ZeroFox Intelligence Assessment - Q2 2026 Ransomware Wrap-up
|by Alpha Team

ZeroFox Intelligence Assessment - Q2 2026 Ransomware Wrap-up
TLP:Clear
Standing Intelligence Requirements

For the most up-to-date list of ZeroFox’s Intelligence Requirements, please visit:
https://cloud.zerofox.com/intelligence/advisories/14956
Link to Download
View the full report here.
Key Findings
- ZeroFox observed at least 1,885 separate ransomware and digital extortion (R&DE) incidents in Q2 2026, a decrease of approximately 8.5 percent from Q1 2026. However, Q2 2026 marked an overall increase of R&DE incidents year-over-year from Q2 2025 and Q2 2024.
- The global R&DE threat environment is almost certainly undergoing a geographic shift. Although historically the largest volume of incidents has occurred in North America, the region’s proportional share is declining. Europe experienced significant year-over-year increases in R&DE incidents the first half of 2026, while the Asia-Pacific region has experienced uninterrupted quarter-over-quarter share growth since Q1 2024—and both are gradually absorbing larger shares.
- Qilin concluded Q2 2026 as the most active ransomware collective globally (at least 295 separate incidents), signaling both its dominance in the first half of 2026 and an unbroken 12-month period as the leading ransomware threat actor that began in Q2 2025.
Tags: tlp:clear, threat actor, global