Close Menu
  • Home
  • News
  • Security
  • Privacy
  • Cybercrime
    • Threat Groups
    • Ransomware
    • Explainers
    • Stealer Logs
  • AI
  • OSINT
  • Tools
    • Ransomtracker
    • Stealercheck
    • FortiBleed Checker
    • Site Check
  • Data
    • Ransomware statistics
    • Ransom payment rate
  • Newsletter
  • About Us
Facebook X (Twitter) Instagram Threads
Ransomnews
  • Home
  • News
  • Security
  • Privacy
  • Cybercrime
    • Threat Groups
    • Ransomware
    • Explainers
    • Stealer Logs
  • AI
  • OSINT
  • Tools
    • Ransomtracker
    • Stealercheck
    • FortiBleed Checker
    • Site Check
  • Data
    • Ransomware statistics
    • Ransom payment rate
  • Newsletter
  • About Us
Facebook X (Twitter) LinkedIn
Ransomnews
Ransomware

Ransomware Q1 2026 leaderboard: who’s claiming the most victims

Ransomnews Research TeamBy Ransomnews Research TeamMay 2, 2026No Comments3 Mins Read878 Views
Share Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
A leaderboard ranking display with vertical bars representing different ransomware operators
Share
Facebook Twitter LinkedIn Pinterest Email Copy Link

The Q1 2026 ransomware leaderboard, built from leak-site claim counts across Ransomtracker and corroborating sources, looks meaningfully different from a year ago. The LockBit and ALPHV exits left a power vacuum that’s been partly filled, partly fragmented. Here’s the snapshot, with the caveats that always apply to leak-site numbers.

The top of the table

RansomHub remains the largest operator by claim count. The post-ALPHV affiliate consolidation is now mature, many of the experienced affiliates that used to run ALPHV operations have moved their pipeline onto RansomHub’s encryptor and infrastructure. The result is high volume and an unusually professional victim-management operation.

Akira is the surprise of Q1. Sustained victim claims across manufacturing, education, and mid-market enterprise. The technical capability remains modest by elite-operator standards but the affiliate base is large and disciplined.

Play rounds out the top three, with a steady cadence of victims and very little operational drama. Play has one of the better surviving brand-recognition profiles among 2024-vintage operators.

The growing mid-tier

The middle of the table is more interesting than the top. Qilin, Medusa, BlackBasta, BianLian, Embargo, and a handful of smaller operators are each claiming dozens to low-hundreds of victims per quarter. None has dominant share, but collectively they account for more activity than the top three.

This fragmentation is structurally different from the LockBit-era market, where one operator dominated. Today’s mid-tier is more resilient to takedowns, disrupting any single one moves a small share of activity to a competitor, but harder to engage diplomatically because there’s no single brand to negotiate with.

// Free tool

How does your own site score?

Run the same forty passive checks against your own domain — TLS and certificates, security headers, SPF and DMARC, cookies before consent, and what your stack quietly reveals. A grade out of 100 in about fifteen seconds.

No signup. Nothing installed. We only request what your site already serves publicly.

The methodology caveats

Leak-site claims are not the same as confirmed victims. Operators routinely list victims who never actually paid, victims who were attacked months ago, and occasionally victims they didn’t actually compromise (pressure tactic). Independent corroboration through victim disclosures, regulatory filings, or news reporting confirms a fraction of the claims.

Our leaderboard counts public claims, not confirmed compromises. The relative ranking is reliable; the absolute numbers should be read as upper bounds. Where we can corroborate, the conversion rate from listed-victim to confirmed-compromise sits around 75-85% across the top operators.

Sectoral patterns

Three sectoral observations from Q1. Manufacturing remains the most-claimed sector across operators, high downtime cost, often weak internal IT, frequently pays. Healthcare claims are up year-over-year, reflecting both genuine increased targeting and increased visibility from regulatory disclosure requirements. Education claims are stable but the per-incident impact is severe given the population’s vulnerability.

What to expect in Q2

Three predictions, each with the standard “we are tracking, not forecasting” disclaimer. The mid-tier will continue to fragment. RansomHub will retain top spot but with declining share. At least one current top-five operator will quietly stop claiming new victims by mid-quarter, either through internal collapse, takedown, or affiliate migration.

The structural story is clear: the era of one dominant operator is over for now, and the diffuse landscape is harder to defend against not because any individual operator is more capable but because there are more of them, faster.

The Ransomnews Monthly

One email a month. Original leak-site data, victim census updates, and the findings that did not make the articles. No spam, unsubscribe any time.

Double opt-in. We store your email, signup time, and IP for consent records (GDPR Art. 7). See our privacy policy.

Share. Facebook Twitter Pinterest LinkedIn Tumblr Telegram Email Copy Link
Previous ArticleWhy hospital ransomware attacks keep getting worse
Next Article Why double extortion isn’t enough anymore: the rise of triple and quadruple extortion
Ransomnews Research Team

The Ransomnews Research Team is the collective byline used for collaborative pieces, editorial briefings, and articles drawing on contributions from multiple researchers. Coverage spans ransomware operations, breach economics, threat actor profiling, OSINT methodology, and emerging risks across security, privacy, and AI.

Related Posts

Interlock: the drive-by ransomware crew CISA flagged

July 20, 2026

SafePay: the centralised crew that skipped affiliates

July 20, 2026

INC Ransom: the RaaS that wins by mastering the basics

July 20, 2026

Comments are closed.

// The Ransomnews Monthly

What leaked, what held up

One email a month: the datasets we verified, and the ones that fell apart under scrutiny.

Double opt-in. We store your email, signup time, and IP for consent records (GDPR Art. 7). See our privacy policy.

// Free tool

How does your own site score?

Forty passive checks on TLS, security headers, email spoofing and privacy. A grade out of 100 in about fifteen seconds.

No signup. Nothing installed. We only request what your site already serves publicly.

// Free tool

Were you in a leak?

Check whether an email address has surfaced in infostealer logs. No signup, no data stored.

Run StealerCheck

// Live data

Ransomtracker

Victims as they are posted to ransomware leak sites, tracked continuously and checked against the claims.

Open the tracker

9,520 confirmed attacks tracked

Facebook X (Twitter) LinkedIn
© 2026 Ransomnews.com

Type above and press Enter to search. Press Esc to cancel.

Cookies on Ransomnews

We use strictly-necessary cookies to run the site and may use first-party analytics to understand which articles are read. Some pages contain affiliate links — when you click one, the affiliate network sets cookies on the merchant's domain to attribute the referral. See the Cookie Policy and Affiliate Disclosure for detail.

RANSOMNEWS.COM

Tracking the criminal infrastructure of the internet.

Independent coverage of ransomware, breach economics, threat actors, privacy, AI security, and the open-source investigation toolkit.

// Topics

  • News
  • Security
  • Privacy
  • Cybercrime
  • AI
  • OSINT
  • Threat Groups
  • Stealer Logs
  • Ransomtracker
  • Stealercheck
  • FortiBleed Checker
  • Site Check

// Site

  • About Us
  • Editorial Team
  • Contact
  • Tip Line
  • Editorial

// Legal

  • Privacy Policy
  • Terms of Service
  • Cookie Policy
  • Funding & Independence
  • RSS Feed
© 2026 Ransomnews.com · Tracking the criminal infrastructure of the internet.