Check Point’s Q2 2026 ransomware report reveals a paradox: the criminal ecosystem is growing more crowded even as fewer victims pay. A leaked backend now shows exactly how little it takes to build a top-tier operation.
The ransomware economy expanded and consolidated at the same time in the second quarter of 2026. According to Check Point Research’s latest State of Ransomware report, data leak sites recorded 2,139 new victims between April and June — a volume essentially flat versus Q1 but a third higher than a year earlier. Yet a leaked internal chat log from the group known as The Gentlemen offered something rarer than victim counts: a rare inside view of how a top-three global ransomware operation gets built, run — and rebuilt within days of being compromised.
The top 10 ransomware groups still dominated the field, but their grip loosened. They accounted for 57.6% of all victims in Q2, down sharply from 71% in the first quarter, while the number of active groups climbed to a record 93, up from 71. Check Point researchers describe this as “de-concentration rather than fragmentation” — the same volume of attacks spread across more names, largely because affiliates displaced by RansomHub’s 2025 retirement found new homes across the ecosystem.
Qilin held onto the top spot for a fourth consecutive quarter with 279 victims, but its count fell 17% quarter-over-quarter. The real story was second place: The Gentlemen posted 269 victims, a 62% jump, and actually outpaced Qilin during June (116 victims to 72). The group finished the quarter within ten victims of the global lead.
Inside a top-tier operation
What sets this quarter apart is not the trajectory but the transparency. Two Check Point Research investigations — a forensic reconstruction of a Gentlemen intrusion and an analysis of chat logs leaked on 4 May after a hosting-provider compromise — exposed the group’s internal machinery. A core team of roughly nine operators, led by an administrator known as “Zeta88” or “Hastalamuerte,” runs the platform while a broader base of independent affiliates carries out much of the actual intrusion work under a 90/10 split, the most generous cut advertised in the criminal market.
Perhaps most notable: Zeta88 reportedly built the group’s “GLOCKER” management panel in about three days using AI coding assistants, including DeepSeek and Qwen — with the self-aware caveat that operators still need to understand and correct the code the tools produce. When the backend leaked publicly, the group acknowledged it on a criminal forum within days, announced locker upgrades to evade endpoint detection, and kept operating into June. Researchers argue this resilience — not the leak itself — is the more important finding: the barriers to reaching the top tier of ransomware have narrowed enough for a single capable operator to get there.
Fewer payers, bigger checks for the few who pay
Ransom payment rates continued a six-year decline, falling to roughly 23% in Coveware’s caseload, down from 85% in 2019. Tested backups are increasingly defeating pure encryption attacks, pushing operators toward data-theft extortion instead. But falling payment rates don’t mean falling revenue: Chainalysis tracked more than $820 million in on-chain ransomware payments during 2025. The payer market is also splitting — average payments rose 15% to $680,081, while the median fell 7% to $300,750, reflecting a “big-game up, mid-market resilient” pattern in which severely hit large enterprises still pay heavily while smaller victims increasingly refuse or negotiate down.
Law enforcement targets shared infrastructure
Rather than chasing individual groups, Q2 enforcement actions concentrated on infrastructure shared across the ransomware supply chain. An international operation coordinated by the US Secret Service and IRS-CI, with Europol and Eurojust, dismantled the AudiA6 cryptocurrency-laundering platform, which had processed roughly €336 million for ransomware actors since 2021. The US Treasury separately sanctioned four major Iranian crypto exchanges over ties to IRGC-linked ransomware actors. Microsoft’s Digital Crimes Unit took down a malware-signing service that had issued fraudulent code-signing certificates to Qilin, Akira, INC and Rhysida customers, while Europol’s Operation Endgame seized 326 servers and recovered 27 million stolen credentials tied to infostealer infrastructure.
Geography and targets shift
The United States’ share of victims fell from 50% to 42% quarter-over-quarter, largely because several of the quarter’s fastest-growing groups — including The Gentlemen and newcomer KryBit — target the US far less than the ecosystem average. Business Services remained the most targeted sector at 33% of victims, followed by Consumer Goods & Services (16%) and Industrial Manufacturing (12%).
Check Point researchers conclude that the window between vulnerability disclosure and exploitation has narrowed to hours rather than weeks, a shift they attribute directly to AI-accelerated exploit development — the same acceleration visible in how The Gentlemen built their own tooling.
Four Technologies for Ransomware Protection
Check Point provides businesses with four different technologies for ransomware protection: Workspace Security protects users, Hybrid Mesh Network Security blocks attack attempts, Exposure Management identifies vulnerabilities, and AI Security ensures the security of AI tools.
Workspace Security protects users in emails, browsers, SaaS applications, and endpoints. Using AI-powered detection, the solution stops ransomware from being delivered before it executes and mitigates lateral movement and data exfiltration following a compromise.
Hybrid Mesh Network Security applies consistent, AI-driven controls at every connection point: From firewalls that block malicious files before they reach devices to CASB scans that intercept malware infiltrating via SaaS platforms like OneDrive and Slack—a method increasingly favored by “access brokers.” Should a compromise still occur, zero-trust access via SASE Private Access limits the scope of the damage. The ransomware can then only access the resources to which the compromised user had access.
Exposure management addresses the more difficult question of which vulnerabilities ransomware groups can actually exploit, rather than simply which ones exist. Check Point’s “2026 Exposure Gap Report” found that vulnerabilities now account for 42.6 percent of critical security gaps. That’s more than double the figure from the previous year. Furthermore, realistically speaking, they can be patched in less than an hour. Utilities using the platform patch 30 percent of their vulnerabilities within this timeframe.
AI Security addresses the very same tools that ransomware groups are currently learning to use. ThreatCloud AI ensures that protection keeps pace with AI-powered exploitation of vulnerabilities. AI Agent Security manages agent permissions and enables an administrator, such as Zeta88, to develop tools within a few days. AI Red Teaming tests a company’s AI applications before deployment. Workforce AI Security prevents login credentials and information about the AI tools employees use from being leaked.

Dr. Jakob Jung is Editor-in-Chief of Security Storage and Channel Germany. He has been working in IT journalism for more than 20 years. His career includes Computer Reseller News, Heise Resale, Informationweek, Techtarget (storage and data center) and ChannelBiz. He also freelances for numerous IT publications, including Computerwoche, Channelpartner, IT-Business, Storage-Insider and ZDnet. His main topics are channel, storage, security, data center, ERP and CRM.
Contact via Mail: jakob.jung@security-storage-und-channel-germany.de