< Back to all clusters
[CRIME] · Brazil, Thailand · 10 sources

started · updated

Ransomware attacks surge with AI-driven threats, Brazil hit hardest

New AI‑powered ransomware, termed agentic ransomware, embeds autonomous artificial‑intelligence agents that can conduct internal reconnaissance, adapt to defenses and selectively encrypt critical assets without needing external command‑and‑control servers. Hackers have already employed such autonomous AI agents to spy on Thailand’s Ministry of Finance.

Recent threat‑intelligence data shows ransomware activity is not declining. In the second quarter of 2026, global ransomware incidents rose 3% from the previous quarter, reaching 2,229 attacks. The Qilin group led the market with 301 victims, followed by The Gentlemen and DragonForce.

In Brazil, ransomware attacks grew 17.8% in 2025, placing the country ninth worldwide and first in Latin America. Attackers increasingly target hypervisor platforms and backup systems, with 93% of incidents focusing on destroying backups before encryption. Forensic data‑recovery services are gaining traction as an alternative to paying ransoms.

Quarter‑two 2026 security reports also highlight phishing as the dominant initial‑access technique, featuring a QR‑code phishing campaign that compromised Microsoft 365 accounts of Australian organisations. Ransomware accounted for over 20% of engagements, often delivered via legitimate remote‑monitoring tools such as trojanized MeshAgent and Zoho Assist.

Entities

Agentic ransomware · Brazil · DragonForce ransomware group · Japan TeleNet Co., Ltd. · Nichirei Corp. · Qilin ransomware group · RansomHouse · Thailand Ministry of Finance

Claims

What the coverage asserts, and how many sources carry each claim.

  • [○ 1 SOURCE] Hackers used an autonomous AI agent to spy on Thailand’s Ministry of Finance. thecyberwire.com
  • [DISPUTED] The Qilin ransomware group recorded 301 victims in Q2 2026, the highest among ransomware groups. www.zdnet.com
  • [○ 1 SOURCE] Agentic ransomware embeds AI agents that autonomously perform reconnaissance and encrypt critical data without external C2 servers. que.com
  • [○ 1 SOURCE] Phishing was the primary initial‑access technique in over half of Cisco Talos IR engagements in Q2 2026. nationalcybersecurity.com
  • [○ 1 SOURCE] In Brazil, 93% of ransomware attacks targeted backup infrastructures, and groups also focused on hypervisor platforms such as VMware ESXi and Microsoft Hyper‑V. leianoticias.com.br
  • [○ 1 SOURCE] Ransomware attacks grew 17.8% worldwide in 2025, with Brazil ranking ninth globally and leading Latin America. leianoticias.com.br
  • [○ 1 SOURCE] A QR‑code phishing campaign targeting Australian organisations used compromised Microsoft 365 accounts to harvest credentials throughout Q2 2026. nationalcybersecurity.com
  • [○ 1 SOURCE] Global ransomware attacks increased 3% in Q2 2026, totaling 2,229 incidents. www.zdnet.com