GuidePoint Security Reports Record-High Ransomware Activity as Victims Rise 75% Year Over Year

GuidePoint Security Reports Record-High Ransomware Activity as Victims Rise 75% Year Over Year

New GRIT Report Shows Ransomware Operations Becoming More Widespread and Moving Faster, Even as Payment Rates Fall

GuidePoint Security, the cybersecurity advisor and services partner organizations rely on to protect what matters most, today released the GuidePoint Research and Intelligence Team’s (GRIT) Q3 2026 Ransomware and Cyber Threat Insights Report.

Even as ransom payment rates declined, GRIT tracked 2,760 ransomware victims in Q3 2026 — more than in any previous quarter — across more groups and more countries.

“The barrier to entry in ransomware keeps dropping,” said Nick Hyatt, Principal Threat Intelligence Consultant at GuidePoint Security. “Tools, playbooks and infrastructure are readily available through the affiliate model, allowing new groups to emerge faster and more actors to launch repeatable campaigns without building capabilities from scratch. That makes volume a viable strategy even when fewer victims pay.”

Key findings from the report include:

  • Ransomware victim volume reached a record high. GRIT recorded 2,760 victims in Q3 2026, up 21% from Q2 2026 and 75% from Q3 2025.
  • The number of threat groups continues to grow. Active ransomware groups numbered 112 in Q3 2026, a 23% quarter-over-quarter increase and a 47% year-over-year increase.
  • Payment rates fell, but average payments increased. Analysis of internal data found that ransomware payment rates fell by more than half year over year, while the average payment among organizations that paid rose 34% and ransomware case volume increased 61%.
  • The Gentlemen narrowly overtook Qilin as the most active threat group. The Gentlemen accounted for 12.9% of observed victims in Q3 2026, compared with 12.6% for Qilin. Together, the two groups claimed about one in four victims.
  • Ransomware targeting is broadening geographically. Victims spanned 115 countries, up from 108 in Q2 2026 and 90 in Q3 2025. The United States remained the most targeted country, accounting for 42% of victims.
  • Manufacturing remains the most impacted industry. Manufacturing continued to lead all industries in observed victim volume, followed by technology and healthcare. Banking and finance returned to the top 10 after dropping out in Q2 2026, driven in part by a sustained social-engineering campaign targeting private equity firms.

The report also examines the rise of ShinyHunters as a prominent data-extortion actor, a surge in vulnerability disclosures — including nearly 1,000 in a single September security update — and the growing use of AI agents in cybercrime.

“Our assessment is that AI is beginning to shorten the time between initial access and impact for some attackers,” Hyatt added. “The encouraging part is that these attacks succeed through familiar weaknesses, such as stolen credentials and unpatched software. Organizations that pair fast patching with strong identity controls and automated response can close that window.”

The GRIT Q3 2026 Ransomware and Cyber Threat Insights Report is based on data obtained from publicly available resources, vendor threat research, internal incident response case data and open-source intelligence collected from illicit forums and marketplaces.

For more information:

About GuidePoint Security

GuidePoint Security helps organizations overcome the most complex cybersecurity challenges, mature their security posture, minimize risk and ensure compliance. As a trusted cybersecurity advisor and partner, GuidePoint keeps people, data, and operations safe. We deliver tailored cybersecurity services and offerings that adapt and scale to safeguard the nation’s leading organizations today, while preparing them to confidently face tomorrow's cyber challenges. More than 5,900 organizations of all sizes and across every industry, as well as over half of U.S. cabinet-level agencies, rely on GuidePoint to strengthen their defenses and reduce risk. Stronger Together. Protecting What’s Next. Learn more at guidepointsecurity.com.

Nicole Lavella
nicole.lavella@guidepointsecurity.com
703-403-7066

View source version on businesswire.com: https://www.businesswire.com/news/home/20261008558530/en/

The articles, information, and content displayed on this webpage may include materials prepared and provided by third parties. Such third-party content is offered for informational purposes only and is not endorsed, reviewed, or verified by Morningstar.

Morningstar makes no representations or warranties regarding the accuracy, completeness, timeliness, or reliability of any third-party content displayed on this site. The views and opinions expressed in third-party content are those of the respective authors and do not necessarily reflect the views of Morningstar, its affiliates, or employees.

Morningstar is not responsible for any errors, omissions, or delays in this content, nor for any actions taken in reliance thereon. Users are advised to exercise their own judgment and seek independent financial advice before making any decisions based on such content. The third-party providers of this content are not affiliated with Morningstar, and their inclusion on this site does not imply any form of partnership, agency, or endorsement.

Popular

Sponsor Center