BitDepthThe silent, growing danger of ransomware

The silent, growing danger of ransomware

BitDepth 1576 for August 17, 2026

If there is any message to be taken from recently released reports on ransomware attacks, it is that there is greater need for sober assessment of the risk these bad actors pose to all companies, not just those that represent juicy targets by virtue of their balance sheets.

Ransomware threats are adapting to targeted weaknesses in technology deployments and are weighing vulnerabilities against potential income with ruthless specificity.

What’s the state of play?

Black Kite’s 2026 ransomware report assessed 7,551 victims globally who were hit by a sharp 60 percent increase in breach volumes in the first half of 2026.

The count of active ransomware groups rose from 127 to 146, with Qilin claiming 1,358 victims, a tally of infamy double that of its nearest rival.

The Black Kite report covers verified victims from April to March of each year.

Attacks on enterprise tier actors worth US$100m or more dropped from 13.9 percent to 9.5 percent of the total victim count, but businesses in the $1-5 million revenue band almost doubled, suggesting a growing shift in attacks to softer, if potentially less lucrative targets.

Black Kite has been tracking ransomware disclosures since 2022 and the count has been steadily rising. This year’s report registered a tripling of observed breaches over 2023.

Black Kite notes that previous reports identified a dominant presence among threat actors. Over the years, LockBit was ascendant, then AlphV and LockBit then RansomHub (which disappeared in May 2025 after claiming 736 victims).

This year, the company’s researchers suggest that the business has evolved into a marketplace for criminality instead of one dominated by dominant ransomware brands.

Brands may disappear, but the threat actors rebrand and reappear.

The overall number of threat actors has increased, with fewer groups disappearing. The spike between November 2025 and March 2026 suggests an increased operating tempo.

The regional threat

Shiva Parasram of the Computer Forensics and Security Institute issued his report on regional ransomware breaches for the first half of 2026 last week. The full report can be accessed on his LinkedIn page and on the company’s website.

CFSI’s breakout of confirmed regional ransomware breaches.

In Parasram’s overview of reported breaches on the dark web, the Caribbean recorded 21 confirmed attack listings over the first six months of 2026, the entire reported total for 2025.

The attacks were carried out by 12 ransomware groups across five Caribbean countries, with the Dominican Republic topping the list of declared breaches with seven listings. Jamaica followed with six listings.

This profile becomes even more worrying because of an apparent increase in interest in Caribbean vulnerabilities, with eight of the twelve groups having no profile in the region’s ransomware attacks in 2025.

Shiva Parasram

At least one major Caribbean communications company is likely to have paid a ransom, after being listed for a breach then being delisted. Other companies that successfully negotiated a payment or value transfer with ransomware groups would never have been listed.

It is generally accepted that visible ransomware breaches represent just half of successful ransomware attacks.

The LockBit ransomware operation made a strong comeback in the Caribbean in the first half of 2026 after being targeted by law enforcement in 2024.

In 2025, the group was responsible for one listing of a breach in the Caribbean, In the first half of 2026, it posted four listings across three countries.

Payload, which emerged in February 2026, was responsible for three listings, targeting Windows and Linux/VMware ESXi platforms.

The Gentlemen, active since mid-2025, listed two breaches in the first two quarters of 2026. The group offers a generous 90 percent revenue split and targets Windows, Linux, NAS, BSD, and ESXi environments.

Who is being targeted?

Globally, between October 2025 and March 2026, every month registered more than 700 victims, with March 2026 soaring to 861 successful data breaches.

Qilin’s attack vector included at least one successful Managed Service Provider (MSP) compromise which hit one vendor and reached downstream to 32 South Korean financial institutions.

Confirmed global breaches by business sector. Chart courtesy Black Kite.

That also represents an increasing globalisation of ransomware vectors, as affiliates and new groups reached out to Europe and Asia to increase their attack profile.

In Europe, Germany increased by 48 percent to 281 victims, Spain by 50 percent to 160, France by 43 percent to 196 while Italy registered a 96 percent increase to 188. That geographic expansion added more than 250 new victims.

In Asia, notable growth included increases in Thailand by 406 percent and South Korea by 407 percent.

Black Kite suggests that these spikes represent a new focus by ransomware brands which may also reflect a greater local understanding of vulnerabilities in those territories.

Construction overtook the healthcare sector with 541 victims, the second largest year over year sector increase by share, but still significantly trailed professional and technical Services with 1,389 and manufacturing with 1,660 victims respectively.

The education sector, which declined in absolute victim count to 250 victims was singled out for its extreme exposure and high stealer log count of 70.2, the result of unpatched vulnerabilities and leaked credentials.

For ransomware groups, smaller victims can be leveraged through exposure of sensitive data and uneven response capacity while enterprise companies in the manufacturing sector attract players capable of mounting operational attacks that affect production, logistics, business continuity, suppliers and customers.

Ransomware breach profiles for the professional sector. Chart courtesy Black Kite.

Ransomware actors also break out across revenue bands. Qilin operated widely across income sectors while Sinobi more clearly targeted lower revenue operators.

Coin Base Cartel, which cleared US$101.3 million in ransomware demands targets high value targets with operations that support those ambitions.

Where are the vulnerabilities?

The Black Kite report warned of the issue of supply chain vulnerabilities, in which third party dependencies or access points can become attack paths into trusted systems.

“An organization could run a disciplined security program, patch on schedule, train its people, and still wake up to an extortion email, because the
breach happened somewhere it never controlled.”

“For many of the year’s most visible incidents, the customer’s core environment was not the clean boundary of the incident.”

“Data, access, and leverage moved through the systems that organizations rely on to operate: SaaS (Software as a Service) integrations, ERP applications, customer service platforms, Auth[orization] tokens, and third party applications connected to high value business data.”

“The vendor’s identity, application permissions, and software exposure become part of the customer’s ransomware surface.”

That warning became an unwelcome reality last week when a major supply chain breach exposed a staggering number of credentials.

On August 11, CloudSEK announced a massive supply chain breach that exposed credentials in CI/CD pipelines (Continuous Integration and Continuous Delivery or Deployment – an automated system for software distribution and updates) exposing active database passwords, third-party API keys and cloud credentials.

The breach affected dozens of major companies, including Amazon Web Services, Kroger and Elon Musk’s X, which use LiteLLM, described as “an open-source AI gateway and Python library that standardizes calls to over 100 large language model providers.”

According to ArsTechnica, the breach was done during a 40 minute window of opportunity when users downloaded a compromised version of the Python package. TeamPCP, a group that includes teenagers, took credit for the exploit.

The profile of changes in security posture of targeted companies after being breached. Chart courtesy Black Kite.

Most alarmingly, victims of ransomware continued to carry critical patch vulnerabilities even after being attacked.

Large data theft incidents produced significant payouts and vulnerabilities in business ecosystem integrations, notably those between Oracle E-Business Suite and Salesforce which proved to be among the most visible supply chain incidents.

Black Kite found a pervasive pattern in affected companies of “exposed information, misconfiguration, open remote access, software vulnerabilities, stealer logs, and credential-related findings present across large portions of the victim population.”

“Misconfiguration appeared in 68.1 percent of victims. Fraudulent domains appeared in 52 percent. Remote access ports appeared in 46.9 percent. Software vulnerabilities appeared in 43.2 percent. Stealer logs appeared in 34.5 percent, and credential stuffing in 21.6 percent.”

“More than 60 percent of victims carried at least one of the three critical ransomware-relevant findings: software vulnerability, credential stuffing, or stealer logs. Nearly one in ten carried all three.”

“These exposures may not have caused every incident – but before many victims appeared on leak sites, ransomware-relevant weakness was already visible from the outside.”

What’s to be done?

Regional businesses and governments must acknowledge that the ransomware and cybersecurity threat landscape is exploring global opportunities and more bad actors are taking advantage of the leverage of readily available infiltration tools and widely distributed stolen credentials data that expose vulnerabilities.

The profile of ransomware extortion by company revenue. Chart by Black Kite.

Black Kite analysts found that three in five victims carried at least one medium to high severity patch vulnerability that left them exposed to further inflitration.

  • AI tools are improving the attack chain.
  • Scripts are getting cleaner.
  • Phishing and vishing attacks are becoming more persuasive and effectively localised.
  • Persona scripts support real-time adaptation during conversations.
  • Communications are more polished and victim specific.

Companies must become more thorough in their post-incident reviews, specifically reviewing stealer logs, KEV (Known Exposure Vulnerabilities) exposure, critical patch vulnerabilities, remote access, SaaS integrations, and vendor-managed access.

Security evaluations must extend to vendors, particularly those with critical access and SaaS platforms.

Cybersecurity initiatives must be prepared for improvements in social engineering initiatives by strengthening identity verification, raising awareness of executive impersonation tactics while improving help desk sensitivity to tactics used to acquire access credentials.

Preventive measures that worked yesterday are unlikely to be effective tomorrow.

The silent, growing danger of ransomware

The silent, growing danger of ransomware

Victims of ransomware continued to carry critical patch vulnerabilities even after being attacked.
Read More
How should a newsroom of the (very near) future work?

How should a newsroom of the (very near) future work?

When generic content becomes easier to produce, the advantage that we have shifts to what is harder to replicate and that is original journalism.
Read More
FNP’s halting stumble to dubious relevance

FNP’s halting stumble to dubious relevance

There are 282,000 fixed line subscribers in Trinidad and Tobago. That number has been dropping incrementally year over year declining 16.1 percent between 2024 and 2025.
Read More
Samsung’s big bet on AI

Samsung’s big bet on AI

"Gemini can now use advanced reasoning to understand your screen context, parse complex images as prompts, and execute multi-step actions across apps.”
Read More
The data centre dilemma

The data centre dilemma

Discourse, instead of a patronising pat on the head asking whether you have a doctorate, should govern communication between a government and the people who elected them.
Read More
How should business and government embrace AI?

How should business and government embrace AI?

"Very few people in the world can quantify the fiscal value of AI." - Anton Alexander
Read More
How influencer marketing works in the Caribbean

How influencer marketing works in the Caribbean

You have to really trust in this influencer to represent your brand, to be an advocate, to be the voice of your brand.
Read More
Yes, a website is work. Yes, it’s worth it

Yes, a website is work. Yes, it’s worth it

AI tools suck up the content of creators across the open internet, turning their work into a pudding of responses in search.
Read More
No more fire in these wires

No more fire in these wires

FireWire effectively died with MacOS 26 Tahoe, when Apple removed the drivers that enabled the OS-level connection to its operating system.
Read More
What the heck is chip binning?

What the heck is chip binning?

Instead of manufacturing multiple versions of a processor with different numbers of active cores, manufacturers create one master processor and then test the yields.
Read More
Solving the region’s journalism problem

Solving the region’s journalism problem

There's formulaic approach to the content that we produce that sometimes totally denies or is ignorant of audience interest.
Read More
Tambini to journalists: “Keep doing what you’re doing”

Tambini to journalists: “Keep doing what you’re doing”

There are lots of international standards to support that idea of the state supporting the media, but that support is often abused, so it has to be based on real...
Read More
How do we unfetter journalism from the shackles of business?

How do we unfetter journalism from the shackles of business?

Journalism must dissect information, deepen the understanding of it and bring clarity to the news consumer.
Read More
What the Canvas hack tells us about higher education software

What the Canvas hack tells us about higher education software

Instructure is managing a very different proposition than most software vendors do. It has positioned itself as an education partner managing a wide range of integrations with education software tools.
Read More
Ghost women in AI? Hardly!

Ghost women in AI? Hardly!

"When I first came out of university a million years ago, everybody was like, why build something here? Just take what's in Europe, lift and shift. That has been the...
Read More
IShowSpeed: Here and gone

IShowSpeed: Here and gone

Watkins has 53 million subscribers on YouTube and his Trinidad and Tobago visit alone clocked 4.8 million views for a five hour and 47 minute stream.
Read More
How TT journalists can turn modern media realities to advantage

How TT journalists can turn modern media realities to advantage

The faceless, anonymized journalist adhering to a house style holds little value for this next generation audience.
Read More
Reuters report on young news readers holds no surprises

Reuters report on young news readers holds no surprises

The critical 18-34 age group recorded a decline in enthusiasm for daily news from 79 percent in 2017 to 64 percent in 2025
Read More
The state of ransomware in the Caribbean

The state of ransomware in the Caribbean

The report counted 21 confirmed dumps of information to the dark web, but Parasram estimates that twice that number were breached.
Read More
Digital döstädning

Digital döstädning

You may not care after you're gone, but a computer desktop littered with file icons is nobody's idea of a good time.
Read More
The silent, growing danger of ransomware The silent, growing danger of ransomware
How should a newsroom of the (very near) future work? How should a newsroom of the...
FNP’s halting stumble to dubious relevance FNP’s halting stumble to dubious relevance
Samsung’s big bet on AI Samsung’s big bet on AI
The data centre dilemma The data centre dilemma
How should business and government embrace AI? How should business and government embrace...
How influencer marketing works in the Caribbean How influencer marketing works in the...
Yes, a website is work. Yes, it’s worth it Yes, a website is work. Yes,...
No more fire in these wires No more fire in these wires
What the heck is chip binning? What the heck is chip binning?
Solving the region’s journalism problem Solving the region’s journalism problem
Tambini to journalists: “Keep doing what you’re doing” Tambini to journalists: “Keep doing what...
How do we unfetter journalism from the shackles of business? How do we unfetter journalism from...
What the Canvas hack tells us about higher education software What the Canvas hack tells us...
Ghost women in AI? Hardly! Ghost women in AI? Hardly!
IShowSpeed: Here and gone IShowSpeed: Here and gone
How TT journalists can turn modern media realities to advantage How TT journalists can turn modern...
Reuters report on young news readers holds no surprises Reuters report on young news readers...
The state of ransomware in the Caribbean The state of ransomware in the...
Digital döstädning Digital döstädning

🤞 Get connected!

A once weekly email notification of new stories on TechNewsTT. Just that. No spam.

Possible UI Glitch. Click top right corner to dismiss 👉

Get Connected!

A once weekly email notification of new stories on TechNewsTT.

Just that. No spam.

Subscribe
Notify of
guest

This site uses Akismet to reduce spam. Learn how your comment data is processed.

0 Comments
Oldest
Newest Most Voted

RELATED POSTS