Check Point Research published its Q1 2026 State of Ransomware report confirming a significant structural shift in the threat landscape. The number of active ransomware groups dropped from 85 to 71 over the quarter while the remaining operators expanded their victim counts, creating a more concentrated and operationally mature ecosystem.
Qilin led all groups with 338 victims across the quarter, maintaining its position as the most prolific operation for three consecutive quarters. The group’s output alone exceeded the combined claims of the bottom 50 active groups, demonstrating the scale advantage that established operations hold over newer or smaller competitors.
The top ten groups accounted for 71.1 percent of all data leak site posted victims, the highest concentration since Q1 2024. Qilin, Akira, The Gentlemen, and LockBit together claimed 41 percent of all victims. Manufacturing absorbed the most attacks with 76 victims in March alone, followed by construction at 53 and finance at 48.
For defenders, the consolidation pattern creates both opportunity and risk. Threat intelligence collection can focus on fewer adversaries who generate more of the threat volume. However, those concentrated groups accumulate resources and infrastructure resilience at rates that make disruption increasingly difficult. The Q1 total of 2,122 victims annualizes to approximately 8,660 organizations, an 18.5 percent projected increase over 2025’s full year total.