< Back to all clusters
[TECHNOLOGY] · United States · 5 sources

BlackFog report reveals 2,160 hidden ransomware attacks in Q1 2026

A security‑firm study for the first quarter of 2026 found that only about 10% of ransomware incidents were publicly disclosed. BlackFog identified 264 disclosed attacks versus 2,160 undisclosed ones, indicating that most breaches are kept secret.

The United States was the most frequently targeted nation, accounting for roughly half of the hidden incidents (1,070) and 61% of the disclosed cases. Manufacturing topped the list of sectors hit by undisclosed attacks, while healthcare led among disclosed incidents. The Qilin ransomware gang was the most active group overall, responsible for 16% of hidden and 8% of public attacks. New threat actors such as The Gentlemen and Akira rose in the undisclosed segment, and ShinyHunters and INC were prominent among disclosed incidents.

Data exfiltration featured in 96% of public attacks. Researchers also noted the growing use of tools like the Venom Stealer delivered via ClickFix and a new command‑and‑control framework called Lotus C2. A parallel concern is the rise of “shadow AI,” with up to 58% of employees using unapproved AI applications, potentially expanding attack surfaces.