Black Kite: Ransomware increasing across all metrics in 2026
Key Highlights
- Black Kite found 7,551 publicly disclosed ransomware victims over the past year, a 24.9% increase, with attacks accelerating in the second half of the reporting period.
- Supply chain vulnerabilities remain a major risk, while AI is helping ransomware groups speed up attacks and improve extortion efforts.
- Manufacturers continue to be a top target, and Black Kite recommends focusing on patching known vulnerabilities, strengthening vendor oversight, and preparing for AI-driven threats.
This year is shaping up to be another record-breaking year for ransomware attacks, with the amount of publicly disclosed victims having already increased by almost 25% from last year, according to one new report.
In 2026, ransomware incursions have grown by 60% during the second half of the reporting period for Black Kite, vendor of a cyber risk management platform.
The cyber surveillance company’s 2026 Ransomware Report: Why Every Year Becomes the Worst Year on Record monitored activity from almost 300 ransomware groups from April 1, 2025, through March 31, 2026.
Within that time, the firm identified 7,551 publicly disclosed ransomware victims, up 24.9% from the previous reporting period. Attacks accelerated by 60% during the second half of that reporting period, but the first half, from April to September 2025, produced 2,904 victims. From Oct. 2025 to March of this year, ransomware disclosures rose to 4,647 victims.
See also: Black Kite: Data breaches escalate to records amid slow disclosure by supply chain companies
Black Kite also identified 146 active ransomware groups by June 2026, including 61 new actors entering during the reporting period.
The report was released as manufacturers continue to struggle with ransomware and cyberattacks, as concerns rise in supply chain risks, business ecosystems, financial impacts of attacks, and overall safety issues when preparing for such incidents.
Manufacturers were hit the hardest by ransomware attacks last year, with a 58% year-over-year increase in victims, according to one study.
'Defining pressures’ and AI as ‘attack chain glue’
Black Kite also reinforced why supply chain exposure is a concern, calling it “one of the year’s defining ransomware pressures.”
The report found that major incidents centered on the systems around breached companies, such as vendor platforms, SaaS integration, ERP applications, and data stores.
The report states that since organizations cannot directly patch a vulnerability it does not own on a platform it does not run—often through a vendor relationship—an attack path can form.
Other key findings of the report include:
-
Qilin, the Ransomware-as-a-Service operation, claimed more than 1,300 victims, nearly twice as many as the nearest threat actor.
-
Over 40% of victims still carried critical patch vulnerabilities in the latest assessment, and 30.8% carried KEV exposure.
-
About 175% higher stealer log exposure in the before-and-after security posture comparison.
-
Oracle E-Business Suite and Salesforce ecosystem integrations defined several of the year's most visible supply chain incidents.
AI also is being used to accelerate attacks. The Black Kite report identified two different ways AI is entering the ransomware cybercrime business: as support for technical execution and as language for extortion pressure.
Intel about post-incident periods
Black Kite named a few ways manufacturers can mitigate the risks of attacks as well as how to effectively respond to an incident.
See also: Crystal Ball 2026: AI-driven cyberattacks are coming. Here’s how to prepare now
For example, the report found that after an attack, Black Kite’s Ransomware Susceptibility Index actually increases; during the post-incident period, organizations should have a structured 30-, 60-, and 90-day external exposure review covering stealer logs, KEV exposure, critical patch vulnerabilities, remote access, SaaS integrations and vendor-managed access.
Other advice from Black Kite’s report included:
-
Prioritizing what attackers already exploit, such as KEV and critical patch vulnerabilities.
-
Extending visibility to include vendor identity, SaaS access and application vulnerability exposure, not only questionnaire-based assessments.
-
Reinforcing the human layer through phishing training, hardened help desk verification, and stronger identity recovery procedures.
-
Preparing for AI-augmented social engineering and threat actors.
About the Author
Sarah Mattalian
Staff Writer
Sarah Mattalian is a Chicago-based journalist writing for Smart Industry and Automation World, two brands of Endeavor Business Media, covering industry trends and manufacturing technology. In 2025, she graduated with a master's degree in journalism from Northwestern University's Medill School of Journalism, specializing in health, environment and science reporting. She does freelance work as well, covering public health and the environment in Chicagoland and in the Midwest. Her work has appeared in Inside Climate News, Inside Washington Publishers, NBC4 in Washington, D.C., The Durango Herald and North Jersey Daily News. She has a translation certificate in Spanish.

