BitDepth 1576 for August 17, 2026
If there is any message to be taken from recently released reports on ransomware attacks, it is that there is greater need for sober assessment of the risk these bad actors pose to all companies, not just those that represent juicy targets by virtue of their balance sheets.
Ransomware threats are adapting to targeted weaknesses in technology deployments and are weighing vulnerabilities against potential income with ruthless specificity.
What’s the state of play?
Black Kite’s 2026 ransomware report assessed 7,551 victims globally who were hit by a sharp 60 percent increase in breach volumes in the first half of 2026.
The count of active ransomware groups rose from 127 to 146, with Qilin claiming 1,358 victims, a tally of infamy double that of its nearest rival.
The Black Kite report covers verified victims from April to March of each year.
Attacks on enterprise tier actors worth US$100m or more dropped from 13.9 percent to 9.5 percent of the total victim count, but businesses in the $1-5 million revenue band almost doubled, suggesting a growing shift in attacks to softer, if potentially less lucrative targets.
Black Kite has been tracking ransomware disclosures since 2022 and the count has been steadily rising. This year’s report registered a tripling of observed breaches over 2023.
Black Kite notes that previous reports identified a dominant presence among threat actors. Over the years, LockBit was ascendant, then AlphV and LockBit then RansomHub (which disappeared in May 2025 after claiming 736 victims).
This year, the company’s researchers suggest that the business has evolved into a marketplace for criminality instead of one dominated by dominant ransomware brands.
Brands may disappear, but the threat actors rebrand and reappear.
The overall number of threat actors has increased, with fewer groups disappearing. The spike between November 2025 and March 2026 suggests an increased operating tempo.
The regional threat
Shiva Parasram of the Computer Forensics and Security Institute issued his report on regional ransomware breaches for the first half of 2026 last week. The full report can be accessed on his LinkedIn page and on the company’s website.
In Parasram’s overview of reported breaches on the dark web, the Caribbean recorded 21 confirmed attack listings over the first six months of 2026, the entire reported total for 2025.
The attacks were carried out by 12 ransomware groups across five Caribbean countries, with the Dominican Republic topping the list of declared breaches with seven listings. Jamaica followed with six listings.
This profile becomes even more worrying because of an apparent increase in interest in Caribbean vulnerabilities, with eight of the twelve groups having no profile in the region’s ransomware attacks in 2025.
At least one major Caribbean communications company is likely to have paid a ransom, after being listed for a breach then being delisted. Other companies that successfully negotiated a payment or value transfer with ransomware groups would never have been listed.
It is generally accepted that visible ransomware breaches represent just half of successful ransomware attacks.
The LockBit ransomware operation made a strong comeback in the Caribbean in the first half of 2026 after being targeted by law enforcement in 2024.
In 2025, the group was responsible for one listing of a breach in the Caribbean, In the first half of 2026, it posted four listings across three countries.
Payload, which emerged in February 2026, was responsible for three listings, targeting Windows and Linux/VMware ESXi platforms.
The Gentlemen, active since mid-2025, listed two breaches in the first two quarters of 2026. The group offers a generous 90 percent revenue split and targets Windows, Linux, NAS, BSD, and ESXi environments.
Who is being targeted?
Globally, between October 2025 and March 2026, every month registered more than 700 victims, with March 2026 soaring to 861 successful data breaches.
Qilin’s attack vector included at least one successful Managed Service Provider (MSP) compromise which hit one vendor and reached downstream to 32 South Korean financial institutions.
That also represents an increasing globalisation of ransomware vectors, as affiliates and new groups reached out to Europe and Asia to increase their attack profile.
In Europe, Germany increased by 48 percent to 281 victims, Spain by 50 percent to 160, France by 43 percent to 196 while Italy registered a 96 percent increase to 188. That geographic expansion added more than 250 new victims.
In Asia, notable growth included increases in Thailand by 406 percent and South Korea by 407 percent.
Black Kite suggests that these spikes represent a new focus by ransomware brands which may also reflect a greater local understanding of vulnerabilities in those territories.
Construction overtook the healthcare sector with 541 victims, the second largest year over year sector increase by share, but still significantly trailed professional and technical Services with 1,389 and manufacturing with 1,660 victims respectively.
The education sector, which declined in absolute victim count to 250 victims was singled out for its extreme exposure and high stealer log count of 70.2, the result of unpatched vulnerabilities and leaked credentials.
For ransomware groups, smaller victims can be leveraged through exposure of sensitive data and uneven response capacity while enterprise companies in the manufacturing sector attract players capable of mounting operational attacks that affect production, logistics, business continuity, suppliers and customers.
Ransomware actors also break out across revenue bands. Qilin operated widely across income sectors while Sinobi more clearly targeted lower revenue operators.
Coin Base Cartel, which cleared US$101.3 million in ransomware demands targets high value targets with operations that support those ambitions.
Where are the vulnerabilities?
The Black Kite report warned of the issue of supply chain vulnerabilities, in which third party dependencies or access points can become attack paths into trusted systems.
“An organization could run a disciplined security program, patch on schedule, train its people, and still wake up to an extortion email, because the
breach happened somewhere it never controlled.”
“For many of the year’s most visible incidents, the customer’s core environment was not the clean boundary of the incident.”
“Data, access, and leverage moved through the systems that organizations rely on to operate: SaaS (Software as a Service) integrations, ERP applications, customer service platforms, Auth[orization] tokens, and third party applications connected to high value business data.”
“The vendor’s identity, application permissions, and software exposure become part of the customer’s ransomware surface.”
That warning became an unwelcome reality last week when a major supply chain breach exposed a staggering number of credentials.
On August 11, CloudSEK announced a massive supply chain breach that exposed credentials in CI/CD pipelines (Continuous Integration and Continuous Delivery or Deployment – an automated system for software distribution and updates) exposing active database passwords, third-party API keys and cloud credentials.
The breach affected dozens of major companies, including Amazon Web Services, Kroger and Elon Musk’s X, which use LiteLLM, described as “an open-source AI gateway and Python library that standardizes calls to over 100 large language model providers.”
According to ArsTechnica, the breach was done during a 40 minute window of opportunity when users downloaded a compromised version of the Python package. TeamPCP, a group that includes teenagers, took credit for the exploit.

Most alarmingly, victims of ransomware continued to carry critical patch vulnerabilities even after being attacked.
Large data theft incidents produced significant payouts and vulnerabilities in business ecosystem integrations, notably those between Oracle E-Business Suite and Salesforce which proved to be among the most visible supply chain incidents.
Black Kite found a pervasive pattern in affected companies of “exposed information, misconfiguration, open remote access, software vulnerabilities, stealer logs, and credential-related findings present across large portions of the victim population.”
“Misconfiguration appeared in 68.1 percent of victims. Fraudulent domains appeared in 52 percent. Remote access ports appeared in 46.9 percent. Software vulnerabilities appeared in 43.2 percent. Stealer logs appeared in 34.5 percent, and credential stuffing in 21.6 percent.”
“More than 60 percent of victims carried at least one of the three critical ransomware-relevant findings: software vulnerability, credential stuffing, or stealer logs. Nearly one in ten carried all three.”
“These exposures may not have caused every incident – but before many victims appeared on leak sites, ransomware-relevant weakness was already visible from the outside.”
What’s to be done?
Regional businesses and governments must acknowledge that the ransomware and cybersecurity threat landscape is exploring global opportunities and more bad actors are taking advantage of the leverage of readily available infiltration tools and widely distributed stolen credentials data that expose vulnerabilities.
Black Kite analysts found that three in five victims carried at least one medium to high severity patch vulnerability that left them exposed to further inflitration.
- AI tools are improving the attack chain.
- Scripts are getting cleaner.
- Phishing and vishing attacks are becoming more persuasive and effectively localised.
- Persona scripts support real-time adaptation during conversations.
- Communications are more polished and victim specific.
Companies must become more thorough in their post-incident reviews, specifically reviewing stealer logs, KEV (Known Exposure Vulnerabilities) exposure, critical patch vulnerabilities, remote access, SaaS integrations, and vendor-managed access.
Security evaluations must extend to vendors, particularly those with critical access and SaaS platforms.
Cybersecurity initiatives must be prepared for improvements in social engineering initiatives by strengthening identity verification, raising awareness of executive impersonation tactics while improving help desk sensitivity to tactics used to acquire access credentials.
Preventive measures that worked yesterday are unlikely to be effective tomorrow.








