Ransomware Attacks Surge Globally, But It’s Not Due to AI
Ransomware attacks have reached an all-time high, with a staggering 25% increase in incident volume over the past year. According to Black Kite, a cybersecurity firm that analyzed ransomware incidents between April 2025 and March 2026, more than 7,500 organizations worldwide fell victim to these devastating cyberattacks. What’s alarming is not just the sheer number of attacks but also their spread across various industries and geographies.
At the heart of this surge lies a complex mix of factors. Researchers point to the fragmentation of the ransomware ecosystem as one key driver. This means that instead of being dominated by a few large, established groups, the field has become increasingly crowded with new actors entering the scene. Black Kite estimates that over 60 new groups have emerged in recent months, adding to the chaos and unpredictability of these attacks.
Another critical factor is the expansion of ransomware attacks on smaller organizations that often lack robust security defenses. These less defended companies are more vulnerable to exploitation by attackers who can easily breach their systems using exposed credentials, misconfigurations, or unpatched vulnerabilities. In fact, Black Kite found that nearly 41% of companies with high ransomware susceptibility scores (based on externally visible factors) experienced a ransomware incident during the study period.
The surge in attacks has also been fueled by third-party and supply chain compromises. These breaches allow attackers to leverage a single breach into multivictim campaigns, making it even harder for organizations to defend themselves. For instance, the Qilin group was able to compromise 32 South Korean financial institutions through a single managed service provider (MSP) attack.
The data also reveals some concerning trends. Manufacturing companies remain the top target for ransomware actors, accounting for over 1,600 victims. Professional and scientific services sectors are also under siege, with nearly 1,400 organizations affected. Construction companies have emerged as the third-most targeted sector, while Europe has seen a significant surge in ransomware attacks.
While large companies continue to be attractive targets, it’s clear that smaller organizations are not immune to these attacks. In fact, Black Kite discovered that organizations in the $50 million to $100 million revenue tier and those with revenues between $1 million and $5 million were disproportionately affected. This means no company is too small a target for attackers.
The democratization of ransomware has made it easier for new actors to enter the scene, but it also highlights the need for organizations to rethink their security strategies. With more than 90% of victims showing a significant spike in their RSI score just before being hit, it’s clear that susceptibility comes down to exposure and predisposition. Organizations must focus on addressing externally visible weaknesses, such as misconfigurations, exposed remote access, and credential stuffing.
As the ransomware landscape continues to evolve, one thing is certain: organizations must be vigilant and proactive in their security efforts. With the stakes higher than ever, it’s essential that companies prioritize patching vulnerabilities, implement robust access controls, and regularly monitor for signs of suspicious activity. By doing so, they can reduce their risk exposure and stay ahead of these cunning attackers.
Source: Dark Reading — 2026-07-21