Ransomware intelligence
Ransomware Groups in 2026
Who the active crews are, their latest claimed victims, the regions and sectors they hit, and how to defend — with victim counts tracked live in our threat-intelligence graph.
Track it daily
Ransomware moves every day. So does our paper.
The Probably Fine Daily is our morning threat-intelligence briefing — new victims, new groups, what actually matters, in plain English. Free.
Read today's Daily →Browse the archiveThe groups — ranked by victims we track
Counts are cumulative claimed victims aggregated across each group's aliases in the Ninja Signal graph. Click any group for its full dossier — latest victims, regions, sectors, suspected origin and affiliates. “Sanctioned” means paying may be illegal.
How do ransomware groups operate?
Ransomware-as-a-Service. A core team builds and maintains the malware, the negotiation portal and the leak site; affiliates do the breaking-in and keep most of any ransom. That is why taking down a brand rarely stops the people — affiliates simply move to the next crew, which is what our lineage links show.
How they get in. Stolen or weak credentials on remote access (VPN/RDP) without MFA; phishing; exploitation of unpatched internet-facing software; and access bought from initial-access brokers.
Double & triple extortion. Modern crews steal data before encrypting, so backups restore systems but don't remove the threat to leak. Triple extortion adds DDoS or direct pressure on your customers and regulators.
Is it legal to pay a ransom?
It can be illegal. Paying a sanctioned group — as LockBit and the Conti/Trickbot operators are (OFAC and the UK) — can breach sanctions law regardless of intent. Paying also funds the next attack and never guarantees recovery. Involve law enforcement and legal counsel, and check sanctions status, before payment is discussed.
How do you defend against ransomware?
- Offline, tested backups (3-2-1).
- Phishing-resistant MFA on every remote entry point.
- Patch known-exploited vulnerabilities fast.
- EDR everywhere, monitored 24/7.
- Segment the network and enforce least privilege.
- Rehearse the incident-response plan.
Frequently asked questions
Who is the biggest ransomware group?
By cumulative tracked victims, LockBit is still the largest despite Operation Cronos in 2024. RansomHub, Play and Qilin lead the current generation.
Is it illegal to pay a ransom?
It can be — paying a sanctioned group (LockBit, Conti/Trickbot operators) may breach OFAC/UK sanctions law. Check status and involve law enforcement first.
What is double and triple extortion?
Double extortion = steal data before encrypting, then threaten to leak it. Triple extortion adds DDoS or contacting your customers, partners and regulators.
Do takedowns work?
They disrupt — Op Cronos (LockBit) and the ALPHV collapse hurt those brands and produced indictments and sanctions — but affiliates and operators rebrand, so the ecosystem persists.
Track it daily
Ransomware moves every day. So does our paper.
The Probably Fine Daily is our morning threat-intelligence briefing — new victims, new groups, what actually matters, in plain English. Free.
Read today's Daily →Browse the archiveFor defenders and the curious. Victim figures are groups' own public leak-site claims, aggregated and tracked — not independently verified. Attribution reflects open-source consensus.