# AI-driven ransomware surge and evolving global threats

> Live situation record from CLSTR: https://clstr.news/situations/worldwide-surge-in-cybercrime-targets-business-logistics-and-government-sectors
> Updated: 2026-08-27T02:04:12.000Z. Sources: 180. Developments: 33.

The ransomware landscape is undergoing a structural shift, characterized by an increase in active criminal groups and the integration of AI. The number of active groups rose from 71 to 93 in the second quarter of 2026. While the top 10 groups now account for a smaller share of victims (57.6%), total victims recorded on leak sites reached 2,139, a 33% year-over-year increase. Notably, the group ‘The Gentlemen’ saw 62% growth, with evidence suggesting AI coding assistants allow small teams to develop management panels in just days. Meanwhile, ransom payment rates have hit a multi-year low of approximately 23%. Qilin remains a prolific operator, but ‘The Gentlemen’ briefly overtook them in June. New technical threats are emerging, such as the DeadLock ransomware and the Aeternum botnet, both of which utilize the Polygon blockchain to create resilient command-and-control mechanisms that evade conventional takedowns. Specific threats continue to target critical infrastructure. The Gunra ransomware-as-a-service operation, also known as ‘Golden Community,’ has prompted a joint advisory from the FBI, CISA, NSA, and South Korea’s National Police Agency. Gunra, a Conti-derived operation, exploits Fortinet firewall and VPN vulnerabilities to target healthcare, financial, and government sectors. The group utilizes a double-extortion model, often demanding ransoms exceeding $10 million. Technical analysis revealed that Gunra can subvert multi-factor authentication by modifying virtual desktop infrastructure files through techniques such as session hijacking. This aligns with a broader trend in the Americas, where attackers are increasingly weaponizing edge infrastructure from providers like Ivanti, Cisco, and Palo Alto Networks to maximize pressure through high-leverage data exfiltration. Recent developments highlight the growing impact of AI, with 89% of surveyed financial providers reporting an increase in AI-driven attacks. These include automated phishing and ‘counter incident response’ tactics, where attackers delete logs to thwart security teams.

## Claims

- Qilin was the most prolific ransomware operator for the fourth consecutive quarter with 279 victims. (disputed by 3 sources)
- The Qilin ransomware group recorded 301 victims in Q2 2026, the highest among ransomware groups. (disputed)
- Gunra ransomware targets critical infrastructure in healthcare, finance, and government sectors. (corroborated by 8 sources)
- Gunra exploits Fortinet vulnerabilities CVE-2024-55591 and CVE-2025-24472 for initial access. (corroborated by 6 sources)
- Gunra operates as a ransomware-as-a-service (RaaS) program. (corroborated by 5 sources)
- DeadLock ransomware uses the Polygon blockchain to store configuration data and leak site posts. (corroborated by 4 sources)
- Artificial intelligence is being used to detect cyber threats and accelerate vulnerability discovery. (corroborated by 3 sources)
- Gunra has been known to demand ransom amounts exceeding $10 million. (corroborated by 3 sources)
- Fortinet introduced a pay‑per‑use security model for SMEs in Spain. (corroborated by 2 sources)
- DeadLock employs a hybrid cryptographic design using Curve25519 and XChaCha20. (corroborated by 2 sources)

## Timeline

### 2026-08-27: Cybersecurity industry shifts toward AI platforms to combat rising ransomware threats

Rising ransomware threats from groups like Qilin and the rise of RaaS are outpacing traditional EDR defenses, driving a shift toward AI-driven security platforms and integrated multi-layered protection.

2 sources. https://clstr.news/cluster/cybersecurity-industry-shifts-toward-ai-platforms-to-combat-rising-ransomware-threats

### 2026-08-14: Gunra ransomware exploits Fortinet flaws to bypass MFA

The Gunra ransomware group is bypassing MFA by exploiting Fortinet vulnerabilities, marking a broader shift toward infrastructure-based attacks and data extortion in the 2026 cyber threat landscape.

6 sources. https://clstr.news/cluster/cybersecurity-threats-escalate-with-gunra-and-deadlock-ransomware

### 2026-08-12: Ransomware landscape shifts as active groups hit record high in Q2 2026

Ransomware activity in Q2 2026 shows a rise in active groups to 93 and increased use of AI tools by criminals, even as ransom payment rates fall to a multi-year low of 23%.

26 sources. https://clstr.news/cluster/microsoft-warns-deadlock-ransomware-uses-decentralized-services-to-survive-takedowns

### 2026-08-11: Gunra ransomware targets critical infrastructure via Fortinet flaws

US and South Korean authorities warn of Gunra ransomware, a RaaS operation exploiting Fortinet vulnerabilities to target critical infrastructure via double-extortion tactics.

14 sources. https://clstr.news/cluster/industrial-ransomware-rises-as-authorities-warn-of-gunra-attacks

### 2026-08-10: Cybersecurity trends show rising ransomware focus on disabling backups and internal defenses

Cybersecurity reports reveal that while perimeter defenses are improving, attackers successfully bypass internal controls 63% of the time, often disabling backups and EDR tools to hinder recovery.

8 sources. https://clstr.news/cluster/ransomware-attackers-increasingly-target-backups-and-security-tools

### 2026-08-09: Financial sector sees surge in AI-driven cyberattacks

TrendAI reports that 89% of financial service providers are seeing an increase in AI-powered cyberattacks, including automated phishing, ransomware, and attempts to bypass security teams.

3 sources. https://clstr.news/cluster/financial-sector-sees-surge-in-ai-driven-cyberattacks

### 2026-07-31: Latin America faces surge in AI‑driven cyber threats

AI boosts cyber defenses but also speeds exploit creation; 52.7% of Latin American firms saw attacks, ransomware rose 16.5% in H1 2026, and patch delays average 16 days, while Spain adopts pay‑per‑use security,

14 sources. https://clstr.news/cluster/fortinet-introduces-payperuse-security-for-spanish-smes

### 2026-07-28: Mexico sees 38% rise in ransomware attacks on businesses, AI use up 90%

Ransomware attacks on Mexican firms rose 38% last year, AI‑driven attacks up 90%; average recovery cost $1.35 million, 70% of ransoms exceed $1 million, amid a shortage of 77,000 security experts.

5 sources. https://clstr.news/cluster/mexico-sees-38-rise-in-ransomware-attacks-on-businesses-ai-use-up-90

### 2026-07-26: Ransomware attacks surge with AI-driven threats, Brazil hit hardest

AI‑driven agentic ransomware is rising, with attacks up 3% globally in Q2 2026 and 17.8% in Brazil, where hypervisor and backup targets dominate; phishing remains the main entry vector.

10 sources. https://clstr.news/cluster/japanese-telecom-provider-telenet-hit-by-ransomware-amid-broader-japan-cyber-attacks

### 2026-07-22: Proofpoint AI‑Era Ransomware Report Shows AI Boosts Attack Success

AI is boosting ransomware success (65% of attacks) and accelerating cyber‑crime, while firms ramp up AI defenses amid a 77% rise in AI‑driven fraud.

9 sources. https://clstr.news/cluster/ai-boosts-ransomware-effectiveness-in-global-organizations-report-shows

### 2026-07-20: Ransomware up 23% globally as Brazil's army warns of combined cyber‑AI threats

Ransomware attacks rose 23% in June 2026, targeting corporate access points, as Brazil's army reports cyber‑AI threats now form a unified strategic challenge.

2 sources. https://clstr.news/cluster/ransomware-up-23-globally-as-brazils-army-warns-of-combined-cyberai-threats

### 2026-07-19: Ransomware attacks surge as compromised identities and AI tools fuel new threats

Compromised credentials now drive 79% of ransomware attacks, AI‑enhanced groups like BlackMamba target hospitals, and governments move to ban ransom payments.

13 sources. https://clstr.news/cluster/uk-plans-ban-on-ransomware-payments-for-public-sector-and-critical-infrastructure

### 2026-07-18: Small Business Cybersecurity Guides Focus on Simple, Low-Cost Measures

Guides urge small businesses to adopt simple, low‑cost cybersecurity steps—employee training, MFA, password managers—while avoiding pricey, unnecessary tools and noting insurance won’t prevent attacks.

2 sources. https://clstr.news/cluster/small-business-cybersecurity-guides-focus-on-simple-low-cost-measures

### 2026-07-13: Corporate Backup Strategies to Counter Ransomware and Wiper Attacks

Studies reveal most firms lack proper backup safeguards against ransomware and wiper attacks; only a minority isolate and test backups, prompting calls for immutable storage, strict isolation, and comprehensive

2 sources. https://clstr.news/cluster/corporate-backup-strategies-to-counter-ransomware-and-wiper-attacks

### 2026-07-13: Small businesses face growing cyber‑insurance and backup challenges

Small firms are urged to adopt immutable backups as insurers tighten requirements; cyber spending now rivals rent, with many still lacking proper insurance and confidence in data protection.

7 sources. https://clstr.news/cluster/cyber-insurance-for-msps-top-providers-and-claims-strategies

### 2026-07-07: AI Agent ‘JadePuffer’ Executes First Fully Autonomous Ransomware Attack

Researchers report JadePuffer, the first ransomware run entirely by an AI agent, which exploited a Langflow flaw, auto‑adapted during the attack, and was set up by a human operator.

7 sources. https://clstr.news/cluster/jadepuffer-ai-ransomware-attack-proves-autonomous-cybercrime

### 2026-07-04: JadePuffer AI Agent Executes First Fully Autonomous Ransomware Attack

Sysdig reports JadePuffer, an autonomous AI agent, carried out a full ransomware attack via a Langflow bug, encrypting 1,342 records and adapting in 31 seconds, marking the first documented agentic ransomware.

28 sources. https://clstr.news/cluster/ai-phishing-surge-and-first-autonomous-ransomware-attack-raise-threats

### 2026-07-02: AI Agent JadePuffer Executes First Fully Autonomous Ransomware Attack

Sysdig reports JadePuffer, the first fully autonomous AI‑driven ransomware, exploiting Langflow (CVE‑2025‑3248) and Nacos vulnerabilities to encrypt data and demand Bitcoin, highlighting a new threat model for

5 sources. https://clstr.news/cluster/aidriven-ransomware-attack-jadepuffer-demonstrates-first-endtoend-autonomous-operation

### 2026-06-29: AI logistics sector sees governance framework rollout and surge in cargo thefts

NMFTA released a free AI governance framework for logistics, while U.S. police busted a multi‑state theft ring stealing $1.3 M of AI data‑center equipment.

2 sources. https://clstr.news/cluster/ai-logistics-sector-sees-governance-framework-rollout-and-surge-in-cargo-thefts

### 2026-06-26: Ransomware Threats Escalate, Targeting Global Financial Systems

Ransomware in 2026 uses AI to target executives, adds triple extortion and attacks IoT, disrupting payment rails, banking platforms and trading systems, threatening global financial stability.

3 sources. https://clstr.news/cluster/ransomware-threats-escalate-targeting-global-financial-systems

### 2026-06-25: SonicWall warns healthcare cyberattacks stay high despite overall decline in 2026

SonicWall’s 2026 Healthcare Protect Brief shows cyber‑attacks on hospitals declined only 17 %, far less than other sectors, driven by exposed remote‑desktop tools, IoT devices and legacy VPNs; ten ransomware —

2 sources. https://clstr.news/cluster/sonicwall-warns-healthcare-cyberattacks-stay-high-despite-overall-decline-in-2026

### 2026-06-24: Ransomware Defense Shifts Toward Resilience and Identity‑Based Protection

Ransomware guidance urges healthcare and Canadian organisations to adopt cyber‑resilience, focusing on identity‑based security as attackers develop tools to disable EDR defenses.

5 sources. https://clstr.news/cluster/ransomware-defense-shifts-toward-resilience-and-identitybased-protection

### 2026-06-19: Ransomware attacks surge 48% globally in May 2026

May 2026 saw a 48 % global rise in ransomware attacks to 698 incidents, with major growth in Asia and heightened targeting of Android devices and private users.

3 sources. https://clstr.news/cluster/ransomware-attacks-surge-48-globally-in-may-2026

### 2026-06-16: AI‑driven ransomware threats push firms toward immutable backup solutions

IT leaders fear AI‑driven ransomware, but many lack immutable backups; CyberSense wins award for AI‑based ransomware recovery platform that verifies backup integrity.

2 sources. https://clstr.news/cluster/aidriven-ransomware-threats-push-firms-toward-immutable-backup-solutions

### 2026-06-15: AI-Driven Healthcare Ransomware Risks and FBI Cyber Range Highlight Expanding Cyber Threats

Agentic AI in healthcare heightens ransomware risks, while the FBI's new Alabama cyber range simulates attacks across homes, hospitals and infrastructure, highlighting expanding cyber threats.

2 sources. https://clstr.news/cluster/ai-driven-healthcare-ransomware-risks-and-fbi-cyber-range-highlight-expanding-cyber-threats

### 2026-06-13: Ransomware Surge Driven by AI and Healthcare Data Threatens Global Cybersecurity

Ransomware activity hit record levels in Q1 2026, boosted by AI‑generated phishing and deep‑fakes, while stolen healthcare data fuels a lucrative underground market, raising global cyber risk.

2 sources. https://clstr.news/cluster/ransomware-surge-driven-by-ai-and-healthcare-data-threatens-global-cybersecurity

### 2026-06-10: Healthcare data breaches spur cybercrime market and push stronger vendor security rules

Health‑ISAC urges tighter third‑party governance as TrendAI shows a global cybercrime market exploiting stolen patient data, with ransomware and vendor compromises driving multimillion‑dollar losses.

2 sources. https://clstr.news/cluster/healthcare-data-breaches-spur-cybercrime-market-and-push-stronger-vendor-security-rules

### 2026-06-09: Healthcare data emerges as top cybercrime commodity

TrendAI finds stolen health records now drive a mature cybercrime market, with ransomware sales making up 36% of activity and vendors serving as supply‑chain multipliers.

2 sources. https://clstr.news/cluster/healthcare-data-emerges-as-top-cybercrime-commodity

### 2026-05-14: Indiana K‑12 schools face surge in cyberattacks, prompting stronger data‑security measures

Indiana K‑12 schools report a sharp rise in cyberattacks, prompting costly fixes and a push for stronger data‑security practices.

2 sources. https://clstr.news/cluster/indiana-k12-schools-face-surge-in-cyberattacks-prompting-stronger-datasecurity-measures

### 2026-05-14: SK Shield reports South Korean SMEs take average 106 days to respond to cyber attacks

SK Shield says South Korean SMEs need 106 days on average to detect and start responding to cyber attacks, with ransomware and data theft most common.

2 sources. https://clstr.news/cluster/sk-shield-reports-south-korean-smes-take-average-106-days-to-respond-to-cyber-attacks

### 2026-05-07: Nigeria's NITDA alerts to AI-driven 'DeepLoad' malware targeting banks and government agencies

Nigeria's NITDA warns that AI‑driven 'DeepLoad' malware is stealing banking credentials and data from banks, agencies and citizens.

2 sources. https://clstr.news/cluster/nigerias-nitda-alerts-to-ai-driven-deepload-malware-targeting-banks-and-government-agencies

### 2026-05-05: Cybercrime Surge Threatens African Enterprises and Global Small Businesses

Cybercrime now makes up over 30% of crimes in parts of Africa, prompting calls for stronger institutional defenses and basic security steps for businesses.

3 sources. https://clstr.news/cluster/cybercrime-surge-threatens-african-enterprises-and-global-small-businesses

### 2026-05-04: India faces 505 cyber threats per minute as credential theft spikes, report says

India logged 265 million cyber detections (505 per minute) in 2025, with credential theft surging against IT firms, report warns.

2 sources. https://clstr.news/cluster/india-faces-505-cyber-threats-per-minute-as-credential-theft-spikes-report-says

---
Cite as: AI-driven ransomware surge and evolving global threats. CLSTR, https://clstr.news/situations/worldwide-surge-in-cybercrime-targets-business-logistics-and-government-sectors
