logo

The State of Ransomware – Q1 2026

ID: 636a1c9f-ece8-5f45-89c2-b4b85da451c6

STIX ID: report--636a1c9f-ece8-5f45-89c2-b4b85da451c6

Feed Name: Check Point Research

Threat Score
85/100

Date Published: 2026-05-11

Date Updated: 2026-05-11

Author: matthewsu

...
...

Q1 2026 ransomware intelligence: 2,122 victims posted to data-leak sites as the ecosystem reconsolidated around fewer, more capable operators—Qilin, Akira, The Gentlemen and LockBit together claiming 41% of victims. Key developments include The Gentlemen’s rapid rise fueled by a 14,700-device FortiGate access stockpile (CVE-2024-55591), LockBit 5.0’s comeback with multi-platform capabilities, notable geographic shifts away from the US, and evidence that large-scale mass-exploitation campaigns (e.g., Cl0p/Oracle EBS) continue to shape country- and industry-level statistics.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.