Monitor this situation.
Unsubscribe anytime.
[SITUATION] · [QUIET] · [TECHNOLOGY]
33 clusters · 180 sources · 115 days · First seen · Last updated
AI-driven ransomware surge and evolving global threats
Overview
The ransomware landscape is undergoing a structural shift, characterized by an increase in active criminal groups and the integration of AI. The number of active groups rose from 71 to 93 in the second quarter of 2026. While the top 10 groups now account for a smaller share of victims (57.6%), total victims recorded on leak sites reached 2,139, a 33% year-over-year increase. Notably, the group ‘The Gentlemen’ saw 62% growth, with evidence suggesting AI coding assistants allow small teams to develop management panels in just days. Meanwhile, ransom payment rates have hit a multi-year low of approximately 23%. Qilin remains a prolific operator, but ‘The Gentlemen’ briefly overtook them in June. New technical threats are emerging, such as the DeadLock ransomware and the Aeternum botnet, both of which utilize the Polygon blockchain to create resilient command-and-control mechanisms that evade conventional takedowns. Specific threats continue to target critical infrastructure. The Gunra ransomware-as-a-service operation, also known as ‘Golden Community,’ has prompted a joint advisory from the FBI, CISA, NSA, and South Korea’s National Police Agency. Gunra, a Conti-derived operation, exploits Fortinet firewall and VPN vulnerabilities to target healthcare, financial, and government sectors. The group utilizes a double-extortion model, often demanding ransoms exceeding $10 million. Technical analysis revealed that Gunra can subvert multi-factor authentication by modifying virtual desktop infrastructure files through techniques such as session hijacking. This aligns with a broader trend in the Americas, where attackers are increasingly weaponizing edge infrastructure from providers like Ivanti, Cisco, and Palo Alto Networks to maximize pressure through high-leverage data exfiltration. Recent developments highlight the growing impact of AI, with 89% of surveyed financial providers reporting an increase in AI-driven attacks. These include automated phishing and ‘counter incident response’ tactics, where attackers delete logs to thwart security teams.
Entities
Claims
What the coverage asserts, and how many sources carry each claim.
Coverage disagrees
Sources make claims that cannot both be true. CLSTR reports the disagreement; it does not decide who is right.
-
"Qilin was the most prolific ransomware operator for the fourth consecutive quarter with 279 victims."
vs
"The Qilin ransomware group recorded 301 victims in Q2 2026, the highest among ransomware groups."
The claims provide different victim counts (279 vs 301) for the Qilin ransomware group's activity in the same period.
- [DISPUTED] Qilin was the most prolific ransomware operator for the fourth consecutive quarter with 279 victims.
- [DISPUTED] The Qilin ransomware group recorded 301 victims in Q2 2026, the highest among ransomware groups.
- [● 8 SOURCES] Gunra ransomware targets critical infrastructure in healthcare, finance, and government sectors.
- [● 6 SOURCES] Gunra exploits Fortinet vulnerabilities CVE-2024-55591 and CVE-2025-24472 for initial access.
- [● 5 SOURCES] Gunra operates as a ransomware-as-a-service (RaaS) program.
- [● 4 SOURCES] DeadLock ransomware uses the Polygon blockchain to store configuration data and leak site posts.
- [● 3 SOURCES] Artificial intelligence is being used to detect cyber threats and accelerate vulnerability discovery.
- [● 3 SOURCES] Gunra has been known to demand ransom amounts exceeding $10 million.
- [● 2 SOURCES] Fortinet introduced a pay‑per‑use security model for SMEs in Spain.
- [● 2 SOURCES] DeadLock employs a hybrid cryptographic design using Curve25519 and XChaCha20.
Timeline
-
21 days ago
[TECHNOLOGY] 2 sourcesCybersecurity industry shifts toward AI platforms to combat rising ransomware threatsRising ransomware threats from groups like Qilin and the rise of RaaS are outpacing traditional EDR defenses, driving a shift toward AI-driven security platforms and integrated multi-layered protection.
-
about 1 month ago
[TECHNOLOGY] 6 sourcesGunra ransomware exploits Fortinet flaws to bypass MFAThe Gunra ransomware group is bypassing MFA by exploiting Fortinet vulnerabilities, marking a broader shift toward infrastructure-based attacks and data extortion in the 2026 cyber threat landscape.
-
about 1 month ago
[TECHNOLOGY] 26 sourcesRansomware landscape shifts as active groups hit record high in Q2 2026Ransomware activity in Q2 2026 shows a rise in active groups to 93 and increased use of AI tools by criminals, even as ransom payment rates fall to a multi-year low of 23%.
-
about 1 month ago
[TECHNOLOGY] 14 sourcesGunra ransomware targets critical infrastructure via Fortinet flawsUS and South Korean authorities warn of Gunra ransomware, a RaaS operation exploiting Fortinet vulnerabilities to target critical infrastructure via double-extortion tactics.
-
about 1 month ago
[TECHNOLOGY] 8 sourcesCybersecurity trends show rising ransomware focus on disabling backups and internal defensesCybersecurity reports reveal that while perimeter defenses are improving, attackers successfully bypass internal controls 63% of the time, often disabling backups and EDR tools to hinder recovery.
-
about 1 month ago
[TECHNOLOGY] 3 sourcesFinancial sector sees surge in AI-driven cyberattacksTrendAI reports that 89% of financial service providers are seeing an increase in AI-powered cyberattacks, including automated phishing, ransomware, and attempts to bypass security teams.
-
about 2 months ago
[TECHNOLOGY] 14 sourcesLatin America faces surge in AI‑driven cyber threatsAI boosts cyber defenses but also speeds exploit creation; 52.7% of Latin American firms saw attacks, ransomware rose 16.5% in H1 2026, and patch delays average 16 days, while Spain adopts pay‑per‑use security,
-
about 2 months ago
[TECHNOLOGY] 5 sourcesMexico sees 38% rise in ransomware attacks on businesses, AI use up 90%Ransomware attacks on Mexican firms rose 38% last year, AI‑driven attacks up 90%; average recovery cost $1.35 million, 70% of ransoms exceed $1 million, amid a shortage of 77,000 security experts.
-
about 2 months ago
[CRIME] 10 sourcesRansomware attacks surge with AI-driven threats, Brazil hit hardestAI‑driven agentic ransomware is rising, with attacks up 3% globally in Q2 2026 and 17.8% in Brazil, where hypervisor and backup targets dominate; phishing remains the main entry vector.
-
about 2 months ago
[TECHNOLOGY] 9 sourcesProofpoint AI‑Era Ransomware Report Shows AI Boosts Attack SuccessAI is boosting ransomware success (65% of attacks) and accelerating cyber‑crime, while firms ramp up AI defenses amid a 77% rise in AI‑driven fraud.
-
about 2 months ago
[TECHNOLOGY] 2 sourcesRansomware up 23% globally as Brazil's army warns of combined cyber‑AI threatsRansomware attacks rose 23% in June 2026, targeting corporate access points, as Brazil's army reports cyber‑AI threats now form a unified strategic challenge.
-
about 2 months ago
[CRIME] 13 sourcesRansomware attacks surge as compromised identities and AI tools fuel new threatsCompromised credentials now drive 79% of ransomware attacks, AI‑enhanced groups like BlackMamba target hospitals, and governments move to ban ransom payments.
-
2 months ago
[TECHNOLOGY] 2 sourcesSmall Business Cybersecurity Guides Focus on Simple, Low-Cost MeasuresGuides urge small businesses to adopt simple, low‑cost cybersecurity steps—employee training, MFA, password managers—while avoiding pricey, unnecessary tools and noting insurance won’t prevent attacks.
-
2 months ago
[TECHNOLOGY] 2 sourcesCorporate Backup Strategies to Counter Ransomware and Wiper AttacksStudies reveal most firms lack proper backup safeguards against ransomware and wiper attacks; only a minority isolate and test backups, prompting calls for immutable storage, strict isolation, and comprehensive
-
2 months ago
[BUSINESS] 7 sourcesSmall businesses face growing cyber‑insurance and backup challengesSmall firms are urged to adopt immutable backups as insurers tighten requirements; cyber spending now rivals rent, with many still lacking proper insurance and confidence in data protection.
-
2 months ago
[TECHNOLOGY] 7 sourcesAI Agent ‘JadePuffer’ Executes First Fully Autonomous Ransomware AttackResearchers report JadePuffer, the first ransomware run entirely by an AI agent, which exploited a Langflow flaw, auto‑adapted during the attack, and was set up by a human operator.
-
2 months ago
[TECHNOLOGY] 28 sourcesJadePuffer AI Agent Executes First Fully Autonomous Ransomware AttackSysdig reports JadePuffer, an autonomous AI agent, carried out a full ransomware attack via a Langflow bug, encrypting 1,342 records and adapting in 31 seconds, marking the first documented agentic ransomware.
-
3 months ago
[TECHNOLOGY] 5 sourcesAI Agent JadePuffer Executes First Fully Autonomous Ransomware AttackSysdig reports JadePuffer, the first fully autonomous AI‑driven ransomware, exploiting Langflow (CVE‑2025‑3248) and Nacos vulnerabilities to encrypt data and demand Bitcoin, highlighting a new threat model for
-
3 months ago
[TECHNOLOGY] 2 sourcesAI logistics sector sees governance framework rollout and surge in cargo theftsNMFTA released a free AI governance framework for logistics, while U.S. police busted a multi‑state theft ring stealing $1.3 M of AI data‑center equipment.
-
3 months ago
[TECHNOLOGY] 3 sourcesRansomware Threats Escalate, Targeting Global Financial SystemsRansomware in 2026 uses AI to target executives, adds triple extortion and attacks IoT, disrupting payment rails, banking platforms and trading systems, threatening global financial stability.
-
3 months ago
[TECHNOLOGY] 2 sourcesSonicWall warns healthcare cyberattacks stay high despite overall decline in 2026SonicWall’s 2026 Healthcare Protect Brief shows cyber‑attacks on hospitals declined only 17 %, far less than other sectors, driven by exposed remote‑desktop tools, IoT devices and legacy VPNs; ten ransomware —
-
3 months ago
[TECHNOLOGY] 5 sourcesRansomware Defense Shifts Toward Resilience and Identity‑Based ProtectionRansomware guidance urges healthcare and Canadian organisations to adopt cyber‑resilience, focusing on identity‑based security as attackers develop tools to disable EDR defenses.
-
3 months ago
[TECHNOLOGY] 3 sourcesRansomware attacks surge 48% globally in May 2026May 2026 saw a 48 % global rise in ransomware attacks to 698 incidents, with major growth in Asia and heightened targeting of Android devices and private users.
-
3 months ago
[TECHNOLOGY] 2 sourcesAI‑driven ransomware threats push firms toward immutable backup solutionsIT leaders fear AI‑driven ransomware, but many lack immutable backups; CyberSense wins award for AI‑based ransomware recovery platform that verifies backup integrity.
-
3 months ago
[TECHNOLOGY] 2 sourcesAI-Driven Healthcare Ransomware Risks and FBI Cyber Range Highlight Expanding Cyber ThreatsAgentic AI in healthcare heightens ransomware risks, while the FBI's new Alabama cyber range simulates attacks across homes, hospitals and infrastructure, highlighting expanding cyber threats.
-
3 months ago
[CRIME] 2 sourcesRansomware Surge Driven by AI and Healthcare Data Threatens Global CybersecurityRansomware activity hit record levels in Q1 2026, boosted by AI‑generated phishing and deep‑fakes, while stolen healthcare data fuels a lucrative underground market, raising global cyber risk.
-
3 months ago
[HEALTH] 2 sourcesHealthcare data breaches spur cybercrime market and push stronger vendor security rulesHealth‑ISAC urges tighter third‑party governance as TrendAI shows a global cybercrime market exploiting stolen patient data, with ransomware and vendor compromises driving multimillion‑dollar losses.
-
3 months ago
[CRIME] 2 sourcesHealthcare data emerges as top cybercrime commodityTrendAI finds stolen health records now drive a mature cybercrime market, with ransomware sales making up 36% of activity and vendors serving as supply‑chain multipliers.
-
4 months ago
[TECHNOLOGY] 2 sourcesIndiana K‑12 schools face surge in cyberattacks, prompting stronger data‑security measuresIndiana K‑12 schools report a sharp rise in cyberattacks, prompting costly fixes and a push for stronger data‑security practices.
-
4 months ago
[TECHNOLOGY] 2 sourcesSK Shield reports South Korean SMEs take average 106 days to respond to cyber attacksSK Shield says South Korean SMEs need 106 days on average to detect and start responding to cyber attacks, with ransomware and data theft most common.
-
4 months ago
[TECHNOLOGY] 2 sourcesNigeria's NITDA alerts to AI-driven 'DeepLoad' malware targeting banks and government agenciesNigeria's NITDA warns that AI‑driven 'DeepLoad' malware is stealing banking credentials and data from banks, agencies and citizens.
-
4 months ago
[TECHNOLOGY] 3 sourcesCybercrime Surge Threatens African Enterprises and Global Small BusinessesCybercrime now makes up over 30% of crimes in parts of Africa, prompting calls for stronger institutional defenses and basic security steps for businesses.
-
5 months ago
[TECHNOLOGY] 2 sourcesIndia faces 505 cyber threats per minute as credential theft spikes, report saysIndia logged 265 million cyber detections (505 per minute) in 2025, with credential theft surging against IT firms, report warns.
Sources
24x7mag.com · 4sysops.com · abcmoney.co.uk · addicted2success.com · affinitymsp.com.au · aktiencheck · analyticsinsight.net · audiencescience.com · australiancybersecuritymagazine.com.au · australianmanufacturing.com.au · avantionline.it · b2b-cyber-security.de · bankofalbuquerque.com · bhaskarlive.in · bhconsulting.ie · bitcoinethereumnews.com · bitmat.it · bleepingcomputer.com · blogspan.net · boardagenda.com · bookclubz.com · borncity.com · brasil247.com · bright.nl · businessdiary.com.ph · businessnewsthisweek.com · businesstechweekly.com · byline.network · calibre800.com · capminds.com · channelinsider.com · christelijknieuws.nl · cioafrica.co · coffsharbournews.com.au · cointrust.com · countryrebel.com · cryptobriefing.com · culturalpolicy.com · cyberinsider.com · cybernoz.com · cyberscoop.com · cybersecuritynews.com · cybersecuritynews.es · cylance.com · dailyguardian.ae · dailyguardian.ca · diario21.com.mx · diarioeldia.uy
This summary has been updated 11 times: see revision history