Ransomware Is Accelerating, But It's Not Because of AI
Ransomware activity is surging, with a 25% increase in incidents between April 2025 and March 2026, driven by a fragmented ecosystem and the emergence of numerous new groups. Black Kite researchers found that many victims, particularly in the $50 million to $100 million revenue range, had significant externally visible weaknesses, leading to a 60% increase in reported victims. The growth is happening without a new type of attacker, but AI has lowered the barrier to entry for more individuals to participate in ransomware operations.
Ransomware activity is experiencing a significant surge, with Black Kite researchers identifying a 25% increase in reported ransomware incidents between April 1, 2025, and March 31, 2026. This growth is largely due to a proliferation of ransomware groups and an expansion of attacks targeting smaller organizations. Between April and September 2025, Black Kite counted 2,904 victims, and from October 2025 to March 2026, they identified 4,647 victims, representing a substantial 60% increase. March 2026 saw the highest number of attacks, with 861 organizations falling victim.
Black Kite’s analysis revealed a consistent pattern: many victims exhibited high ransomware susceptibility indices (RSI) – a measure of an organization’s exposure to ransomware based on externally visible factors like exposed credentials and unpatched vulnerabilities. Specifically, 41% of companies with an RSI higher than 0.8 experienced a ransomware incident, while only 0.14% of organizations with scores below 0.2 did. More than 90% of victims showed a significant spike in their RSI score just before being hit.
Black Kite attributed the growth to a democratization of the ransomware landscape, with established groups like Qilin, Everest, Cl0p, and World Leaks continuing to target US-based organizations, while newer groups primarily focused on victims in Europe, South America, Africa, Asia, and the Middle East. AI did not directly accelerate ransomware attacks, but it lowered the technical skill barrier, enabling more individuals to participate. Black Kite observed that ransomware operations lasted a median of just 4.9 months before dissolving.
Manufacturing companies remained the top target, followed by professional, scientific, and technical services, and construction companies emerged as the third-most targeted sector. Notably, ransomware attacks in Europe outpaced those in the US. While large companies were still targeted, the growth in volume was largely driven by organizations in the $50 million to $100 million revenue tier and those in the $1 million to $5 million range – indicating that no company was immune.
Despite the increase in incidents, many victims appeared to address their vulnerabilities only after an attack, suggesting a reactive approach rather than proactive security measures. Black Kite recommends treating the post-incident period as ongoing work, emphasizing structured exposure reviews at 30, 60, and 90 days, prioritizing exploitation of vulnerabilities over CVSS scores, and extending visibility into vendor and SaaS relationships, along with implementing continuous monitoring.
