BlackFog reports 40% rise in undisclosed ransomware
Mon, 3rd Aug 2026 (Today)
BlackFog's Q2 ransomware report shows a 40% year-on-year rise in undisclosed attacks, with 2,027 incidents identified during the quarter.
The report recorded 306 publicly disclosed ransomware attacks, up 16% from the previous quarter, and noted that publicly reported incidents represented only a small share of overall activity. The findings were based on publicly available information, ransomware leak sites, open-source intelligence and data gathered through BlackFog's own systems.
The data points to a ransomware market that remains fragmented and active. Across undisclosed attacks, 93 groups were active during the quarter, including 28 new groups, twice the number seen in the first quarter.
Qilin was the most active group in undisclosed incidents, with 285 attacks, or 14% of the total. It was followed by The Gentlemen with 219 attacks, or 11%, and Dragon Force with 137 attacks, or 7%.
Among publicly disclosed incidents, Shiny Hunters accounted for 28 attacks, representing 9% of the total. Qilin followed with 19 attacks, or 6%, while INC was linked to 13 attacks, or 4%.
Attribution remained a challenge, with 30% of all publicly disclosed ransomware incidents not linked to any known group.
Sector trends
Healthcare was the most targeted sector in disclosed attacks, with 81 incidents accounting for 26% of the total. The services sector ranked second with 45 attacks, or 15%, followed by government with 30 attacks, or 10%.
While healthcare remained the leading target by volume, the sharpest quarterly change came in services. Disclosed attacks on the services sector rose 221% compared with the first quarter.
Geographically, the United States remained the main target for disclosed attacks, accounting for 169 incidents, or 55% of the total. Australia ranked second with 54 incidents, or 18%.
The highest ransom demand recorded during the quarter was USD $25 million. The report also found that 97% of disclosed incidents involved data exfiltration, which BlackFog described as the highest rate it has recorded.
New groups
One of the newer groups highlighted in the report was Settra, first observed in June. Settra claimed 22 victims during the quarter, more than any other newly identified group in the period.
BlackFog said the group launched attacks across seven countries within its first four days of activity: the US, UK, France, Portugal, Taiwan, South Korea and Singapore. The speed and spread of those attacks suggest some new entrants are arriving with international reach from the outset rather than building gradually.
The report also underlined the continuing role of stolen data in ransomware incidents. The average volume of data taken per undisclosed incident reached 508GB, while victims were given an average of seven days to meet ransom demands.
That combination of short deadlines and large-scale data theft reflects a model in which extortion extends beyond system disruption. Attackers are increasingly relying on the threat of releasing or misusing stolen information, even when victims choose not to disclose an incident publicly.
The quarterly figures add to evidence that the gap between disclosed and undisclosed ransomware cases remains wide. With more than 2,000 undisclosed attacks identified against 306 publicly disclosed incidents, the report suggests many events still do not enter the public record.
For companies and public bodies, that imbalance complicates efforts to assess the scale of the threat across sectors and regions. It also makes it harder to track shifts in attacker behaviour when a substantial share of activity becomes visible only through leak sites and related monitoring.
BlackFog said 57 ransomware variants were associated with disclosed attacks during the quarter, a 21% increase from the first quarter. The rise points to a broadening field of tools and brands in circulation, alongside the appearance of newly formed groups.
Dr Darren Williams, Founder and Chief Executive Officer of BlackFog, commented on the findings.
"The trends we've identified over the last quarter underline not only the scale of the ransomware threat, but also how quickly new groups can emerge and establish themselves. This is a landscape shaped by persistent, well-organised and highly motivated threat actors. While the tactics used by these groups continue to evolve, one objective remains consistent: stealing data. Data exfiltration is at the heart of modern ransomware and will continue to be the primary goal of these attacks. The defining difference between organisations that recover quickly and those left facing significant financial, operational and reputational damage is their ability to prevent data from leaving the endpoint in the first place. Preventing data exfiltration is no longer just part of the ransomware defence strategy - it is the strategy," said Dr Darren Williams, Founder and Chief Executive Officer of BlackFog.