BlackFog published its Q2 2026 State of Ransomware report today, covering publicly disclosed and undisclosed attacks between April and June. The undisclosed count has risen even as the overall total fell 6% from Q1 2026, pointing to the structural gap between what organisations report publicly and what circulates on leak sites.
Publicly disclosed attacks numbered 306, up 16% from the previous quarter. Healthcare absorbed the heaviest hit: 81 attacks, 26% of the disclosed total. Services sector disclosures surged 221% from Q1, and government accounted for 30 attacks (10%). The United States remained the primary target, with 169 disclosed incidents (55%), followed by Australia with 54 (18%).
Exfiltration reached its highest recorded rate: 97% of disclosed incidents involved data theft, with an average of 508 GB stolen per undisclosed incident. Victims were given an average of seven days to meet ransom demands before data was published.
The group landscape has fragmented rapidly. 93 ransomware groups were active in Q2, including 28 newly formed ones — twice the number from Q1. Among undisclosed attacks, Qilin led with 285 (14%), followed by The Gentlemen with 219 (11%) and Dragon Force with 137 (7%). Among disclosed attacks, Shiny Hunters was the most active at 28 (9%). One arrival worth watching: Settra, first observed in June 2026, claimed 22 victims and operated across seven countries within its first four days, suggesting pre-existing infrastructure rather than a genuinely new entrant.
30% of publicly disclosed incidents could not be attributed to any known group.
To stay across the latest in cloud, AI and enterprise tech analysis from Compare the Cloud, subscribe to our weekly newsletter at https://www.comparethecloud.net/newsletter