Ransomware attacks were up year over year in June for the fourth consecutive month, according to the NCC Group, though attacks increased just 3% in Q2 2026 versus the previous quarter. VPNs and other network edge devices continue to be prime initial access targets. And an autonomous AI agent enters the fray.
Here is a rundown of recent ransomware developments.
NCC Group reports that ransomware gangs targeted the industrials sector (30%) above all other verticals in Q2, followed by the consumer discretionary industry (24%) and information technology (11%). Healthcare (10%) was the fourth most targeted industry, with an April attack on Signature Healthcare in Massachusetts disrupting ambulance services, forcing cancer treatment cancellations, and leading Brockton Hospital to use downtime procedures for several weeks.
Government entities experienced 89 confirmed and 98 unconfirmed ransomware attacks in the first half of 2026, according to a report from Comparitech. US government agencies were targeted the most, accounting for 31% of those attacks, though at a rate 23% less than 2H 2025. Industries under increasing attack over the past six months include transportation (52%), healthcare (35%), retail (28%), and technology (23%), Comparitech found.
Ransomware groups Qilin and The Gentlemen came in No. 1 and No. 2 in both NCC Group’s list for most attacks in Q2 2026 and Comparitech’s list for 1H 2026, though Comparitech notes that The Gentlemen, reportedly a Qilin splinter group, topped Qilin in victims claimed on their respective data leak sites for the month of June. Cyber resilience platform vendor Halcyon recently called The Gentlemen “one of the fastest-scaling ransomware threats” it has tracked.
Akira, DragonForce, Lockbit, and INC rounded out both lists’ top 6 most active threat ransomware actors. NCC Group also singled out KryBit as a notable emerging group — first observed in March 2026 — that operates as ransomware-as-a-service specializing in targeting Windows, Linux, VMware ESXi, and NAS devices. According to Halcyon, KryBit’s activity model gives the group notable growth potential.
Both Qilin and The Gentlemen have been observed deploying “EDR killer” tools of late, according to reports from Cisco Talos and ESET, respectively.
The tools, which are not new, attempt to bypass or disable endpoint security agents on PCs and servers. Notable, however, is that affiliates must develop or source their own EDR killers, a significant undertaking given the breadth of platforms used by defenders and thus a sign of growing threat group sophistication.
Network edge vulnerabilities and credentials, VPNs in particular, are being increasingly exploited by ransomware groups, according to NCC Group, which notes Akira, Qilin, and The Gentlemen as heavy users of these primary vectors. Targeted devices include systems from Fortinet, Citrix, and Check Point. Arctic Wolf recently announced an ongoing Qilin campaign versus a vulnerability in Palo Alto Networks’ GlobalProtect VPN.
Researchers from Sysdig detailed the operations of an autonomous AI agent, dubbed JadePuffer, that completed its entire intrusion chain, from initial access to database extortion, using an LLM to adapt its actions and execute more than 600 coordinated payloads. The agent harvested credentials, established persistence, and mapped internal services before encrypting configuration records, deleting the original tables, and leaving behind a Bitcoin ransom demand in what Sysdig researchers labeled “the first documented case of agentic ransomware.”