Development, begins together.
Banner alanı
IFM Sensor

🚨 Cyber Threats on the Rise: Ransomware Attacks Breaking Records in 2026! 📈

Ahmet Ö.

Corporate
  • EMS Engineer
  • art_315_ab12218e43894101b831c11765b7a8a1.jpg

    Rising Ransomware Trends 📊​


    2026 is poised to be a record-breaking year for ransomware attacks. According to a new report, the number of publicly disclosed victims has already increased by nearly 25% compared to last year.

    Ransomware attacks surged by 60% in the second half of the reporting period, as per the report from cyber risk management platform provider Black Kite.

    Black Kite's 2026 Report Details 🔍​


    Cyber surveillance company Black Kite's study, titled "2026 Ransomware Report: Why Every Year Is the Worst Year on Record?", examined the activities of approximately 300 ransomware groups between April 1, 2025, and March 31, 2026.

    During this period, the firm identified 7,551 publicly disclosed ransomware victims, marking a 24.9% increase over the previous reporting period. Attacks accelerated by 60% in the second half of the reporting period. While there were 2,904 victims in the first half (April-September 2025), this number rose to 4,647 between October 2025 and March 2026.

    Black Kite also detected 146 active ransomware groups as of June 2026, 61 of which were new actors entering the sector during the reporting period.

    Manufacturers Targeted 🏭​


    The report was released at a time when manufacturers continue to grapple with ransomware and cyberattacks. Supply chain risks, business ecosystems, the financial impact of attacks, and general security concerns are among the growing issues when preparing for such incidents.

    Manufacturers were the most affected sector by ransomware attacks last year, experiencing a 58% annual increase in the number of victims.

    Supply Chain and AI: New Threat Vectors 🔗🤖​


    Black Kite emphasized that supply chain exposure was "one of the defining ransomware pressures of the year." According to the report, major incidents often focused on systems surrounding breached companies, including vendor platforms, SaaS integrations, ERP applications, and data repositories.

    Since organizations cannot directly patch a vulnerability on a platform they do not own (often through a vendor relationship), an attack path can emerge.

    Other Key Findings 💡​


    • Qilin, a Ransomware-as-a-Service operation, claimed over 1,300 victims, nearly double that of the closest threat actor.
    • Over 40% of victims still had critical patch vulnerabilities in their latest assessment, and 30.8% had KEV (Known Exploited Vulnerabilities) exposure.
    • In security posture benchmarking, stolen log exposure was 175% higher.
    • Oracle E-Business Suite and Salesforce ecosystem integrations defined some of the most visible supply chain incidents of the year.

    Artificial intelligence (AI) is also being used to accelerate attacks. The Black Kite report stated that AI is entering the ransomware cybercrime business in two distinct ways: as technical execution support and as language for extortion pressure.

    Black Kite called AI "attack chain glue" because it connects existing tactics, reduces the time between stages, and elevates the baseline quality of criminal operations.

    Recommendations for the Post-Incident Period 🛡️​


    Black Kite offered several ways manufacturers can reduce their attack risks and respond effectively to an incident.

    For example, the report revealed that Black Kite's Ransomware Susceptibility Index actually increased after an attack. In the post-incident period, organizations need to conduct a structured 30, 60, and 90-day external exposure review covering stolen logs, KEV exposure, critical patch vulnerabilities, remote access, SaaS integrations, and vendor-managed access.

    Black Kite's Other Recommendations 📝​


    • Prioritize issues such as KEV and critical patch vulnerabilities that attackers are already exploiting.
    • Expand visibility to include vendor identity, SaaS access, and application vulnerability exposure, not just survey-based assessments.
    • Strengthen the human layer through phishing training, reinforced help desk authentication, and stronger identity recovery procedures.
    • Be prepared for AI-powered social engineering and threat actors.
     
    Back
    Top