State of Ransomware: June 2026

Published 1 July 2026 · ThreatVectr Intelligence

712-7%
Claimed attacks
vs 769 the month before
70
Groups active
78
Countries affected
55
Busiest day
15 June

Ransomware groups claimed 712 attacks on organisations worldwide in June 2026, down 7% on the previous month's 769. 70 distinct groups posted at least one victim during the month, across 78 countries. The busiest single day was 15 June, with 55 victims listed.

The Gentlemen was the most active operation of the month, claiming 117 victims — 16% of all listings. Qilin (78) and LockBit (34) followed. 8 groups appeared for the first time, including Settra, Dark project, Booba project, Xpl0itrs.

Business Services bore the heaviest targeting, with 114 claimed victims, ahead of Manufacturing (80) and Technology (64). By geography, United States accounted for 206 claims — 29% of the month — with Germany (49) and United Kingdom (24) next.

Claims per day — June 2026

Most active groups

  1. 1The Gentlemen1117
  2. 2Qilin178
  3. 3LockBit334
  4. 4Akira·30
  5. 5INC Ransom·30
  6. 6Nova228
  7. 7SettraNew26
  8. 8DragonForce525
  9. 9SafePay·20
  10. 10Shinyhunters1120

First seen this month:Settra, Dark project, Booba project, Xpl0itrs, Unsafe, Wallstreet, Blackfield, Redact

Most-targeted sectors

  1. 1Business Services114
  2. 2Manufacturing80
  3. 3Technology64
  4. 4Consumer Services56
  5. 5Healthcare56
  6. 6Agriculture and Food Production36
  7. 7Construction32
  8. 8Transportation/Logistics26
  9. 9Public Sector22
  10. 10Education21

Most-affected countries

  1. 1United States206
  2. 2Germany49
  3. 3United Kingdom24
  4. 4Canada22
  5. 5France19
  6. 6Brazil18
  7. 7India18
  8. 8Italy17
  9. 9Mexico14
  10. 10Thailand14

Every figure in this report counts a claim posted to a criminal leak site, observed via the monitoring service ransomware.live. A listing is an extortion tactic, not a confirmed breach: some claims are exaggerated, some are duplicates under new branding, and a few are outright false. Companies named in listings have not necessarily confirmed any incident, and ThreatVectr does not publish victim names from this dataset.

Cite this report

This report is free to cite and reproduce with attribution. Suggested citation:

ThreatVectr, “State of Ransomware: June 2026”, https://threatvectr.com/ransomware-tracker/reports/june-2026

Journalists and researchers: for questions about the data or methodology, contact the newsdesk.

Most ransomware starts with one email

The groups in this report overwhelmingly get in through phishing. Train2Secure runs realistic phishing simulations and short training that teach your team to spot the lure.

Start free — no card required
© 2026 Threat Vectr