- NordStellar reports 2,581 ransomware attacks in Q2 2026, with Qilin (299) and The Gentlemen (284) leading the activity, far ahead of DragonForce (147).
- American SMEs were hit hardest, with 769 incidents; Canada (97), Germany (83) and the United Kingdom (74) followed, while attacks on billion-dollar companies jumped 74%.
- Experts say rivalry between Qilin and The Gentlemen is behind the rise, with major commercial successes seen as reputational trophies in the underground cybercriminal world.
Two ransomware gangs are fighting for dominance, and US-based SMBs are suffering the most, experts say.
New data on the state of ransomware in 2026, compiled by security experts at NordStellar, shows that two groups – Qilin and The Gentlemen – are by far the most active.
After analyzing more than 200 bad actor blogs, NordStellar concluded that there were 2,581 ransomware attacks in the second quarter of the year – and of that number, 299 belonged to Qilin, the world’s most active bad actor. The Gentlemen follow closely with 284 attacks. The third most active group – DragonForce – doesn’t even come close with “only” 147 attacks.
SMEs and businesses attacked
Although the race seems tight, it was actually the Gentlemen who did the heavy lifting between April and June 2026. This group saw a 39% increase in attacks, while Qilin activity actually decreased somewhat compared to the first quarter.
In this morbid race to the bottom, the biggest victims are U.S.-based small and medium-sized businesses (SMEs). These companies, with up to 200 employees and less than $25 million in revenue, suffered 769 attacks in the second quarter of 2026, followed by Canada (97), Germany (83) and the United Kingdom (74).
NordStellar also mentioned US companies, which are now increasingly being targeted. Attacks against organizations with revenues exceeding $1 billion increased 74%, from 23 incidents in the first quarter to 40 in the second quarter.
“Ransomware actors traditionally target SMBs, as these organizations often lack comprehensive defenses, which can increase the chances of an attack being successful,” commented Vakaris Noreika, cybersecurity expert at NordStellar.
“This recent uptick in corporate targeting is unusual and may be a temporary fluctuation. This change likely stems from rivalry among dominant threat actors: a successful attack on a large corporation is a badge of honor that boosts a group’s reputation within underground cybercrime.”
The best antivirus for every budget
Follow TechRadar on Google News And add us as your favorite source to get our news, reviews and expert opinions in your feeds.




