Ransomware Gangs Vie for Cyber Supremacy
A rivalry between major threat actors is escalating, with data showing a surge in attacks targeting small businesses and large enterprises.
A high-stakes power struggle between prominent cybercrime syndicates is altering the threat landscape, as two groups compete to secure their dominance in the digital underworld. Data indicates that this tactical competition is resulting in a sharp rise in incident volume, disproportionately impacting smaller organizational structures while simultaneously drawing larger corporations into the crosshairs.
The Leaders of the Malware Race
Analysis of threat actor activity during the second quarter of 2026 highlights two primary organizations driving the current surge in malicious operations. By monitoring more than 200 threat actor blogs, researchers identified 2,581 distinct ransomware incidents during this period. The data reveals that Qilin and The Gentlemen are significantly outpacing other groups in frequency, with DragonForce trailing behind as the third most active entity.
While Qilin remains the most prolific actor overall, its operational pace saw a slight decline compared to the previous quarter. In contrast, The Gentlemen have ramped up their efforts, recording a 39% increase in activity during the April to June timeframe.
Data on the 2026 Ransomware Landscape
- Total ransomware attacks in Q2 2026: 2,581
- Attacks attributed to Qilin: 299
- Attacks attributed to The Gentlemen: 284
- Attacks attributed to DragonForce: 147
- US-based SMBs affected: 769
- Percentage increase in attacks against $1 billion+ revenue enterprises: 74%
Escalating Risks for Smaller Businesses
Small and medium-sized businesses continue to bear the brunt of these campaigns. These organizations, typically characterized by having fewer than 200 employees and annual revenues under $25 million, recorded 769 incidents in the United States alone. Other regions, including Canada, Germany, and the UK, also reported significant attack counts, though at a lower volume than the US.
Security researchers suggest that these smaller targets remain attractive due to perceived deficiencies in their defensive infrastructure. By selecting organizations with less robust security postures, attackers can maximize their success rates.
Ransomware actors historically target SMBs because these organizations often lack comprehensive defenses, which can increase the likelihood of a successful attack.
— Vakaris Noreika, cybersecurity expert at NordStellar
The Pivot Toward Corporate Targets
The landscape is shifting as major enterprises with revenues exceeding $1 billion are increasingly targeted. Data shows these high-value organizations experienced 40 incidents in Q2, up from 23 in the first quarter, representing a 74% increase. Experts view this trend as a byproduct of the ongoing rivalry between threat groups, where large-scale breaches are used to solidify a group's standing.
This recent spike in enterprise targeting is unusual and may be a temporary fluctuation. This shift likely stems from the rivalry between dominant threat actors — a successful hit on a major corporation is a badge of honor that boosts a group’s reputation within the cybercriminal underground.
— Vakaris Noreika, cybersecurity expert at NordStellar
Implications for Security Postures
This escalating competition suggests that organizational size may no longer be a reliable indicator of risk. As rival gangs seek higher-profile targets to boost their reputations, both large enterprises and smaller firms face a more volatile environment. For businesses, this suggests that the threshold for what constitutes a "high-value" target is evolving. The focus on reputation-building within the cybercriminal community implies that defensive strategies must account for attackers motivated by status as much as direct financial gain, potentially leading to more aggressive exploitation tactics regardless of the victim's scale.
Sources
- TechRadar Original source
Continue Reading
Unicode Trick Fuels Million-Email Phishing Surge
A campaign hides 'funding' lure words with invisible Unicode tags, splitting keywords to slip past filters.
French hospital fined €500,000 after breach exposes data of 727,000
CNIL fines Hôpital privé de la Loire for security failures that led to a breach exposing data of over 727,000 people.
AI-Driven Malware Marks Exilwire's Underground Trade in Breached Hosts
BraZetsu framework turns compromised Windows machines into commercial inventory for Intermediary access brokers.