Skip to content
Tech News
← Back to articles

Ransomware Is Accelerating, But It's Not Because of AI

read original more articles
Why This Matters

The rapid acceleration of ransomware attacks highlights the increasing sophistication and scale of cyber threats facing both enterprises and consumers. This surge underscores the urgent need for stronger cybersecurity defenses and proactive threat mitigation strategies across industries.

Key Takeaways

Ransomware is not just growing, it is actually accelerating, with activity surging between October 2025 and March 2026, as more than 60 new groups entered an increasingly crowded criminal ecosystem.

For enterprises, the surge means not only more attacks but also a larger and constantly changing pool of adversaries to track and defend against.

25% Increase in Incident Volume

Black Kite analyzed ransomware incidents between April 1, 2025, and March 31, 2026, and identified 7,551 known victims worldwide. That represented a 25% increase over the previous 12-month period, with much of the growth concentrated in the second half of the year. Black Kite counted 2,904 victims between April and September 2025 and 4,647 between October 2025 and March 2026, marking a 60% increase in reported ransomware victims. March 2026 was the busiest month with as many as 861 organizations — or nearly 28 per day — falling victim to a ransomware attack.

Related:'WP2Shell' Opens Millions of WordPress Sites to Remote Takeover

"This isn't a problem we've contained," says Ferhat Dikbiyik, chief research and intelligence officer at Black Kite. "It's still a lucrative business, and the barrier to running one keeps getting lower."

Black Kite attributed the growth in attack volume to a combination of factors, including the fragmentation of the ransomware ecosystem, the emergence of dozens of new groups, and an expansion of attacks on small and less defended organizations. The company also pointed to third-party and supply chain compromises, such as those involving Oracle and Salesforce as allowing attackers to leverage a single breach into multivictim campaigns. "Groups like Qilin redefined what a single attack looks like, with one [managed service provider or MSP] compromise reaching 32 South Korean financial institutions," Dikbiyik notes. "One vendor, dozens of victims."

Many Victims Had Externally Visible Weaknesses

One consistent pattern Black Kite uncovered was that many victims had high ransomware susceptibility index (RSI) scores — a measure the company uses to assesses an organization's exposure to ransomware attacks based on externally visible factors like exposed credentials and unpatched vulnerabilities. Some 41% of companies that had an RSI higher than 0.8 experienced a ransomware incident during the study period, compared to just 0.14% of organizations with scores below 0.2. More than 90% of victims showed a meaningful spike in their RSI score just before being hit.

Susceptibility comes down to exposure and predisposition, Dikbiyik points out. "Exposure is what's externally visible: misconfigurations, exposed remote access, credential stuffing, stealer logs," he says. "Predisposition is who you are, your geography, your industry, your revenue band, the size of your digital footprint." Most victims, Dikbiyik adds, weren't breached because they were uniquely weak. "They were breached because they were visible, exposed, and a fit for what attackers were already looking for."

... continue reading