Ransomware Attacks Rose 25% in a Year. Artificial Intelligence Isn't the Main Driver.
A new report tracked 7,551 victims worldwide between April 2025 and March 2026. The growth came from more criminal groups, weaker targets, and supply-chain shortcuts, not fancy AI tools.

Key points
- Security firm Black Kite recorded 7,551 confirmed ransomware victims worldwide between April 2025 and March 2026, a 25% rise on the prior year.
- Victim numbers jumped 60% in the second half of that period, from 2,904 in April-September 2025 to 4,647 in October 2025-March 2026.
- March 2026 was the single busiest month on record, with 861 organisations hit, roughly 28 per day.
- More than 60 new criminal groups entered the ransomware market during the study window; Black Kite counts 146 active groups as of March 2026.
- Over 90% of victims showed measurable, externally visible security weaknesses just before they were attacked.
Ransomware, which is malicious software that locks a business's files and demands payment to restore them, is not just a persistent problem. It is getting faster and wider.
That is the headline finding from Black Kite's annual ransomware report, covering April 2025 through March 2026. The company, which monitors public breach disclosures and victim lists posted by criminal gangs, counted 7,551 known victims across that twelve-month span. March 2026 alone accounted for 861 of them.
How did so many organisations get hit at once?
Two things happened together. First, the criminal market fragmented. More than 60 new ransomware groups started operating during the study period, lowering the average skill level required to run an attack campaign. Black Kite's chief research officer, Ferhat Dikbiyik, puts it plainly: "The barrier to running one keeps getting lower."
Second, attackers found a shortcut. Instead of targeting one company at a time, they broke into suppliers and IT service providers that many businesses share. One attack on a managed service provider, which is a company that handles IT systems on behalf of other businesses, let the group known as Qilin hit 32 South Korean financial institutions in a single campaign.
Supply-chain incidents involving Oracle and Salesforce were cited in the report as further examples of how one break-in can ripple outward to dozens of victims.
Artificial intelligence played a role, but a limited one. Open-source AI tools lowered the cost of writing attack code and let people with less technical skill enter the market. Early signs of AI-written code turned up inside some ransomware programs. Even so, Dikbiyik is careful about the claim. "What I can say is the growth is human. AI just let more people show up at once."
Manufacturing was the most targeted industry, with 1,660 victims. Professional and technical services firms came second at 1,389. Construction entered the top three for the first time. Nearly half of all victims (49.3%) were based in the United States, though European attacks grew faster.
Small businesses are no longer safe by obscurity. A large share of new activity fell on companies earning between one million and five million dollars a year.
For ordinary people, the risk is indirect but real. When a hospital, a payroll firm, or a local manufacturer gets locked out of its systems, staff cannot work, patients may face delays, and personal data held on company servers can be stolen and sold.
Black Kite found that more than 90% of victims had visible warning signs before the attack. Exposed passwords, unpatched software (software that has not received the latest security fixes from its maker), and open remote-access portals were common. Dikbiyik's advice after an incident: treat recovery as a 90-day process with formal security reviews at the 30, 60, and 90-day marks, not a single box to tick. Patch what attackers are actually exploiting right now, not just whatever software carries the highest theoretical risk score.



