AI-driven ransomware attacks spike in early 2026, hitting thousands of firms worldwide
In the first quarter of 2026, ransomware activity surged despite a decline in the number of active criminal groups. Check Point analysts reported that over 2,000 organisations were compromised, roughly 700 each month, as remaining gangs use artificial intelligence to compress the attack lifecycle from days to minutes. Sergey Shykevich warned that "AI is shortening the attack life‑cycle – from gaining access to exploitation – making existing exposure points more dangerous than ever."
Fortinet’s 2026 Global Threat Landscape Report documented a 389 % year‑over‑year rise in ransomware victims, identifying 7,831 confirmed cases worldwide, up from about 1,600 a year earlier. The report linked the surge to the availability of AI‑powered toolsets such as WormGPT, FraudGPT and BruteForceAI. The most affected sectors were manufacturing (1,284 victims), business services (824) and retail (682). Geographically, the United States accounted for 3,381 attacks, followed by Canada (374) and Germany (291).
Four largest ransomware gangs now control close to 40 % of successful breaches, allowing them to target high‑value industries where downtime is costly. Experts advise moving beyond endpoint security toward zero‑trust network architectures and continuous exposure management to mitigate the accelerated, AI‑enhanced threat.