zerofox logo
Advisories

ZeroFox Intelligence Assessment - Q2 2026 Ransomware Wrap-up

|by Alpha Team

banner image

ZeroFox Intelligence Assessment - Q2 2026 Ransomware Wrap-up

TLP:Clear

Standing Intelligence Requirements

DDW

For the most up-to-date list of ZeroFox’s Intelligence Requirements, please visit:

https://cloud.zerofox.com/intelligence/advisories/14956

Link to Download

View the full report here.

Key Findings

  • ZeroFox observed at least 1,885 separate ransomware and digital extortion (R&DE) incidents in Q2 2026, a decrease of approximately 8.5 percent from Q1 2026. However, Q2 2026 marked an overall increase of R&DE incidents year-over-year from Q2 2025 and Q2 2024.
  • The global R&DE threat environment is almost certainly undergoing a geographic shift. Although historically the largest volume of incidents has occurred in North America, the region’s proportional share is declining. Europe experienced significant year-over-year increases in R&DE incidents the first half of 2026, while the Asia-Pacific region has experienced uninterrupted quarter-over-quarter share growth since Q1 2024—and both are gradually absorbing larger shares.
  • Qilin concluded Q2 2026 as the most active ransomware collective globally (at least 295 separate incidents), signaling both its dominance in the first half of 2026 and an unbroken 12-month period as the leading ransomware threat actor that began in Q2 2025.

Tags: tlp:clear threat actor global