# Global ransomware threat landscape 2026

> Live situation record from CLSTR: https://clstr.news/situations/q1-2026-ransomware-wave-largely-undisclosed-and-often-triggered-by-identity-breaches
> Updated: 2026-07-22T17:12:28.000Z. Sources: 113. Developments: 38.

Through mid‑2026 the ransomware ecosystem kept accelerating, driven by AI‑powered toolkits and expanding RaaS franchise models. Dwell times lengthened and ransom‑payment rates rose, with AI‑generated threats rated the top global risk. U.S. cyber‑enabled crime losses hit $20.9 billion in 2025 and the average breach cost a record $10.22 million. A July Portuguese report recorded a 29 % jump in weekly attacks (averaging 2,639 incidents), while ransomware activity grew 33 % year‑on‑year, most often hitting education, public administration and telecoms. The gang “The Gentlemen” accounted for 17 % of June attacks. Generative‑AI misuse surfaced as a data‑leak vector, with one in 26 corporate AI prompts flagged high‑risk, affecting 85 % of firms using such tools. Compromised credentials now initiate 79 % of ransomware incidents, overtaking exploited vulnerabilities. Malicious‑email and phishing still represent 50 % of attacks, but new large‑scale phishing kits such as “Jalisco” and “OmegaLord” exploit MFA weaknesses in Microsoft 365 accounts. Average ransom demands have slipped, yet mean post‑attack restoration costs sit near $1.7 million, with the UK seeing the highest median demand at $2.5 million. Quishing – fraudulent QR‑code phishing – made up 4.8 % of detected email threats in Portugal and now accounts for 11 % of phishing emails in Brazil, with roughly 100 000 monthly detections. Chile shows a similar surge, reaching 12 % of phishing attacks and a 146 % incident rise in early 2026. Analysts project global cyber‑crime expenses to climb from $10.5 trillion in 2025 to $12.2 trillion by 2031, with daily ransomware damage expected to rise from $156 million to over $726 million. A medium‑size manufacturing firm could face $1.46 million in ransomware losses and 100 days of recovery.

## Timeline

### 2026-07-22: QR Code Phishing Hits 11% of Brazil Email Attacks, Experts Warn of Rapid Rise

QR code phishing now accounts for 11% of Brazil’s email attacks, surging from 0.8% in 2021 to over 12% and prompting calls for heightened user vigilance.

15 sources. https://clstr.news/cluster/qr-code-phishing-quishing-surges-globally

### 2026-07-20: Portugal reports QR code phishing as seventh most common email threat

ESET reports QR‑code phishing (“quishing”) made up 4.8% of Portugal’s email threats Dec 2025‑May 2026, ranking seventh, with ~100 k monthly detections and 11% of global phishing using QR codes.

2 sources. https://clstr.news/cluster/portugal-reports-qr-code-phishing-as-seventh-most-common-email-threat

### 2026-07-20: Global Cybercrime Costs Projected to Exceed $12 Trillion by 2031

Cybercrime costs could hit $12.2 trillion by 2031, with daily ransomware losses projected to top $726 million; a new calculator estimates $1.46 million for a typical mid‑size firm, and a list of 25 major cyber‑

2 sources. https://clstr.news/cluster/global-cybercrime-costs-projected-to-exceed-12-trillion-by-2031

### 2026-07-16: Cyber insurance at inflection point amid rising AI-driven threats and falling premiums

S&P Global Ratings says rising AI‑driven cyber threats and falling premiums put the global cyber‑insurance market at an inflection point, forcing insurers to choose modest price hikes or risk technical losses;

2 sources. https://clstr.news/cluster/cyber-insurance-at-inflection-point-amid-rising-ai-driven-threats-and-falling-premiums

### 2026-07-15: Ransomware attacks pivot to compromised identities in 2026

Sophos reports 79% of ransomware attacks now start with compromised credentials; phishing tops entry vectors, MFA gaps persist, recovery costs stay high. Italy and Brazil rank among the top ten countries hit by

8 sources. https://clstr.news/cluster/brazil-joins-top10-list-of-countries-most-targeted-by-ransomware

### 2026-07-15: Cyber Insurance Market to Reach $32.2 B by 2030

Cyber‑insurance is set to more than double to $32.2 B by 2030, driven by ransomware, regulation and AI‑enhanced risk models, with North America leading the market.

3 sources. https://clstr.news/cluster/cyber-insurance-market-to-reach-322-b-by-2030

### 2026-07-13: Portugal reports 29% rise in cyber attacks, 2,639 incidents per week

June 2026 saw Portugal record 2,639 weekly cyber‑attacks, a 29% YoY rise, with ransomware surging and generative‑AI prompts exposing sensitive data in most firms.

2 sources. https://clstr.news/cluster/portugal-reports-29-rise-in-cyber-attacks-2639-incidents-per-week

### 2026-07-07: American Users Shift Trust as Cybercrime and Spam Surge

US consumers face rising spam calls, phishing and $20 B in cyber losses, prompting greater distrust of tech services and reliance on advanced security measures.

2 sources. https://clstr.news/cluster/american-users-shift-trust-as-cybercrime-and-spam-surge

### 2026-06-30: US cybercrime losses top $20 billion as insurance market faces rising claims

U.S. cybercrime losses hit $20.9 billion in 2025, while the cyber‑insurance market struggles with a 53 % loss ratio and rising third‑party claims.

3 sources. https://clstr.news/cluster/united-states-cybercrime-losses-hit-209-billion-straining-cyberinsurance-market

### 2026-06-25: ExtraHop Study Finds 49% of Ransomware Victims Detect Intrusion Only After Data Loss

ExtraHop reports 49% of ransomware victims detect attacks only after data theft, dwell time averages 2.5 weeks, ransom payments drop to $2.8 M but 83% still pay, and AI infrastructure is now the top security‑at

2 sources. https://clstr.news/cluster/extrahop-study-finds-49-of-ransomware-victims-detect-intrusion-only-after-data-loss

### 2026-06-19: Portugal and Brazil report sharp rise in ransomware and operational cyber attacks

Portugal and Brazil face rising ransomware and operational cyber attacks, with Portugal seeing a 48% ransomware jump and Brazil reporting 3,348 weekly attempts per firm, prompting calls for stronger continuity‑

2 sources. https://clstr.news/cluster/portugal-and-brazil-report-sharp-rise-in-ransomware-and-operational-cyber-attacks

### 2026-06-14: Global Cybersecurity Threats Surge Across Sectors in 2026

Cyber attacks spike in 2026, hitting tourism, businesses and governments; Vietnam sees 502 M data leaks, Dominican Republic reports AI‑driven attacks, and Spain's S2 Grupo posts 54% revenue growth.

7 sources. https://clstr.news/cluster/cybersecurity-becomes-top-priority-for-companies-and-governments-worldwide

### 2026-06-12: Latin American Firms Face Rising Cybersecurity and Fraud Risks

Latin American businesses report high cybersecurity incidents and prioritize fraud and data security, with Argentine firms facing 76% incident rates and SMEs in eight countries highlighting protection as a key‑

2 sources. https://clstr.news/cluster/latin-american-firms-face-rising-cybersecurity-and-fraud-risks

### 2026-06-10: Construction industry faces surge in ransomware attacks, report shows

A QBE‑Control Risks report finds construction leads global ransomware attacks in 2025, with digitalisation expanding vulnerabilities and EU NIS2 tightening rules.

2 sources. https://clstr.news/cluster/construction-industry-faces-surge-in-ransomware-attacks-report-shows

### 2026-06-08: Silent Ransom Group uses fast‑flux botnet to extort US law firms

Silent Ransom Group has extorted dozens of U.S. law firms, using in‑person USB theft and a fast‑flux botnet across 18 countries to host data‑leak sites.

2 sources. https://clstr.news/cluster/silent-ransom-group-uses-fastflux-botnet-to-extort-us-law-firms

### 2026-06-06: Cyber‑crime groups recruit attackers with crypto payouts and rapid physical infiltrations across Europe

Russian hackers offer crypto rewards for attacks on Europe, while Silent Ransom Group adds quick physical infiltrations and AI‑driven phishing, highlighting a surge in low‑cost, profitable cyber‑crime.

2 sources. https://clstr.news/cluster/cybercrime-groups-recruit-attackers-with-crypto-payouts-and-rapid-physical-infiltrations-across-euro

### 2026-06-06: Hack‑for‑Hire groups and ransomware gang adopt new infiltration tactics

Hack‑for‑hire services target journalists and officials in MENA and beyond, while the Silent Ransom Group uses fake tech staff to steal data and extort victims without encrypting files.

4 sources. https://clstr.news/cluster/hackforhire-groups-and-ransomware-gang-adopt-new-infiltration-tactics

### 2026-06-06: Cybersecurity Costs Strain Companies and Investors, Global Study Finds

Stricter digital security measures increase compliance costs and hinder investors, while global cybercrime costs trillions, drives ransomware spikes and pushes cybersecurity spending past $1 trillion.

2 sources. https://clstr.news/cluster/cybersecurity-costs-strain-companies-and-investors-global-study-finds

### 2026-06-05: Silent Ransom Group escalates ransomware attacks with physical IT imposters

Silent Ransom Group (UNC3753) targeted U.S. firms, adding in‑person IT imposters who stole data with USB drives, prompting FBI and Google alerts about the new ransomware escalation.

4 sources. https://clstr.news/cluster/silent-ransom-group-escalates-ransomware-attacks-with-physical-it-imposters

### 2026-06-05: Silent Ransom Group’s physical law‑firm attacks and Google’s Android deep‑fake call protection

Polish law firms face physical ransomware attacks by Silent Ransom Group, while Google launches Android deep‑fake call detection to block spoofed scams.

2 sources. https://clstr.news/cluster/silent-ransom-groups-physical-lawfirm-attacks-and-googles-android-deepfake-call-protection

### 2026-06-05: Ransomware leverages vulnerable drivers and remote encryption to bypass defenses

Warlock ransomware uses vulnerable drivers to disable security tools, while ransomware’s remote encryption rise prompts defenses like Sophos CryptoGuard that monitor file operations to block attacks.

2 sources. https://clstr.news/cluster/ransomware-leverages-vulnerable-drivers-and-remote-encryption-to-bypass-defenses

### 2026-06-02: 2026 Cybersecurity Landscape: Rise of Multi‑Extortion Ransomware and Shift to End‑to‑End Encrypted File Sharing

2026 sees ransomware adopting multi‑extortion and AI‑driven attacks, while firms adopt end‑to‑end encrypted file‑sharing tools like Proton Drive and Tresorit for stronger data protection.

2 sources. https://clstr.news/cluster/2026-cybersecurity-landscape-rise-of-multiextortion-ransomware-and-shift-to-endtoend-encrypted-file-

### 2026-05-29: Ransomware groups Everest and Chaos attack firms in Colombia and United States

Everest ransomware hit a Colombian firm and Chaos ransomware struck U.S. retailer Powerhouse, both threatening data leaks and demanding negotiations.

2 sources. https://clstr.news/cluster/ransomware-groups-everest-and-chaos-attack-firms-in-colombia-and-united-states

### 2026-05-29: Kaspersky report finds ransomware attacks falling yet becoming more industrialized

Kaspersky’s 2026 report shows ransomware attacks slightly down but more industrialized, with data theft focus, post‑quantum crypto, and rising EDR‑killer use.

2 sources. https://clstr.news/cluster/kaspersky-report-finds-ransomware-attacks-falling-yet-becoming-more-industrialized

### 2026-05-28: FBI warns of new in‑person ransomware attacks targeting law firms

The FBI warns that attackers now pose as IT support, enter offices, and install devices to steal data for ransom, targeting law firms and other sectors.

2 sources. https://clstr.news/cluster/fbi-warns-of-new-inperson-ransomware-attacks-targeting-law-firms

### 2026-05-27: US Law Firms Face Surge in Cyber Extortion and Data Breaches

A ransomware group stole 700 GB of client data from a West Virginia law firm, and the FBI warned that the Silent Ransom Group is targeting U.S. law firms with phishing, fake IT calls, and in‑person visits to ex

8 sources. https://clstr.news/cluster/us-law-firms-face-surge-in-cyber-extortion-and-data-breaches

### 2026-05-25: Spain's 2025 Cybersecurity Report Highlights Ransomware as Leading Threat

Spain's Yarix 2025 report, based on 1,000 incidents, names ransomware and data leaks as top cyber threats, especially to finance, energy, transport and public sectors, and calls for automated, early‑detection C

2 sources. https://clstr.news/cluster/spains-2025-cybersecurity-report-highlights-ransomware-as-leading-threat

### 2026-05-24: Foxconn confirms ransomware attack on US factories, 8 TB data stolen by Nitrogen group

Foxconn acknowledged a ransomware breach by Nitrogen that stole about 8 TB of data and disrupted its Wisconsin and Texas factories.

2 sources. https://clstr.news/cluster/foxconn-confirms-ransomware-attack-on-us-factories-8-tb-data-stolen-by-nitrogen-group

### 2026-05-24: Latin America Tops Global Ransomware Rates as Threats Shift to Post‑Quantum Tactics

Latin America led ransomware attacks in 2025 at 8.13% of firms, while global threats evolve with post‑quantum encryption, encryptionless extortion and advanced evasion tools.

2 sources. https://clstr.news/cluster/latin-america-tops-global-ransomware-rates-as-threats-shift-to-postquantum-tactics

### 2026-05-20: Ransomware gangs use stolen personal data to threaten victims with real‑world violence

Ransomware groups use stolen personal data to threaten victims with real‑world violence, hiring locals for intimidation.

2 sources. https://clstr.news/cluster/ransomware-gangs-use-stolen-personal-data-to-threaten-victims-with-realworld-violence

### 2026-05-18: Ransomware Threat Targets Venezuelan Manufacturing in 2026

ESET warns ransomware will target Venezuelan factories in 2026 and remains a top threat to Spanish firms.

5 sources. https://clstr.news/cluster/ransomware-threat-targets-venezuelan-manufacturing-in-2026

### 2026-05-16: AI‑Powered Cyber Attacks Drive Surge in Cybersecurity Spending and Stock Volatility

AI‑driven hacks boost ransomware, cost $1.1T, push cybersecurity firms to raise R&D and spur stock focus on AI‑resilient vendors.

4 sources. https://clstr.news/cluster/aipowered-cyber-attacks-drive-surge-in-cybersecurity-spending-and-stock-volatility

### 2026-05-15: Foxconn cyberattack hits North American factories, threatens AI server supply

Foxconn confirmed a ransomware attack on its North American factories, halting AI server production and prompting data‑theft claims.

3 sources. https://clstr.news/cluster/foxconn-cyberattack-disrupts-north-american-ai-server-production

### 2026-05-14: AI-Enabled Ransomware Threats Prompt Calls for Terrorism Designation

Ransomware now AI-driven and faster, spurring calls to label it terrorism and urging stronger, AI‑based defenses.

2 sources. https://clstr.news/cluster/ai-enabled-ransomware-threats-prompt-calls-for-terrorism-designation

### 2026-05-14: Fortinet reports rising AI-driven cyber threats in Philippines and Canada

Fortinet warns of growing AI‑driven cyber threats in the Philippines and a surge in ransomware attacks in Canada.

4 sources. https://clstr.news/cluster/fortinet-reports-rising-ai-driven-cyber-threats-in-philippines-and-canada

### 2026-05-13: Ransomware attacks become more organized in 2026, fueled by AI and fewer powerful groups

Ransomware attacks in 2026 are driven by AI and fewer powerful groups, targeting mainly the US and causing extensive downtime.

2 sources. https://clstr.news/cluster/ransomware-attacks-become-more-organized-in-2026-fueled-by-ai-and-fewer-powerful-groups

### 2026-05-12: AI-driven ransomware attacks spike in early 2026, hitting thousands of firms worldwide

AI accelerates ransomware, causing a 389% rise in Q1 2026 with thousands of victims in the US, Canada and Germany.

3 sources. https://clstr.news/cluster/ai-driven-ransomware-attacks-spike-in-early-2026-hitting-thousands-of-firms-worldwide

### 2026-05-07: BlackFog report reveals 2,160 hidden ransomware attacks in Q1 2026

BlackFog says Q1 2026 saw 2,160 undisclosed ransomware attacks, far outpacing the 264 disclosed, with the US as the primary target.

5 sources. https://clstr.news/cluster/blackfog-report-reveals-2160-hidden-ransomware-attacks-in-q1-2026

---
Cite as: Global ransomware threat landscape 2026. CLSTR, https://clstr.news/situations/q1-2026-ransomware-wave-largely-undisclosed-and-often-triggered-by-identity-breaches
