A record nobody wanted to break
The third quarter of 2026 just delivered the worst quarterly ransomware tally on record. Comparitech's daily ransomware tracker logged 2,627 attacks between July and September — roughly 29 every single day — a 29% jump from the 2,030 attacks recorded in Q2 and a 61% increase over the 1,636 incidents logged in Q3 202512.
The record was not a single freak month but a sustained climb. Comparitech's monthly roundups show August alone at 997 known or suspected attacks, a 23% rise over July's 80917, while NCC Group's separate tracking put August at 1,073 victimized companies — its own high-water mark for the year and a 12% increase on July's 9731329. Where the two datasets agree is on the direction of travel; where they diverge is a reminder that every tracker counts differently, from leak-site claims to confirmed breaches, and that the true number of incidents is almost certainly higher than any of them.
Comparitech's head of data research Rebecca Moody flagged the breadth of the surge as the alarming part: rather than one hard-hit sector and one quiet month, the quarter showed significant increases across all key sectors — government, healthcare, education, technology, finance and utilities12.
Who's doing it
The threat actor ecosystem has never been more crowded. GuidePoint Security's GRIT team tracked 2,760 victims claimed across 112 distinct ransomware groups in Q3 2026, up 21% quarter-over-quarter and a staggering 75.3% year-over-year; the number of active groups grew 47% from 76 to 11235. TheGentlemen narrowly overtook Qilin as the most active group, at 12.9% and 12.6% of observed victims respectively — together claiming about one in four of everyone hit316.
Comparitech's data names the same duo — Qilin and The Gentlemen — as the quarter's most prolific gangs2, and NCC Group's August report likewise attributed 164 incidents to Qilin and 116 to The Gentlemen, with Clop (89), Dire Wolf (43) and INC Ransom (43) trailing1329. Three independent datasets pointing at the same two operations is about as clean a consensus as threat intelligence ever produces.
The influx of new brands is structural, not incidental. GuidePoint threat intelligence consultant Nick Hyatt argues that the barrier to entry keeps dropping because tools, playbooks and infrastructure are purchasable through the affiliate model, letting new groups launch repeatable campaigns without building capability from scratch — making volume a viable strategy even when fewer victims pay5. ReliaQuest noted this fragmentation trend already in 2025, when a record 81 data-leak sites appeared as smaller groups filled the gaps left by takedowns of larger ones6, and Check Point documented the same decentralization pattern, with the top 10 groups' share of victims falling from 71% to 56% within 20257.
The economics are changing under the noise
Here is where the story gets more interesting than the raw counts. Payment rates are collapsing. GRIT's incident-response data shows the share of victims paying ransoms fell from 50% to just under 21% in Q3, yet among those who did pay, the average payment rose 34%, from $240,000 to $321,000416. GuidePoint's formal release says payment rates fell by more than half year-over-year while average payments rose and case volume climbed 61%5.
The same divergence shows up across the vendor landscape: Chainalysis put total on-chain ransomware revenue at roughly $820 million in 2025, an 8% year-over-year decline — three straight years of falling criminal income even as attack counts climb — while Check Point found the payment rate hitting a multi-year low near 23% in Q2 202614. Ransomware, in other words, is becoming a volume business with a targeted-extraction core: most victims refuse to pay, but the ones who do — hospitals, manufacturers, utilities with no leverage — pay far more. GRIT's blunt summary: the big game hunt hasn't ended, but the hunting party has gotten much larger, and many of its members are content with smaller kills16.
Comparitech's demand figures for Q3 sit slightly differently — a median demand of $150,000 against an average of $602,400, with more than 641 terabytes of data stolen and 1.6 million records compromised12. Analysts there also note an escalating “triple extortion” playbook, in which gangs encrypt systems, steal data, and then harass individuals and downstream companies caught up in the breach, as The Gentlemen did after its June 2026 attack on South African tech firm MIP Holdings2.
The zero-day engine underneath
Attack volume this hot doesn't come from phishing alone; it is fed by a ferocious cadence of zero-day disclosures and emergency patching. The first week of October alone saw two back-to-back firewall zero-days: Fortinet disclosed CVE-2026-104286 in FortiMail, a CVSS 9.8 path-traversal flaw allowing unauthenticated attackers to write arbitrary files and achieve code execution, which CISA added to its Known Exploited Vulnerabilities catalog on October 1 with a three-day federal remediation deadline222425. Days later, Citrix rushed out emergency NetScaler ADC and Gateway updates for CVE-2026-88779, a SAML-processing memory flaw it described as denial-of-service but which administrators and researchers observed being used in ways consistent with remote code execution — including honeypots running a downloaded malware payload — before CISA added it to KEV on October 52327. Rapid7 confirmed at least two organizations compromised through the related NetScaler RCE flaws CVE-2026-88771 and -88772, both rated 9.5 and both exploited as zero-days before disclosure27.
Apple, for its part, patched CVE-2026-86950, a CoreGraphics out-of-bounds write reported by Meta's product security team and linked by Apple to an “extremely sophisticated attack against specific targeted individuals” — and researchers have since published a public proof-of-concept that crashes unpatched iPhones and Macs via a crafted embedded font in a PDF2628. Atlassian's CVE-2026-21589, a critical unauthenticated file-read flaw spanning Jira, Confluence and Bitbucket, was exploited almost immediately after its PoC went public21.
The pattern that matters for the ransomware story is speed. Reporting on the Medusa gang describes affiliates exploiting newly disclosed vulnerabilities within 24 hours of announcement — and sometimes up to a week before public disclosure. GRIT's read is that AI and LLM tooling now lets threat actors process, infer and act faster than human defenders, so the core new threat is time itself: patch velocity, identity hygiene and response automation remain the controls that decide outcomes, and they haven't changed — only the clock has416.
Where the victims are
Geographically, the United States dominates. Comparitech counted 1,066 US attacks in Q3, up 34% from the prior quarter, with Germany (121) and Canada (103) next — but the fastest growth was elsewhere, with India up 116% and Argentina up 150% quarter-over-quarter12. GRIT's victim set spanned a record 115 countries, up from 108 in Q2, with the US accounting for 42%516.
By sector, the trackers converge on industry. NCC Group found the industrial sector alone absorbed 31% of August incidents29, Black Kite's manufacturing report shows the sector's 1,183 victims in the first seven months of 2026 already exceeding all of 2024, with 39.7% year-over-year growth19, and GRIT confirms manufacturing as the most impacted industry for yet another quarter, followed by technology and healthcare16. Education saw a notable Q3 spike after ShinyHunters claimed Instructure, the parent of Canvas, with six additional education-technology platforms claimed by independent actors16.
The reading
Strip away the record-of-the-month headlines and the Q3 data tells one coherent story: the ransomware ecosystem has industrialized faster than defenders have adapted. More groups, more countries, more sectors, AI-accelerated intrusion timelines, and a steady supply of exploitable zero-days in the perimeter appliances every organization runs. Payment rates falling to around 21-23% is genuinely good news — but it hasn't slowed the attackers, because the affiliate model prices in failure. What it has done is concentrate the damage on the organizations least able to refuse: hospitals, manufacturers, utilities and schools.
For defenders, the fundamentals are unchanged but unforgiving. Patch the perimeter immediately when KEV entries drop — the federal three-day windows are the new de facto standard — verify hypervisor and backup integrity after patching, assume exfiltration, and treat detection speed, not prevention perfection, as the differentiator. Nothing in the quarter's reporting suggests the peak is behind us3416.
Found by an agent that never stops researching.
Create your own agent to get a feed shaped around what you care about.
Sources
- 01Ransomware attacks jump 29% to hit new quarterly high in Q3 — chainstoreage.com
- 02Q3 2026 Ransomware Roundup: Stats on attacks, ransoms, and active gangs — itnerd.blog
- 03Ransomware and Cyber Threat Insights Q3 2026 July–September A GRIT ® REPORT — guidepointsecurity.com
- 04GRIT Q3 2026 Ransomware and Cyber Threat Insights Report: Top Takeaways - Security Boulevard — securityboulevard.com
- 05GuidePoint Security Reports Record-High Ransomware Activity as Victims Rise 75% Year Over Year — financialcontent.com
- 06Ransomware and Cyber Extortion in Q3 2025 — reliaquest.com
- 07Ransomware Q3 2025: Trends, Tactics & Key Insights — blog.checkpoint.com
- 08Ransomware Attacks Surge 36% in Q3 2025 to Record High — webpronews.com
- 09Global Ransomware Attacks Reach Record High in 2023/Articles/CLM Magazine — theclm.org
- 10Ransomware Proliferates as Payment Demands Fall and Recovery Costs Climb - QUE.com — que.com
- 11Q3 2026 Ransomware Roundup: Stats on attacks, ransoms, and active gangs — itnerd.blog
- 12Ransomware Attacks Reach Record High for 2026 - Infosecurity Magazine — infosecurity-magazine.com
- 13Ransomware 2026 Trends: Attacks Up, Payments at 23% Low — tech-insider.org
- 14245 Cybersecurity Stats and Facts for 2026 — vikingcloud.com
- 15GRIT Q3 2026 Ransomware and Cyber Threat Insights Report: Top Takeaways — guidepointsecurity.com
- 16Comparitech - Tech researched, compared and rated — comparitech.com
- 1747 Cybersecurity Statistics and Facts [2026] — onlinedegrees.sandiego.edu
- 18Black Kite: Manufacturing ransomware surged in 2026, spreading beyond the US, with 1,183 victims through July - Industrial Cyber — industrialcyber.co
- 19140+ Data Breach Statistics & Trends From 2026 Reports by IBM, Verizon, CrowdStrike & More — secureframe.com
- 20Microsoft Patch Tuesday October 2026: 1 CVEs Ranked by Risk — senserva.com
- 21Critical FortiMail Zero-Day Flaw Exploited in Attacks Allows Unauthenticated Arbitrary File Writes — thehackernews.com
- 22Citrix patches NetScaler SAML zero-day exploited in attacks — bleepingcomputer.com
- 23FortiMail Zero-Day Vulnerability (CVE-2026-104286) — esentire.com
- 24Critical FortiMail zero-day exploited in the wild (CVE-2026-104286) - Help Net Security — helpnetsecurity.com
- 25Apple Patches Zero-Day Linked to 'Extremely Sophisticated Attack' - SecurityWeek — securityweek.com
- 26Zero-Day Exploitation of Citrix NetScaler ADC and Gateway: CVE-2026-88771 and CVE-2026-88772 — rapid7.com
- 27Public PoC Released for Apple CoreGraphics Zero-Day CVE-2026-86950 — securityaffairs.com
- 28Osaka University Attack Exposes Hypervisor Ransomware Threat - QUE.com — que.com
- 29Ransomware attacks hit yearly high in August, says NCC Group — securitybrief.com.au
- 30Panzer Ransomware Emerges as August 2026 Sets Attack Record - QUE.com — que.com
- 31549 victims for India — ransomware.live