State of Ransomware: September 2026
Published 1 October 2026 · ThreatVectr Intelligence
Ransomware groups claimed 831 attacks on organisations worldwide in September 2026, down 25% on the previous month's 1,114. 77 distinct groups posted at least one victim during the month, across 91 countries. The busiest single day was 14 September, with 54 victims listed.
The Gentlemen was the most active operation of the month, claiming 102 victims — 12% of all listings. Qilin (74) and Storm (37) followed. 8 groups appeared for the first time, including Vexy ransomware, N0n, Endzone, Spirals.
Manufacturing bore the heaviest targeting, with 139 claimed victims, ahead of Professional Services (95) and Technology (94). By geography, United States accounted for 259 claims — 31% of the month — with Germany (36) and Canada (29) next.
Claims per day — September 2026
Most active groups
- 1The Gentlemen110212%
- 2Qilin1749%
- 3Storm3374%
- 4Akira4344%
- 5Krybit2344%
- 6SafePay15324%
- 7Auditteam35283%
- 8INC Ransom3283%
- 9Cl0p6253%
- 10Emperador14233%
First seen this month:Vexy ransomware, N0n, Endzone, Spirals, Blacklocks, Imnotavillain, Secp0, Ulose
Most-targeted sectors
- 1Manufacturing139
- 2Professional Services95
- 3Technology94
- 4Other77
- 5Healthcare74
- 6Retail & E-Commerce52
- 7Financial Services41
- 8Education34
- 9Transportation31
- 10Government & Defense28
Most-affected countries
- 1United States259
- 2Germany36
- 3Canada29
- 4United Kingdom29
- 5Brazil28
- 6Italy26
- 7India24
- 8Argentina17
- 9Spain17
- 10France17
Every figure in this report counts a claim posted to a criminal leak site, observed via the monitoring service ransomware.live. A listing is an extortion tactic, not a confirmed breach: some claims are exaggerated, some are duplicates under new branding, and a few are outright false. Companies named in listings have not necessarily confirmed any incident, and ThreatVectr does not publish victim names from this dataset.
Cite this report
This report is free to cite and reproduce with attribution. Suggested citation:
ThreatVectr, “State of Ransomware: September 2026”, https://threatvectr.com/ransomware-tracker/reports/september-2026
Journalists and researchers: for questions about the data or methodology, contact the newsdesk.
Most ransomware starts with one email
The groups in this report overwhelmingly get in through phishing. Train2Secure runs realistic phishing simulations and short training that teach your team to spot the lure.