Ransomware groups logged 2,393 attacks on their public leak sites in the first quarter, up 4.5 percent from the previous quarter, across 79 active groups, according to Group-IB's 2026 ransomware ecosystem report released Tuesday.
The structure that once organized the trade is breaking down.
A handful of large ransomware as a service operations used to recruit affiliates and split the proceeds, but affiliates skimming funds and operators refusing to pay have eroded trust in the criminal underground.
The report said that it led to pushing more attackers to work alone and sharpening competition.
Korea has already lived that scenario.
The threat has already surfaced in Korea.
Ransomware reports to the Korea Internet & Security Agency jumped to 192 in the second half of 2025 from 82 in the first half, and the January attack on conglomerate Kyowon Group crippled about 600 of its 800 servers and exposed as many as 9.6 million user accounts.
AI is deepening the threat across the attack chain, Group-IB said, citing its use to help build the payload behind the group known as The Gentlemen and to set ransom demands based on victims' cyber insurance coverage.
The firm urged companies to watch underground markets for stolen access before intrusions begin and to fold contractors and service providers into their security reviews.
AJP Takeaways
- Group-IB's 2026 ransomware ecosystem report, released Sept. 9, 2026, counted 2,393 attacks posted to leak sites by 79 active groups in the first quarter, up 4.5 percent from the previous quarter, as criminal operators fragmented into competing independent crews.
- Ransomware reports to the Korea Internet & Security Agency rose to 192 in the second half of 2025 from 82 in the first half.
- Attackers are increasingly using artificial intelligence to develop malware and calibrate ransom demands, prompting Group-IB to urge firms to monitor underground access markets and extend security assessments to contractors and service providers.
Copyright ⓒ Aju Press All rights reserved.