Trending Topics

What is ransomware? 2026 Update
Ransomware attacks remain one of the most costly information security risks. Not just in financial terms but reputationally too. Here, we explain both how ransomware works and how you can best defend against it. Jump to each section using the following links:
Back to basics
Ransomware is, as the name implies, a type of malware designed to hold a network and its data hostage until a fee is paid to the criminals responsible. That, however, is too simplistic a definition, especially as ransomware techniques and tactics have changed over the years.
The basic premise of compromising a network to access and encrypt the data within remains. However, both the methods of compromise and the nature of the extortion have evolved to make avoiding payment a harder and costlier option for the victim organisation.
It’s unusual for the encryption of data to be the only impact of a successful ransomware attack anymore. Instead, that data will likely have been exfiltrated by the attackers before encryption, adding the threat of publication or sale to the extortion equation. This is sometimes known as double-extortion ransomware.
In addition, ransomware groups may subject victims to denial of service attacks of still-operational websites and services to further add to the pressure to pay.
Who is at risk from a ransomware attack?
Going back in time, ransomware was aimed mostly at individuals. That’s when the ransoms were relatively small – and people’s cybersecurity awareness likewise.
This changed as soon as organised criminals realised they could actually make real money by targeting the enterprise. Not just businesses, mind you: any enterprise that can be seen as a potential valuable target.
This has meant that big brands, paying big ransoms, have been the subject of media headlines. But they’re not alone. The education and health sectors are both under constant attack, with universities and hospitals among the victims.
If you’re a small business, then you’re not off the ransomware radar either: if you have valuable clients in the supply chain, then there is still money to be made.
The prime driver for ransomware attackers is a double-whammy of how valuable the data is and how likely the target will be to pay up. Larger enterprises will likely have costly ransomware insurance than smaller ones, while smaller businesses may have less robust defences.
Why do ransomware threats matter?
All successful cyberattacks matter. If a threat actor has found a way through your defences then you need to reassess and adjust your security strategy to prevent repeats. Obviously, there is the potential financial impact of a ransomware attack, although as more governments look to make ransomware payments illegal the direct extortion might have less of an impact.
Indirect costs, however, still mount up. There are insurance premiums to consider, hits to productivity and, perhaps most importantly, the real cost of reputational damage and litigation from impacted customers or clients.
What impact has AI had on ransomware?
The mantra “Everything changes, Everything stays the same” was almost made for the ransomware threat.
Social engineering has long been avenue number one for the would-be ransomware attacker, but the technology involved with phishing campaigns has evolved massively with the availability of AI resources, including those aimed directly at the criminal market.
The end result is that these initial access attacks are now much harder to spot and defend against, employing highly targeted, highly believable email and text messages, as well as deepfake audio and video.
When it comes to probing organisations for weaknesses, what could have taken weeks or months of surveillance and scanning can now be accomplished in minutes using AI. Not just finding vulnerabilities, mind you, but all of the identification of assets, phishing optimisation and behaviour shifts to avoid detection that go along with a ransomware attack.
Not only can such AI-powered threats automate the attack process, they can also adapt in real-time. But here’s the kicker: these autonomous ransomware campaigns can and are executed in their thousands, all at the same time, with human intervention needed only when success has been achieved.
Thanks to AI, the odds are now in favour of the attacker – both in terms of identifying weaknesses and in the time it takes to exploit them.
Who are the main ransomware threat groups in 2026?

According to the latest BlackFog State of Ransomware Report, covering quarter one of 2026, 38% of all publicly disclosed ransomware attacks weren’t attributed to any known group at all. However, that doesn’t mean that there has been a decline in the number of ransomware threat actors. Far from it: 79 groups claimed ransomware victims in the first three months of 2026 alone.
The most active players are as follows:
Qilin: The most active group in the BlackFog analysis in 2026, in terms of both disclosed and undisclosed attacks. Qilin employs a ransomware-as-a-service model for its many affiliates.
The Gentlemen: A group that has come a long way in a short time. Since first emerging in 2025, it has been responsible for 273 successful attacks. Leveraging double extortion methods, this group targets mid-to-large-sized organisations to demand higher ransom payments.
Akira: The FBI has described Akira as “continuing to evolve”. It says the group is responsible for at least 250 attacks across a wide variety of industry sectors. It has a reputation for targeting virtualised environments.
International law enforcement takedowns: Have they had any effect?
Many assume that ransomware groups, often based in countries such as Russia and North Korea, sit out of reach of the law. Not so, as many international law enforcement takedowns have proved.
In March 2026, Europol and Microsoft hit the Typhoon 2FA infrastructure – often used by ransomware actors – and seized more than 300 domains used by the criminal organisation.
A year previous, the FBI seized large parts of the Lumma Stealer infrastructure. That was a huge blow, as this infostealer malware was used by ransomware actors to compromise login credentials as part of initial access operations. The FBI has also had success targeting dark web criminal marketplaces used by ransomware players .
Unfortunately, criminal organisations in the cyber space are like a hydra: cut off one head and ten new ones grow back.
Take the takedown of Typhoon 2FA infrastructure, for example. Within a month, threat intelligence analysts reported that the group’s activity was back to pre-raid levels. The tactics, techniques and procedures didn’t change; the threat actors simply moved to new infrastructure and carried on.
How can you best mitigate against a ransomware attack?
Although, as noted above, law enforcement have successfully taken down ransomware group infrastructure, the ultimate mitigation responsibility rests with you.
Let’s deal with the elephant in the mitigation room first: data backups alone won’t protect your business against ransomware attacks. Yes, you need them; no, they are not a silver bullet. First of all, threat actors might compromise your access to backup data as well as primary data. Secondly, a backup does not protect you from the exfiltrated data extortion threat.
Cyber insurance isn’t a mitigation either, although far too many organisations treat it as such. However, what a genuinely responsible cyber-insurance policy brings to the mitigation table is compliance with the security basics that can help protect you from the ransomware threat: endpoint protection, patch management, penetration/vulnerability scanning, and identity & access management, for example.
The mistakes SMEs make when dealing with the ransomware threat
Talking of cyber insurance, according to the latest Hiscox Cyber Readiness Report, the biggest mistakes that SMEs make when it comes to being prepared for the ransomware threat are as follows:
Treating ransomware purely as an IT issue. Although this is understandable, it really is a mistake. Ransomware attacks quickly escalate beyond IT and will impact operations, revenue and reputation. Ransomware is a business risk, and must be seen as such.
Relying on ransom payment as a quick fix. See the next section for the legalities of paying a ransom, but there are other factors to consider too. First, there’s no guarantee that paying will get your data back; you’re dealing with criminals after all. Some decryption keys are known to fail, and there can be no trust that stolen data will be destroyed by the attackers. Second, paying leaves you open to repeat attacks, from the same group or other affiliated actors.
A lack of proper attack preparation. Needless to say, failing to have multi-factor authentication, strong password policies, and either none or untested incident response plans will leave you exposed to ransomware before and after any attack.
Should you pay a ransom: the latest guidance
First things first: it is not, generally speaking, illegal to pay a ransomware ransom. In the UK, for example, the most recent government advice is that it “does not condone making ransomware payments,” and there are no guarantees for organisations doing so that they will regain access to data.
However, there are exceptions where it is illegal: public sector bodies and those operating critical national infrastructure, payment of ransoms to groups on official financial sanctions lists and those involved in what is suspected to be terrorist activity.
The FBI and the US Cybersecurity and Infrastructure Security Agency advise against paying ransoms for the same reasons as the UK government. However, it’s also generally legal for private businesses to do so.
Here, though, federal regulations and state-specific bans come into play. You should always check your own regional legislature before assuming legality. Like the UK, there are prohibited individuals and entities to whom monies cannot be paid.
Summary
- Ransomware groups continue to target everyone from small businesses to large enterprises, as well as the education, health and government sectors.
- It is now commonplace for ransomware to exfiltrate data before encryption and hold it hostage against a threat to publish or sell it.
- Financial harm isn’t limited to ransoms: productivity loss, legal action, and reputational damage all hit the bottom line.
- While it isn’t illegal to pay ransoms in most cases, check your local laws (including state level where applicable) or you may find yourself in trouble.
This article was updated on 10 April 2026 with new sections “What impact has AI had on ransomware?”, “International law enforcement takedowns: Have they had any effect?” and ‘Should you pay a ransom: the latest guidance”. We also updated the summary.
It was further updated on 7 May 2026 with new sections “Who are the main ransomware threat groups in 2026?” and “The mistakes SMEs make when dealing with the ransomware threat”.
