< Back to situations

Monitor this situation.

[SITUATION] · [QUIET] · [TECHNOLOGY]

33 clusters · 180 sources · 115 days · First seen · Last updated

AI-driven ransomware surge and evolving global threats

Overview

The ransomware landscape is undergoing a structural shift, characterized by an increase in active criminal groups and the integration of AI. The number of active groups rose from 71 to 93 in the second quarter of 2026. While the top 10 groups now account for a smaller share of victims (57.6%), total victims recorded on leak sites reached 2,139, a 33% year-over-year increase. Notably, the group ‘The Gentlemen’ saw 62% growth, with evidence suggesting AI coding assistants allow small teams to develop management panels in just days. Meanwhile, ransom payment rates have hit a multi-year low of approximately 23%. Qilin remains a prolific operator, but ‘The Gentlemen’ briefly overtook them in June. New technical threats are emerging, such as the DeadLock ransomware and the Aeternum botnet, both of which utilize the Polygon blockchain to create resilient command-and-control mechanisms that evade conventional takedowns. Specific threats continue to target critical infrastructure. The Gunra ransomware-as-a-service operation, also known as ‘Golden Community,’ has prompted a joint advisory from the FBI, CISA, NSA, and South Korea’s National Police Agency. Gunra, a Conti-derived operation, exploits Fortinet firewall and VPN vulnerabilities to target healthcare, financial, and government sectors. The group utilizes a double-extortion model, often demanding ransoms exceeding $10 million. Technical analysis revealed that Gunra can subvert multi-factor authentication by modifying virtual desktop infrastructure files through techniques such as session hijacking. This aligns with a broader trend in the Americas, where attackers are increasingly weaponizing edge infrastructure from providers like Ivanti, Cisco, and Palo Alto Networks to maximize pressure through high-leverage data exfiltration. Recent developments highlight the growing impact of AI, with 89% of surveyed financial providers reporting an increase in AI-driven attacks. These include automated phishing and ‘counter incident response’ tactics, where attackers delete logs to thwart security teams.

Entities

Fortinet · Polygon · FBI · CISA · Microsoft

Claims

What the coverage asserts, and how many sources carry each claim.

Coverage disagrees

Sources make claims that cannot both be true. CLSTR reports the disagreement; it does not decide who is right.

  • "Qilin was the most prolific ransomware operator for the fourth consecutive quarter with 279 victims."

    vs

    "The Qilin ransomware group recorded 301 victims in Q2 2026, the highest among ransomware groups."

    The claims provide different victim counts (279 vs 301) for the Qilin ransomware group's activity in the same period.

Timeline

  1. 21 days ago

    [TECHNOLOGY] 2 sources
    Cybersecurity industry shifts toward AI platforms to combat rising ransomware threats

    Rising ransomware threats from groups like Qilin and the rise of RaaS are outpacing traditional EDR defenses, driving a shift toward AI-driven security platforms and integrated multi-layered protection.

  2. about 1 month ago

    [TECHNOLOGY] 6 sources
    Gunra ransomware exploits Fortinet flaws to bypass MFA

    The Gunra ransomware group is bypassing MFA by exploiting Fortinet vulnerabilities, marking a broader shift toward infrastructure-based attacks and data extortion in the 2026 cyber threat landscape.

  3. about 1 month ago

    [TECHNOLOGY] 26 sources
    Ransomware landscape shifts as active groups hit record high in Q2 2026

    Ransomware activity in Q2 2026 shows a rise in active groups to 93 and increased use of AI tools by criminals, even as ransom payment rates fall to a multi-year low of 23%.

  4. about 1 month ago

    [TECHNOLOGY] 14 sources
    Gunra ransomware targets critical infrastructure via Fortinet flaws

    US and South Korean authorities warn of Gunra ransomware, a RaaS operation exploiting Fortinet vulnerabilities to target critical infrastructure via double-extortion tactics.

  5. about 1 month ago

    [TECHNOLOGY] 8 sources
    Cybersecurity trends show rising ransomware focus on disabling backups and internal defenses

    Cybersecurity reports reveal that while perimeter defenses are improving, attackers successfully bypass internal controls 63% of the time, often disabling backups and EDR tools to hinder recovery.

  6. about 1 month ago

    [TECHNOLOGY] 3 sources
    Financial sector sees surge in AI-driven cyberattacks

    TrendAI reports that 89% of financial service providers are seeing an increase in AI-powered cyberattacks, including automated phishing, ransomware, and attempts to bypass security teams.

  7. about 2 months ago

    [TECHNOLOGY] 14 sources
    Latin America faces surge in AI‑driven cyber threats

    AI boosts cyber defenses but also speeds exploit creation; 52.7% of Latin American firms saw attacks, ransomware rose 16.5% in H1 2026, and patch delays average 16 days, while Spain adopts pay‑per‑use security,

  8. about 2 months ago

    [TECHNOLOGY] 5 sources
    Mexico sees 38% rise in ransomware attacks on businesses, AI use up 90%

    Ransomware attacks on Mexican firms rose 38% last year, AI‑driven attacks up 90%; average recovery cost $1.35 million, 70% of ransoms exceed $1 million, amid a shortage of 77,000 security experts.

  9. about 2 months ago

    [CRIME] 10 sources
    Ransomware attacks surge with AI-driven threats, Brazil hit hardest

    AI‑driven agentic ransomware is rising, with attacks up 3% globally in Q2 2026 and 17.8% in Brazil, where hypervisor and backup targets dominate; phishing remains the main entry vector.

  10. about 2 months ago

    [TECHNOLOGY] 9 sources
    Proofpoint AI‑Era Ransomware Report Shows AI Boosts Attack Success

    AI is boosting ransomware success (65% of attacks) and accelerating cyber‑crime, while firms ramp up AI defenses amid a 77% rise in AI‑driven fraud.

  11. about 2 months ago

    [TECHNOLOGY] 2 sources
    Ransomware up 23% globally as Brazil's army warns of combined cyber‑AI threats

    Ransomware attacks rose 23% in June 2026, targeting corporate access points, as Brazil's army reports cyber‑AI threats now form a unified strategic challenge.

  12. about 2 months ago

    [CRIME] 13 sources
    Ransomware attacks surge as compromised identities and AI tools fuel new threats

    Compromised credentials now drive 79% of ransomware attacks, AI‑enhanced groups like BlackMamba target hospitals, and governments move to ban ransom payments.

  13. 2 months ago

    [TECHNOLOGY] 2 sources
    Small Business Cybersecurity Guides Focus on Simple, Low-Cost Measures

    Guides urge small businesses to adopt simple, low‑cost cybersecurity steps—employee training, MFA, password managers—while avoiding pricey, unnecessary tools and noting insurance won’t prevent attacks.

  14. 2 months ago

    [TECHNOLOGY] 2 sources
    Corporate Backup Strategies to Counter Ransomware and Wiper Attacks

    Studies reveal most firms lack proper backup safeguards against ransomware and wiper attacks; only a minority isolate and test backups, prompting calls for immutable storage, strict isolation, and comprehensive

  15. 2 months ago

    [BUSINESS] 7 sources
    Small businesses face growing cyber‑insurance and backup challenges

    Small firms are urged to adopt immutable backups as insurers tighten requirements; cyber spending now rivals rent, with many still lacking proper insurance and confidence in data protection.

  16. 2 months ago

    [TECHNOLOGY] 7 sources
    AI Agent ‘JadePuffer’ Executes First Fully Autonomous Ransomware Attack

    Researchers report JadePuffer, the first ransomware run entirely by an AI agent, which exploited a Langflow flaw, auto‑adapted during the attack, and was set up by a human operator.

  17. 2 months ago

    [TECHNOLOGY] 28 sources
    JadePuffer AI Agent Executes First Fully Autonomous Ransomware Attack

    Sysdig reports JadePuffer, an autonomous AI agent, carried out a full ransomware attack via a Langflow bug, encrypting 1,342 records and adapting in 31 seconds, marking the first documented agentic ransomware.

  18. 3 months ago

    [TECHNOLOGY] 5 sources
    AI Agent JadePuffer Executes First Fully Autonomous Ransomware Attack

    Sysdig reports JadePuffer, the first fully autonomous AI‑driven ransomware, exploiting Langflow (CVE‑2025‑3248) and Nacos vulnerabilities to encrypt data and demand Bitcoin, highlighting a new threat model for

  19. 3 months ago

    [TECHNOLOGY] 2 sources
    AI logistics sector sees governance framework rollout and surge in cargo thefts

    NMFTA released a free AI governance framework for logistics, while U.S. police busted a multi‑state theft ring stealing $1.3 M of AI data‑center equipment.

  20. 3 months ago

    [TECHNOLOGY] 3 sources
    Ransomware Threats Escalate, Targeting Global Financial Systems

    Ransomware in 2026 uses AI to target executives, adds triple extortion and attacks IoT, disrupting payment rails, banking platforms and trading systems, threatening global financial stability.

  21. 3 months ago

    [TECHNOLOGY] 2 sources
    SonicWall warns healthcare cyberattacks stay high despite overall decline in 2026

    SonicWall’s 2026 Healthcare Protect Brief shows cyber‑attacks on hospitals declined only 17 %, far less than other sectors, driven by exposed remote‑desktop tools, IoT devices and legacy VPNs; ten ransomware —

  22. 3 months ago

    [TECHNOLOGY] 5 sources
    Ransomware Defense Shifts Toward Resilience and Identity‑Based Protection

    Ransomware guidance urges healthcare and Canadian organisations to adopt cyber‑resilience, focusing on identity‑based security as attackers develop tools to disable EDR defenses.

  23. 3 months ago

    [TECHNOLOGY] 3 sources
    Ransomware attacks surge 48% globally in May 2026

    May 2026 saw a 48 % global rise in ransomware attacks to 698 incidents, with major growth in Asia and heightened targeting of Android devices and private users.

  24. 3 months ago

    [TECHNOLOGY] 2 sources
    AI‑driven ransomware threats push firms toward immutable backup solutions

    IT leaders fear AI‑driven ransomware, but many lack immutable backups; CyberSense wins award for AI‑based ransomware recovery platform that verifies backup integrity.

  25. 3 months ago

    [TECHNOLOGY] 2 sources
    AI-Driven Healthcare Ransomware Risks and FBI Cyber Range Highlight Expanding Cyber Threats

    Agentic AI in healthcare heightens ransomware risks, while the FBI's new Alabama cyber range simulates attacks across homes, hospitals and infrastructure, highlighting expanding cyber threats.

  26. 3 months ago

    [CRIME] 2 sources
    Ransomware Surge Driven by AI and Healthcare Data Threatens Global Cybersecurity

    Ransomware activity hit record levels in Q1 2026, boosted by AI‑generated phishing and deep‑fakes, while stolen healthcare data fuels a lucrative underground market, raising global cyber risk.

  27. 3 months ago

    [HEALTH] 2 sources
    Healthcare data breaches spur cybercrime market and push stronger vendor security rules

    Health‑ISAC urges tighter third‑party governance as TrendAI shows a global cybercrime market exploiting stolen patient data, with ransomware and vendor compromises driving multimillion‑dollar losses.

  28. 3 months ago

    [CRIME] 2 sources
    Healthcare data emerges as top cybercrime commodity

    TrendAI finds stolen health records now drive a mature cybercrime market, with ransomware sales making up 36% of activity and vendors serving as supply‑chain multipliers.

  29. 4 months ago

    [TECHNOLOGY] 2 sources
    Indiana K‑12 schools face surge in cyberattacks, prompting stronger data‑security measures

    Indiana K‑12 schools report a sharp rise in cyberattacks, prompting costly fixes and a push for stronger data‑security practices.

  30. 4 months ago

    [TECHNOLOGY] 2 sources
    SK Shield reports South Korean SMEs take average 106 days to respond to cyber attacks

    SK Shield says South Korean SMEs need 106 days on average to detect and start responding to cyber attacks, with ransomware and data theft most common.

  31. 4 months ago

    [TECHNOLOGY] 2 sources
    Nigeria's NITDA alerts to AI-driven 'DeepLoad' malware targeting banks and government agencies

    Nigeria's NITDA warns that AI‑driven 'DeepLoad' malware is stealing banking credentials and data from banks, agencies and citizens.

  32. 4 months ago

    [TECHNOLOGY] 3 sources
    Cybercrime Surge Threatens African Enterprises and Global Small Businesses

    Cybercrime now makes up over 30% of crimes in parts of Africa, prompting calls for stronger institutional defenses and basic security steps for businesses.

  33. 5 months ago

    [TECHNOLOGY] 2 sources
    India faces 505 cyber threats per minute as credential theft spikes, report says

    India logged 265 million cyber detections (505 per minute) in 2025, with credential theft surging against IT firms, report warns.

Sources

24x7mag.com · 4sysops.com · abcmoney.co.uk · addicted2success.com · affinitymsp.com.au · aktiencheck · analyticsinsight.net · audiencescience.com · australiancybersecuritymagazine.com.au · australianmanufacturing.com.au · avantionline.it · b2b-cyber-security.de · bankofalbuquerque.com · bhaskarlive.in · bhconsulting.ie · bitcoinethereumnews.com · bitmat.it · bleepingcomputer.com · blogspan.net · boardagenda.com · bookclubz.com · borncity.com · brasil247.com · bright.nl · businessdiary.com.ph · businessnewsthisweek.com · businesstechweekly.com · byline.network · calibre800.com · capminds.com · channelinsider.com · christelijknieuws.nl · cioafrica.co · coffsharbournews.com.au · cointrust.com · countryrebel.com · cryptobriefing.com · culturalpolicy.com · cyberinsider.com · cybernoz.com · cyberscoop.com · cybersecuritynews.com · cybersecuritynews.es · cylance.com · dailyguardian.ae · dailyguardian.ca · diario21.com.mx · diarioeldia.uy

This summary has been updated 11 times: see revision history