Ransomware Activity Surges, But AI Isn’t the Culprit
A disturbing trend is unfolding in the world of cybersecurity: ransomware attacks are accelerating at an alarming rate. According to a recent analysis by Black Kite, more than 60 new groups have entered the crowded criminal ecosystem between October 2025 and March 2026, leading to a surge in activity that’s left many organizations reeling.
The numbers are staggering: 7,551 known victims worldwide were identified during this period, representing a 25% increase over the previous 12 months. But what’s most concerning is the sheer volume of attacks – March 2026 saw as many as 861 organizations fall victim to a ransomware attack, with nearly 28 per day being targeted.
So, why is this happening? According to Black Kite’s chief research and intelligence officer, Ferhat Dikbiyik, it’s not because of AI-powered attackers. Instead, the company points to a combination of factors that are driving the growth in ransomware activity. One key factor is the fragmentation of the ransomware ecosystem, which has led to the emergence of dozens of new groups.
This fragmentation has created an environment where smaller and newer entrants can pick up victims with ease – often targeting organizations in Europe, South America, Africa, or other regions that may not have the same level of cybersecurity sophistication as their US-based counterparts. In fact, nearly half of the victims (49.3%) were US-based organizations, but it’s worth noting that ransomware attacks in Europe outpaced those in the US.
Another contributing factor is the expansion of attacks on small and less defended organizations. These targets often have high ransomware susceptibility index (RSI) scores – a measure used to assess an organization’s exposure to ransomware attacks based on externally visible factors like exposed credentials and unpatched vulnerabilities. Black Kite found that 41% of companies with RSI scores above 0.8 experienced a ransomware incident during the study period.
What’s striking is that many victims showed a meaningful spike in their RSI score just before being hit, suggesting that susceptibility comes down to exposure and predisposition – not unique weakness. As Dikbiyik notes, “Exposure is what’s externally visible: misconfigurations, exposed remote access, credential stuffing, stealer logs… Predisposition is who you are, your geography, your industry, your revenue band, the size of your digital footprint.”
Manufacturing companies remained the top target for ransomware actors, accounting for 1,660 victims. But it’s worth noting that large companies were no longer the engine of volume growth – instead, a lot of activity happened among organizations in the $50 million to $100 million revenue tier and in the $1 million to $5 million range.
In short, the ransomware landscape is becoming increasingly complex and challenging for organizations to navigate. While AI-powered attackers may be getting attention, it’s clear that the real drivers behind this surge are the fragmentation of the ecosystem, the emergence of new groups, and the expansion of attacks on less defended organizations. As Dikbiyik warns, “This isn’t a problem we’ve contained – it’s still a lucrative business, and the barrier to running one keeps getting lower.”
So what can organizations do to protect themselves? First and foremost, they need to be aware of their exposure and predisposition. Regularly assessing your RSI score and addressing any externally visible weaknesses is essential. Additionally, investing in robust cybersecurity measures, such as multi-factor authentication, regular patching, and employee education, will help reduce the risk of a ransomware attack.
Source: Dark Reading — 2026-07-21