossible travel, and bulk SharePoint or Salesforce access. IntelliOS coverageNo dedicated product yet |
| Technology VMware ESXi, backup platforms, and recovery identity[1][3][4]First cited source May 13, 2026 · Latest cited source Jul 9, 2026 Exploitable conditionAttackers reach hypervisors, backup consoles, repositories, or recovery credentials from production identity or shared administration paths. | Which companies should care The Gentlemen and At-Bay Akira casework show why virtualization and backups belong in the first incident scope, not the recovery afterthought. Business riskEnterprise-wide encryption, unrecoverable backups, extended downtime, larger ransom pressure, and loss of evidence during restoration. | What to monitor New hypervisor admin access, SSH enablement, mass VM shutdown, backup deletion, retention changes, repository access, and restore-test failures. IntelliOS coverageNo dedicated product yet |
| Technology Third-party, MSP, and SaaS integration trust[3][7][10][11]First cited source May 13, 2026 · Latest cited source Jul 27, 2026 Exploitable conditionProvider data, OAuth tokens, API keys, shared administration, or customer information are stolen and reused downstream. | Which companies should care Check Point documents provider-to-client reuse, while LevelBlue and Arete describe trusted integration compromise and SaaS extortion paths. Business riskOne compromise can become a multi-tenant or customer-impact incident with notification, contractual, and recovery complexity. | What to monitor Provider account changes, cross-tenant anomalies, connected-app access, API-key use, customer-specific data access, and supplier compromise notices. IntelliOS coverage |
Source-Bound Exposure and Targeting
Victimology Matrix
This is not a raw victim list. Publicly named organizations are shown when reliable sources identify them, with confirmation and attribution boundaries preserved. Where no defensible name exists, IntelliOS uses the narrowest supported exposure population. Sector or geography matches remain scoping signals; they do not prove compromise.
| Victim / exposure population | Sectors | Geography | Confirmation status | How companies should use it |
|---|---|---|---|---|
| Victim / exposure populationOrganizations named on ransomware leak sites[1]Evidence dated Jul 9, 2026 | SectorsBusiness services, consumer goods and services, industrial manufacturing, government, and other sectors | GeographyNorth America 44%; APAC 23%; Europe 22% in Check Point’s June dataset | Confirmation statusActor-published victim listings; not independently confirmed incidents | How companies should use itUse for sector and regional prioritization, external-attack-surface review, and third-party monitoring—not as a verified breach count. |
| Victim / exposure populationPublicly disclosed ransomware victims[2]Evidence dated Jul 2, 2026 | SectorsHealthcare led BlackFog’s June sector count, followed by services and education | Geography102 disclosures across 21 countries | Confirmation statusPublic disclosure and qualified claim tracking within BlackFog’s methodology | How companies should use itHealthcare, education, and service organizations should validate downtime, sensitive-data, and recovery assumptions against the sector pattern. |
| Victim / exposure populationAnnual public-disclosure and posture population[11]Evidence dated Jul 27, 2026 | SectorsManufacturing led Black Kite's annual disclosure cohort, followed by professional, scientific, and technical services; construction rose to third | GeographyU.S. remained the largest single country, while Europe grew faster in Black Kite's reporting-period comparison | Confirmation statusPublicly disclosed victims plus Black Kite posture observations; not a confirmed incident census or the same population as Check Point, BlackFog, or ransomware.live | How companies should use itUse the annual view to validate sector, geography, revenue-band, and post-incident exposure assumptions before setting third-party and attack-surface monitoring thresholds. |
| Victim / exposure populationOrganizations hit by ransomware in Sophos and Proofpoint surveys[12][13]First cited source Jul 21, 2026 · Latest cited source Jul 22, 2026 | SectorsCross-industry survey respondents rather than named victims | GeographySophos global survey and Proofpoint 12-market survey | Confirmation statusSelf-reported ransomware experience from security and IT respondents | How companies should use itUse the results to stress-test people, identity, email, malicious-link, and payment-decision controls; do not convert them into incident prevalence. |
| Victim / exposure populationOrganizations exposed through edge-device access[1][3]First cited source May 13, 2026 · Latest cited source Jul 9, 2026 | SectorsCross-industry; especially organizations with internet-facing FortiGate or remote-access infrastructure | GeographyDevice-driven rather than limited to one country | Confirmation statusVendor analysis of Gentlemen access inventory and leaked internal material | How companies should use itInventory edge systems, review historical administrative access, rotate exposed credentials, and investigate prior reachability even after patching. |
| Victim / exposure populationService providers and downstream customers[3]Evidence dated May 13, 2026 | SectorsMSPs, IT service firms, and customers reached through shared administration or stolen provider information | GeographyNot bounded to one region in retained reporting | Confirmation statusDocumented downstream-client scenario in Check Point research | How companies should use itScope provider and customer environments together when shared accounts, remote tooling, or customer data may have been exposed. |
Distinct Operational Records
Ransomware Threat Actors & Operations
The Gentlemen rapid-scale RaaS and access-broker operation
Check Point describes a mid-2025 entrant that recruited affiliates, offered access to previously exploited FortiGate devices, developed Windows/Linux/ESXi capability, and reached the top position in its June leak-site dataset.[1][3]First cited source May 13, 2026 · Latest cited source Jul 9, 2026
Downstream client targeting through stolen provider information
Check Point documented a scenario in which information stolen from a service provider supported a later attack against the provider’s client, making third-party trust a concrete ransomware investigation boundary.[3]Evidence dated May 13, 2026
AI-era people and identity pressure
Proofpoint and Sophos independently make people, malicious links, email, compromised credentials, and MFA coverage gaps current ransomware campaign constraints. The campaign-level implication is not a named actor; it is that ransomware operations increasingly reach objectives through trusted human and identity workflows.[12][13]First cited source Jul 21, 2026 · Latest cited source Jul 22, 2026
Post-incident exposure persistence
Black Kite’s annual report pairs disclosures with before-and-after posture signals, showing that incident recovery and exposure closure can diverge. Treat remediation as a continuing attack-surface and third-party-risk campaign rather than a one-time recovery milestone.[11]Evidence dated Jul 27, 2026
Source-Bound Actor Context
Notable Actors & Criminal Ecosystems
The Gentlemen
Fast-growing RaaS operator and initial-access broker; 17% of Check Point’s June published-attack dataset. Retained reporting describes FortiGate access inventory and Windows, Linux, and ESXi encryption capability.[1][3]First cited source May 13, 2026 · Latest cited source Jul 9, 2026
Qilin
Established RaaS operation that represented 11% of Check Point’s June published attacks and remained a major affiliate destination even after losing the top position. Black Kite separately reports Qilin at 1,358 disclosed victims in its April 2025-March 2026 dataset, reinforcing Qilin as a cross-window watch priority without merging the datasets.[1][11]First cited source Jul 9, 2026 · Latest cited source Jul 27, 2026
LockBit
Long-running ransomware brand that rose from 1% to 7% of Check Point’s published-attack dataset between May and June, illustrating how visible activity can rebound quickly.[1]Evidence dated Jul 9, 2026
Malware, Implants, and Intrusion Tooling
Malware Summary
Source-backed malware and malicious tooling named in the retained campaigns. The table distinguishes malware families, open-source tools, custom implants, exploit or collection tooling, and reported outcomes that lack a publicly identified sample.
| Malware / tooling | Classification and campaign | Capability and potential impact | What defenders should monitor |
|---|---|---|---|
| Malware / toolingThe Gentlemen lockers and GentleKiller[1][3][5][6][8]First cited source May 13, 2026 · Latest cited source Jul 10, 2026 | Classification and campaignRaaS locker family and EDR-disabling toolingCheck Point, LevelBlue, Arete, and Unit 42 describe The Gentlemen as a fast-scaling operation with Windows, Linux, ESXi, and defense-evasion capability. | Capability and potential impactSupports data theft, security-tool impairment, and cross-platform encryption that can extend impact from endpoints into recovery-critical infrastructure. | What defenders should monitorDriver loading, EDR tamper events, new ransomware binaries, ESXi access, unusual Group Policy or NETLOGON staging, and leak-site or negotiation changes. |
| Malware / toolingAkira ransomware[4][6]First cited source May 13, 2026 · Latest cited source Jul 6, 2026 | Classification and campaignRansomware operation and lockerAt-Bay casework and Arete June observations keep Akira prominent in both case impact and monthly activity. | Capability and potential impactCan create server-scale encryption, backup destruction, large demands, and rapid business-continuity pressure. | What defenders should monitorBackup deletion, high-volume encryption, anomalous remote administration, BYOVD activity, data staging, and Akira-branded extortion contact. |
| Malware / toolingINC/Lynx-related ransomware activity[6][9]First cited source Jul 6, 2026 · Latest cited source Jul 14, 2026 | Classification and campaignRansomware operations and reported code lineageArete links FortiBleed credential exposure to INC and Lynx operations and reports lineage overlap among INC, Lynx, and Sinobi. | Capability and potential impactCredential access against edge devices can provide ransomware affiliates with reusable footholds and downstream access paths. | What defenders should monitorFortiGate credential exposure, anomalous VPN sessions, INC or Lynx payload indicators, configuration theft, and post-patch credential use. |
| Malware / toolingHelix extortion tooling and SaaS data-theft workflow[10]Evidence dated Jul 17, 2026 | Classification and campaignIdentity-led extortion operation without required endpoint encryptionArete describes Helix using vishing, device-code phishing, Microsoft 365 identity abuse, and SharePoint data theft. | Capability and potential impactShows how extortion can proceed through cloud sessions and data access even if endpoint ransomware never runs. | What defenders should monitorDevice-code authentication, new OAuth grants, bulk SharePoint reads, unusual OneDrive or SharePoint export, vishing reports, and trusted-person impersonation. |
Enterprise Exposure
Affected Technologies & Trust Boundaries
Internet-facing edge and remote-access systems
Unpatched appliances and valid credentials can create the initial foothold. Owned-asset inventory, historical authentication review, management-interface restriction, and privileged credential rotation are required when exposure is plausible.[3]Evidence dated May 13, 2026
Virtualization, identity, and backup control planes
Cross-platform ransomware capability means responders must include VMware ESXi, administrative consoles, identity services, backup infrastructure, and recovery credentials in the first collection and containment plan.[1][3]First cited source May 13, 2026 · Latest cited source Jul 9, 2026
Service-provider trust paths
Shared tooling, support accounts, tenant administration, and customer information can extend one compromise into downstream organizations.[3]Evidence dated May 13, 2026
Email, links, MFA coverage, and identity telemetry
Current survey evidence makes malicious email, phishing, malicious links, compromised credentials, and MFA gaps a ransomware exposure surface. Control reviews should prove coverage across SaaS, VPN, firewall admin, legacy applications, privileged roles, and session revocation.[12][13]First cited source Jul 21, 2026 · Latest cited source Jul 22, 2026
External posture after incident closure
Critical vulnerabilities, KEV exposure, and stealer-log exposure can remain visible after a ransomware disclosure. Incident closure should include post-restoration external attack-surface validation and vendor-risk follow-up.[11]Evidence dated Jul 27, 2026
Current Carry-Forward Watchlist
Top 10 Specific Threats to Monitor
Prioritized source-backed developments that convert the rolling activity record into named operational monitoring requirements.
| # | Threat / Category | Why It Matters | What to Monitor | IntelliOS Coverage |
|---|---|---|---|---|
| 1 | Threat / Category Actor momentum The Gentlemen leak-site and affiliate activity[1][3]First cited source May 13, 2026 · Latest cited source Jul 9, 2026 | Why it mattersA fast-growing RaaS and access-broker operation led Check Point’s June published-attack dataset. | What to monitorNew victim posts; affiliate recruitment; negotiation or infrastructure changes; updated Windows, Linux, or ESXi capability; new access inventory claims. | IntelliOS coverage |
| 2 | Threat / Category Established RaaS Qilin activity and affiliate movement[1][11]First cited source Jul 9, 2026 · Latest cited source Jul 27, 2026 | Why it mattersQilin remained second in Check Point’s June dataset and Black Kite separately reports major annual growth for Qilin in its disclosure cohort. | What to monitorLeak-site changes; affiliate recruitment; rebrands; shared infrastructure; movement of known affiliates or access brokers; Qilin mentions in edge-exploitation reporting. | IntelliOS coverage |
| 3 | Threat / Category Initial access Email, malicious links, and AI-assisted impersonation[12][13]First cited source Jul 21, 2026 · Latest cited source Jul 22, 2026 | Why it mattersSophos and Proofpoint make user interaction, malicious links, and AI-enhanced trust abuse current ransomware entry concerns. | What to monitorHigh-risk URL clicks, phishing reports, new downloads, suspicious OAuth or device-code flows, impersonation reports, and employee interactions with realistic malicious content. | IntelliOS coverage |
| 4 | Threat / Category Initial access Internet-facing edge appliances[3][9][11][12]First cited source May 13, 2026 · Latest cited source Jul 27, 2026 | Why it mattersThe Gentlemen research, Arete FortiBleed reporting, Sophos firewall findings, and Black Kite posture data keep firewalls, VPNs, and gateways at the center of ransomware access review. | What to monitorUnknown administrative logins; impossible travel; new VPN sessions; management-interface exposure; KEV/critical vulnerabilities; unexplained configuration or account changes. | IntelliOS coverage |
| 5 | Threat / Category Identity Stolen credentials and MFA coverage gaps[3][12][13]First cited source May 13, 2026 · Latest cited source Jul 22, 2026 | Why it mattersValid access can shorten the path from entry to lateral movement and extortion; MFA must cover the systems attackers actually use. | What to monitorPassword spraying; dormant-account use; MFA changes; new tokens or sessions; privilege elevation; service-account misuse; VPN, firewall-admin, SaaS, and legacy-app MFA exceptions. | IntelliOS coverage |
| 6 | Threat / Category Recovery infrastructure VMware ESXi and virtualization administration[1][3]First cited source May 13, 2026 · Latest cited source Jul 9, 2026 | Why it mattersCross-platform locker capability places hypervisors and management consoles inside the primary ransomware target set. | What to monitorNew root or administrative access; SSH enablement; mass VM shutdown; datastore changes; unfamiliar binaries or scripts. | IntelliOS coverage |
| 7 | Threat / Category Recovery infrastructure Backup deletion, policy change, or credential use[1][3]First cited source May 13, 2026 · Latest cited source Jul 9, 2026 | Why it mattersAttackers gain leverage when backups and restoration paths are reachable from production identities. | What to monitorRetention changes; repository deletion; new admin grants; failed restore tests; unusual access to backup consoles or secrets. | IntelliOS coverage |
| 8 | Threat / Category Pre-encryption behavior Data staging and large outbound transfers[1][2][3]First cited source May 13, 2026 · Latest cited source Jul 9, 2026 | Why it mattersDouble-extortion pressure usually depends on data theft before encryption or public posting. | What to monitorArchive creation; unusual cloud or S3 transfers; bulk file access; new compression tools; egress to unapproved destinations. | IntelliOS coverage |
| 9 | Threat / Category Third-party risk Service-provider and customer trust paths[3]Evidence dated May 13, 2026 | Why it mattersStolen provider information can support a later downstream-client attack. | What to monitorShared accounts; remote-management access; cross-tenant anomalies; customer-specific data access; provider compromise notices. | IntelliOS coverage |
| 10 | Threat / Category Exposure management Post-incident unresolved vulnerabilities and stealer exposure[11]Evidence dated Jul 27, 2026 | Why it mattersBlack Kite's annual posture findings show that restored organizations may still present exploitable conditions to attackers. | What to monitorCritical CVSS exposure, KEV exposure, stealer-log hits, open management ports, vendor-risk exceptions, and external posture after incident closure. | IntelliOS coverage |
| 11 | Threat / Category Victimology Healthcare, manufacturing, services, education, and middle-market targeting[1][2][11][12]First cited source Jul 2, 2026 · Latest cited source Jul 27, 2026 | Why it mattersRetained sources place these sectors or revenue bands prominently in their separate June, annual, and survey datasets. | What to monitorSector-specific actor claims; vendor alerts; third-party access changes; outage or extortion reports; regional shifts; revenue-band concentration in disclosure datasets. | IntelliOS coverage |
Operational Standards from the Evidence
Best Practices and Lessons Learned
The practices below convert the retained public evidence into repeatable executive standards. Each lesson remains bounded to its cited sources.
- 1
Best Practice
Separate claims from confirmed incidents[1][2]First cited source Jul 2, 2026 · Latest cited source Jul 9, 2026
Lesson Learned
Leak-site posts are useful momentum indicators but may be incomplete, duplicated, disputed, or strategically timed.
Minimum Operating Standard
Report source-specific counts and require independent evidence before calling an organization a confirmed victim.
- 2
Best Practice
Treat edge exposure as an investigation trigger[3]Evidence dated May 13, 2026
Lesson Learned
Patching closes a current path but does not prove attackers never used the system or its credentials.
Minimum Operating Standard
For historically exposed edge systems, review logs and identities, rotate credentials, and escalate unexplained access into incident response.
- 3
Best Practice
Measure people and identity defenses as ransomware controls[12][13]First cited source Jul 21, 2026 · Latest cited source Jul 22, 2026
Lesson Learned
Current survey evidence places malicious email, phishing, malicious links, compromised credentials, and MFA coverage gaps at the start of many ransomware stories.
Minimum Operating Standard
Track phishing reporting and click outcomes, isolate risky links, enforce phishing-resistant MFA for privileged and remote access, close MFA exceptions on VPN/firewall/SaaS/legacy systems, and rehearse rapid token and session revocation.
- 4
Best Practice
Protect recovery as a separate security zone[1][3]First cited source May 13, 2026 · Latest cited source Jul 9, 2026
Lesson Learned
Windows-only assumptions miss ESXi, backup, identity, and management-plane exposure.
Minimum Operating Standard
Segment recovery infrastructure, use separate privileged identities, monitor administrative actions, and test restoration under attack conditions.
- 5
Best Practice
Hunt before encryption[3]Evidence dated May 13, 2026
Lesson Learned
Identity abuse, remote administration, staging, and security-control changes appear earlier than the ransom note.
Minimum Operating Standard
Maintain detections and response playbooks for pre-encryption behavior and empower responders to contain before business impact is visible.
- 6
Best Practice
Scope trusted third parties[3]Evidence dated May 13, 2026
Lesson Learned
Provider data and access can create a second victim beyond the initially compromised organization.
Minimum Operating Standard
Include MSPs, customers, shared tooling, tenant access, and contractual notification paths in ransomware tabletop exercises.
- 7
Best Practice
Close exposure after restoration[11]Evidence dated Jul 27, 2026
Lesson Learned
Black Kite's posture findings show that recovery and exposure closure can diverge; attackers can still see unresolved critical vulnerabilities, KEVs, and credential exposure after public disclosure.
Minimum Operating Standard
Before declaring closure, validate external posture, KEV and critical remediation, credential rotation, stealer-log cleanup, vendor exposure, and proof that the original access path no longer works.
- 8
Best Practice
Make ransomware a continuity decision[1][2][3][11][12][13]First cited source May 13, 2026 · Latest cited source Jul 27, 2026
Lesson Learned
The central question is whether the business can operate and recover while identity, virtualization, email, SaaS, or key vendors are unavailable.
Minimum Operating Standard
Set maximum tolerable downtime, recovery priorities, decision authority, communications triggers, payment and nonpayment thresholds, and restoration evidence before an incident.
Automation Transparency
AI Agent Run Status
| Agent | Ransomware Rolling Intelligence Card Publisher |
|---|---|
| Status | Active · rolling 90-day automation |
| Cadence | Weekly on Monday at midday ET; publish only when retained evidence materially changes the card |
| Previous run | 27-Jul-2026 · 12:00 PM ET · Run ACT-RANSOM-20260727-1200 |
| Previous result | Published v10 after retaining Black Kite, Sophos, and Proofpoint as separate annual or survey datasets; no email or external notification was sent by this local job. |
| What the previous run found |
|
| Next run | 03-Aug-2026 · midday ET |
| Sources monitored |
|
| Publication and alert policy | Publish and alert only for a material source-backed change; do not notify for no-change checks or date-only rolling-window movement. |
Related Intelligence and CARDS Records
Other IntelliOS Products
Rolling Intelligence
U.S. SMB Ransomware Activity & Exposure Trends
Companion quantitative view of reconciled U.S. claim concentration, canonical actor alignment, SMB evidence limits, and practical controls. Its totals must remain separate from this global landscape synthesis.
Open productPANDA Sector Brief
Ransomware Targeting U.S. SMBs
Sector and business-risk analysis for small and midsize U.S. organizations.
Open productCARDS Actor Record
Thegentlemen Actor Card
Connected actor intelligence, source-bound attribution context, behaviors, relationships, and defensive relevance.
Open productCARDS Actor Record
Qilin Actor Card
Connected actor intelligence, source-bound attribution context, behaviors, relationships, and defensive relevance.
Open productCARDS Actor Record
Akira Actor Card
Connected actor intelligence, source-bound attribution context, behaviors, relationships, and defensive relevance.
Open productCARDS Actor Record
INC Ransom Actor Card
Connected actor intelligence, source-bound attribution context, behaviors, relationships, and defensive relevance.
Open productCARDS Actor Record
Lynx Actor Card
Connected actor intelligence, source-bound attribution context, behaviors, relationships, and defensive relevance.
Open productCARDS Campaign Record
The Gentlemen RAAS Operations Campaign Card
Connected campaign intelligence, activity timeline, affected technologies, actors, techniques, and source boundaries.
Open productPublication History
Version Change Log
| Version | Date | Change | Monitoring |
|---|---|---|---|
| Versionv10 | Date27-Jul-2026 | ChangeRetained Black Kite's 2026 Ransomware Report, Sophos State of Ransomware 2026, and Proofpoint's 2026 AI-Era Ransomware Report as distinct annual and survey datasets. Updated Research Framing, BLUF, Executive Summary, metrics, victimology, initial access, exploitable technologies, malware/tooling, monitoring priorities, best practices, AI Agent Status, and source audit while preserving the rule that leak-site claims, disclosures, surveys, posture signals, and U.S. SMB tracker counts are never merged. | MonitoringWeekly Monday rolling 90-day check and material-change publication |
| Versionv9 | Date26-Jul-2026 | ChangeExpanded Timeline of Notable Activity from seven high-level entries to 18 operational developments spanning Akira casework, The Gentlemen affiliate scale and pre-encryption behavior, Q2 identity and supply-chain abuse, edge exploitation, dwell-time compression, BYOVD, public victimology, an edge-credential campaign, and Helix identity-led extortion. Added seven direct sources and kept their case, research, IR, leak-site, and disclosure populations separate. | MonitoringWeekly Monday rolling 90-day check and material-change publication |
| Versionv8 | Date26-Jul-2026 | ChangeRepositioned the product as the global ransomware ecosystem and operations view; corrected the stored coverage period to the full Apr 28–Jul 26 rolling window; explicitly separated worldwide June rankings from the companion U.S. SMB claim population; and removed an out-of-window March source from retained citations. | MonitoringWeekly Monday rolling 90-day check and material-change publication |
| Versionv7 | Date24-Jul-2026 | ChangeAdded the PETRA report database to the governed source audit and weekly monitor. The 90-day query returned no qualifying Apr 26–Jul 24 publication, so PETRA is recorded as checked but not used rather than presented as current-period evidence. | MonitoringWeekly Monday rolling 90-day check and material-change publication |
| Versionv6 | Date24-Jul-2026 | ChangeReplaced the abbreviated four-class Research Framing source summary with a complete Tier 0–Tier 8 audit showing checked, candidate-hit, selected, and not-used counts plus the retained and excluded source names in every tier. | MonitoringWeekly Monday rolling 90-day check and material-change publication |
| Versionv5 | Date24-Jul-2026 | ChangeAdded a source-cited donut chart showing The Gentlemen, Qilin, LockBit, and other listed-group shares in Check Point’s June public extortion dataset; retained the distinction between leak-site listings and independently confirmed intrusions. | MonitoringWeekly Monday rolling 90-day check and material-change publication |
| Versionv4 | Date24-Jul-2026 | ChangeRebuilt Research Framing with explicit source roles, methodology boundaries, and an executive decision standard; moved Timeline of Notable Activity ahead of BLUF; and expanded the timeline from four to seven milestones covering operator intelligence, downstream-provider exposure, leak-site activity, public victimology, pre-encryption decisions, and publication dates. | MonitoringWeekly Monday rolling 90-day check and material-change publication |
| Versionv3 | Date24-Jul-2026 | ChangeRebuilt the card to the Government Activity gold standard with shared banner, Research Framing, Persona / Audience, BLUF, Executive Summary, victimology, campaign and actor context, technology trust boundaries, timeline, top-10 monitoring table, best practices, AI Agent status, related IntelliOS products, and source-bound defaults. | MonitoringWeekly Monday rolling 90-day check and cumulative publication |
| Versionv2 | Date24-Jul-2026 | ChangeConverted the product to a rolling 90-day window and removed evidence that aged outside the active display period. | MonitoringSuperseded by v3 |
| Versionv1 | Date17-Jul-2026 | ChangeInitial Ransomware Rolling Intelligence Card publication. | MonitoringSuperseded by v3 |
Citations
Retained Sources and Claim Treatment
| # | Publisher | Published | Publication / Evidence | Why Used / Claim Treatment | Source |
|---|---|---|---|---|---|
| Source1 | PublisherCheck Point Research | Published2026-07-09 | Publication / evidenceSource indexprimary research | Why used / claim treatmentRansomware data-leak-site disclosures; published attacks are not independently confirmed incidents. | SourceA New Ransomware Leader Emerges as June 2026 Attack Volumes Climb Worldwide https://blog.checkpoint.com/research/a-new-ransomware-leader-emerges-as-june-2026-attack-volumes-climb-worldwide/ |
| Source2 | PublisherBlackFog | Published2026-07-02 | Publication / evidenceSource indexecosystem monitor | Why used / claim treatmentPublic disclosures and actor claims are retained separately; disputed attribution remains qualified. | SourceThe State of Ransomware: June 2026 https://www.blackfog.com/the-state-of-ransomware-june-2026/ |
| Source3 | PublisherCheck Point Research | Published2026-05-13 | Publication / evidenceSource indexprimary research | Why used / claim treatmentTradecraft is based on vendor analysis of leaked internal material; victim totals remain actor-published claims. | SourceWhen the Ransomware Gang Gets Hacked: The Gentlemen https://blog.checkpoint.com/research/when-the-ransomware-gang-gets-hacked-what-the-gentlemen-leak-reveals-about-modern-ransomware-risk/ |
| Source4 | PublisherAt-Bay | Published2026-05-13 | Publication / evidenceSource indexincident response | Why used / claim treatmentFirst-party case study of one Akira incident. The server count, demand, negotiated amount, and response timing are case-specific—not landscape prevalence or expected outcomes. | SourceInside an Akira Ransomware Attack: 60 Servers, Destroyed Backups, and an 85% Negotiated Reduction https://www.at-bay.com/case-studies/akira-ransomware-attack-case-study/ |
| Source5 | PublisherLevelBlue SpiderLabs | Published2026-05-18 | Publication / evidenceSource indexprimary research | Why used / claim treatmentLevelBlue separates observed and public operational evidence from an unverified underground offer of alleged Gentlemen-related data. Leak-site counts and underground material are not confirmed victim incidents. | SourceA Closer Look at The Gentlemen's Alleged Leak https://www.levelblue.com/blogs/spiderlabs-blog/a-closer-look-at-the-gentlemens-alleged-leak |
| Source6 | PublisherArete | Published2026-07-06 | Publication / evidenceSource indexincident response | Why used / claim treatmentMonthly Arete incident-response observations. Actor mix, tooling, and access findings remain bounded to Arete's evidence and are not a universal incident census. | SourceRansomware Trends & Data Insights: June 2026 https://areteir.com/resources/ransomware-trends-data-insights-june-2026 |
| Source7 | PublisherLevelBlue | Published2026-07-23 | Publication / evidenceSource indexincident response | Why used / claim treatmentFrontline Q2 incident-response findings across LevelBlue's integrated teams. Percentages describe the stated case population; they are not a global ransomware or victim census. | SourceLevelBlue TTP Briefing Q2 2026: Stolen Identities Outpace Defenses https://www.levelblue.com/blogs/spiderlabs-blog/ttp-briefing-q2-2026 |
| Source8 | PublisherPalo Alto Networks Unit 42 | Published2026-07-10 | Publication / evidenceSource indexprimary research | Why used / claim treatmentUnit 42 ransomware-operation analysis. Its Scorpius cluster names and attribution boundaries are preserved rather than silently merged with another vendor's actor identity. | SourceNo Manners Here: The Ruthless Rise of The Gentlemen Ransomware https://unit42.paloaltonetworks.com/the-gentlemen-ransomware/ |
| Source9 | PublisherArete | Published2026-07-14 | Publication / evidenceSource indexprimary research | Why used / claim treatmentArete synthesis of reported campaign evidence. Credential exposure and reported actor links do not prove that every exposed device was compromised or used for ransomware. | SourceFortiBleed Campaign Linked to INC and Lynx Ransomware Operations https://areteir.com/resources/fortibleed-campaign-linked-to-inc-and-lynx-ransomware-operations |
| Source10 | PublisherArete | Published2026-07-17 | Publication / evidenceSource indexprimary research | Why used / claim treatmentSource-qualified analysis of a newly reported identity-led extortion group. Suggested relationships to other actor ecosystems remain unresolved. | SourceHelix Extortion Group Debuts in SharePoint Data Theft Attacks https://areteir.com/resources/helix-extortion-group-debuts-in-sharepoint-data-theft-attacks |
| Source11 | PublisherBlack Kite | Published2026-07-27 | Publication / evidenceSource indexprimary research | Why used / claim treatmentBlack Kite annual public-disclosure and exposure-posture research. The April 2025-March 2026 victim count, June 2026 active-group count, and post-disclosure posture findings remain Black Kite methodology and are not added to June leak-site or U.S. SMB tracker populations. | Source2026 Ransomware Report https://blackkite.com/reports/2026-ransomware-report |
| Source12 | PublisherSophos | Published2026-07-22 | Publication / evidenceSource indexprimary research | Why used / claim treatmentVendor-agnostic survey of 2,158 IT and security leaders whose organizations were hit by ransomware in the previous 12 months. Survey outcomes inform preparedness and control priorities; they are not a measured incident-response or leak-site population. | SourceThe State of Ransomware 2026: Payments Drop as Encryption Climbs https://www.sophos.com/en-us/blog/sophos-state-of-ransomware-2026 |
| Source13 | PublisherProofpoint | Published2026-07-21 | Publication / evidenceSource indexprimary research | Why used / claim treatmentGlobal survey of security professionals on ransomware, AI-enabled social engineering, malicious-link entry, payment behavior, repeat extortion, and data theft. The survey measures respondent experience and perception, not verified incident prevalence. | Source2026 AI-Era Ransomware Report https://www.proofpoint.com/us/resources/threat-reports/ai-era-ransomware-report |
