Rankiteo Logo
Rankiteo
Leader in Cyber Underwriting
Loading...

The Rankiteo MCP server is now available.

Discover MCP
🔐

Ransomware Tracker & Statistics

Real-time analytics on 19,615 ransomware incidents tracked by Rankiteo. Explore ransomware strains, affected industries, threat actors, and severity trends shaping the global threat landscape.

19,615
Ransomware Incidents
30
Known Strains
23.5K
Companies Affected
79.9
Avg Severity

Ransomware Strains

Unknown

High
17924 incidents91.4%Avg sev: 78.3

Qilin

Critical
160 incidents0.8%Avg sev: 98.4

Cl0p

Critical
115 incidents0.6%Avg sev: 93.8

LockBit

Critical
113 incidents0.6%Avg sev: 96.5

Akira

Critical
87 incidents0.4%Avg sev: 97.9

ALPHV/BlackCat

Critical
81 incidents0.4%Avg sev: 97.2

Medusa

Critical
56 incidents0.3%Avg sev: 97.2

Rhysida

Critical
47 incidents0.2%Avg sev: 95.5

Everest

Critical
43 incidents0.2%Avg sev: 98

Conti

Critical
40 incidents0.2%Avg sev: 97.6

INC Ransom

Critical
40 incidents0.2%Avg sev: 98.1

REvil/Sodinokibi

Critical
27 incidents0.1%Avg sev: 93.3

Ransomware Incidents Over Time

09
10
11
12
01
02
03
04
05
06
07
08
09
10
11
12
01
02
03
04
05
06
07
08
09
10
11
12
01
02
03
04
05
06
07
08

Most Targeted Industries

Hospitals and Health Care
1597
Financial Services
910
Software Development
768
Government Administration
747
['Software Development']
605
IT Services and IT Consulting
524
Insurance
465
Higher Education
432
Retail
372
['Hospitals and Health Care']
364
Banking
340
['Computer and Network Security']
325

Threat Actors

Qilin167
ShinyHunters167
Insider149
Cl0p128
Hacker107
LockBit103
Cybercriminal85
Akira79
ALPHV/BlackCat69
Scattered Spider53
INC Ransom51
Rhysida46
Everest45
Play42
Medusa38
Anonymous38

Recent Ransomware Incidents

IncidentSeverityStrainIndustryDate
UnitedHealth, Ticketmaster, MGM Resorts, Ripple, Snowflake, Google, Allianz, Equifax, Maersk, Toyota, Merck and Oracle: 2025 Cybersecurity Almanac: 100 Facts, Figures, Predictions And Statistics100 (Critical)Akira['Hospitality', 'Pharmaceutical Manufacturing', 'Technology, Information and Internet', 'Financial Services', 'Software Development', 'Entertainment Providers', 'IT Services and IT Consulting', 'Motor Vehicle Manufacturing', 'Hospitals and Health Care', 'Transportation, Logistics, Supply Chain and Storage']2025-12-11 00:00:00
Hong Kong precision components supplier and Italian maritime port authority: Ransomware Groups Surge In Q4 2025 – Cyble Insights100 (Critical)Qilin['International Trade and Development', 'Computer and Network Security']2026-01-01 00:00:00
Tencent, MySpace, Twitter, Weibo, Canva, Adobe, Deezer, AdultFriendFinder, U.S. Government and Brazil Government: The 12-Terabyte Ghost: How a Record-Shattering Data Leak Is Arming a New Generation of Cyberattacks100 (Critical)Unknown['Software Development', 'Technology, Information and Internet', 'Government Administration', 'Entertainment Providers', 'Musicians']2025-01-01 00:00:00
Foreign Office and UK Government: Russian hackers infiltrate UK government emails in cyberattack targeting Foreign Office officials100 (Critical)Unknown['Government Relations Services', 'Government Administration']2026-07-05 00:00:00
Verizon, McDonald’s, AT&T, Vodafone, Australian energy utility, Shell, VMware, Citrix, GitHub and Cursor IDE: Weekly Cyber Security Newsletter Bulletin – Entra ID RCE, Claude Code Ransomware, T-Mobile Cable, Azure Credential Theft +20 Stories100 (Critical)Medusa['Restaurants', 'Utilities', 'Oil and Gas', 'Telecommunications', 'IT Services and IT Consulting', 'Software Development']2026-08-20 00:00:00
SolarWinds, Kaseya, MoveIt Transfer, PowerSchool, DaVita, NASCAR, Marks & Spencer, Caesars Entertainment and Change Healthcare: Ransomware trends, statistics and facts in 2026100 (Critical)Cl0p['Hospitality', 'Consumer Services', 'Spectator Sports', 'E-Learning Providers', 'Retail', 'Software Development', 'Information Technology & Services', 'Hospitals and Health Care']2024-12-25 00:00:00
Udemy, McGraw-Hill, Vercel and Harvard University: Udemy Data Breach – ShinyHunters Allegedly Claims Compromise of 1.4M User Records100 (Critical)Unknown['Higher Education', 'E-Learning Providers', 'Software Development', 'Education Administration Programs']2026-04-24 00:00:00
Check Point: CISA Warns of Check Point Authentication Vulnerability Exploited in Attacks100 (Critical)Unknown['Computer and Network Security']2026-07-22 00:00:00
Broadcom100 (Critical)Cl0pSemiconductor Manufacturing2025-06-16 00:00:00
Shoppers Drug Mart, President’s Choice, Loblaw, No Frills and PC Optimum: “Threat Actor” on the dark web claims Loblaw’s “low-level” data breach is a much larger threat100 (Critical)Unknown['Financial Services', 'Retail', 'Retail Groceries']2026-03-13 00:00:00
Aquasecurity: CISA Adds Aquasecurity Trivy Scanner Vulnerability to KEV Catalog100 (Critical)Unknown['Computer and Network Security']2026-03-28 00:00:00
Kawasaki Motors Europe, Volkswagen, Toyota, Avis Rent a Car, Jaguar Land Rover, Nissan and Scania: Major Cyber Attacks Targeting the Automotive Industry 2025100 (Critical)RansomHub['Industrial Machinery Manufacturing', 'Financial Services', 'Motor Vehicle Manufacturing']2025-11-07 00:00:00
Heathrow Airport, Copenhagen Airport and Charles de Gaulle Airport: Major cyberattack on aviation IT systems snarls flights across Europe and hits Prague connections100 (Critical)Unknown['Airlines and Aviation']2026-04-07 00:00:00
openSUSE, CentOS, AlmaLinux, Ubuntu and Fedora: Dirty Frag Linux Vulnerability Let Attackers Gain Root Privileges – PoC Released100 (Critical)Unknown['Software Development', 'IT Services and IT Consulting']2026-05-07 00:00:00
LiteLLM: LiteLLM RCE Vulnerability Exploited in the Wild to Run Commands100 (Critical)Unknown['Software Development']2026-06-01 00:00:00
Capcom, Coinbase, Hertz, Conduent, Insight Partners, Pinellas County, Arapahoe County and Lincoln Parish: U.S. Government & Enterprise100 (Critical)LockBit['Market Research', 'Computer Games', 'Travel Arrangements', 'Financial Services', 'Business Consulting and Services', 'Investment Banking', 'Government Administration']2024-01-01 00:00:00
Linksys, Hikvision, Cisco, Ubiquiti, Draytek, Fortinet, Araknis and Mimosa Networks: China-Linked JDY Botnet Uses 1,500+ SOHO and IoT Devices for Rapid Vulnerability Exploitation100 (Critical)Unknown['Software Development', 'Computer Networking Products', 'Telecommunications', 'Engineering Services', 'Technology, Information and Internet', 'IT Services and IT Consulting', 'Computer and Network Security']2024-01-01 00:00:00
Fortinet, Foxconn, Comcast, Chevron, Samsung, AT&T, Mercedes-Benz and Toyota: FortiBleed leak exposes Fortinet VPN credentials for 73,000 devices.100 (Critical)Unknown['Oil and Gas', 'Computers and Electronics Manufacturing', 'Appliances, Electrical, and Electronics Manufacturing', 'Telecommunications', 'Computer and Network Security', 'Motor Vehicle Manufacturing']2026-05-01 00:00:00
K&L Gates, Ofcom, MOVEit, Kirkland & Ellis, Proskauer Rose, PwC, Aon and Shell: Kirkland, K&L Gates and Proskauer hit by ransomware attack100 (Critical)Cl0p['Law Practice', 'Oil and Gas', 'Telecommunications', 'Professional Services', 'Financial Services']2023-07-07 07:00:00
Sophos, CrowdStrike, Microsoft, Proton Drive, SentinelOne, Bitdefender, ESET and McAfee: New Avalon Malware Framework Packs CrownX Ransomware Capabilities100 (Critical)CrownX (part of Avalon framework)['Software Development', 'Technology, Information and Internet', 'Computer and Network Security']2026-03-11 00:00:00

Ransomware Statistics & Attack Trends - 2026 Overview

Ransomware continues to be the most financially devastating form of cybercrime, with threat actors encrypting critical data and demanding multi-million-dollar payments from organizations of every size. Rankiteo tracks ransomware incidents globally in real time, cataloguing strains, targeted industries, responsible threat actors, severity scores, and data exfiltration status to give security professionals and decision-makers a comprehensive, always-current picture of the ransomware landscape.

This tracker aggregates intelligence from 19,615 monitored ransomware incidents affecting 23,490 companies worldwide. Each incident is enriched with contextual data, including the ransomware strain, industry classification, and the threat group responsible, enabling pattern analysis that goes far beyond simple incident counts.

Why Track Ransomware Statistics?

Granular ransomware data serves multiple stakeholders across the cybersecurity and risk ecosystem:

  • CISOs & Security Teams: Identify emerging strains and which industries are under active attack to fine-tune detection rules, endpoint defenses, and backup strategies.
  • Third-Party Risk Managers: Assess whether vendors and suppliers operate in industries or geographies with elevated ransomware exposure to strengthen supply chain due diligence.
  • Cyber Insurers & Underwriters: Use strain-level frequency, severity distributions, and industry concentration data to model ransomware loss scenarios and calibrate premiums and coverage limits.
  • Incident Response Teams: Study threat actor TTPs and strain behaviours documented in historical incidents to accelerate containment and recovery during an active attack.
  • Executives & Boards: Communicate the scale and velocity of the ransomware threat with concrete, real-world statistics to justify investments in resilience and response capabilities.

Understanding Ransomware Strains

Modern ransomware operates through a Ransomware-as-a-Service (RaaS) model, where the developers of a strain lease their malware to affiliate operators in exchange for a share of the ransom. This model has driven explosive growth in the number of active strains: groups like LockBit, ALPHV/BlackCat, Cl0p, Black Basta, and REvil/Sodinokibi have each claimed hundreds of victims. Rankiteo maps every tracked incident to its strain, normalising name variants (e.g., "LockBit 3.0", "Lock Bit" → "LockBit") so that analysts can accurately compare strain prevalence and lethality.

Threat Actors & Attribution

Attribution is challenging but essential. Where threat intelligence allows, each incident is linked to the responsible threat actor or affiliate group. Rankiteo consolidates aliases and variants, merging labels like "Hackers" and "Hacker", or "Insider" and "Former Employee" - into canonical categories for cleaner analysis. For a deeper ranking of the most prolific groups, see the Threat Actor Leaderboard.

Methodology & Related Resources

Rankiteo identifies ransomware incidents by continuously monitoring dark web leak sites, government CERT advisories, vendor security bulletins, breach notification filings, and curated open-source threat intelligence feeds. Each incident is automatically classified, scored for severity on a 1–10 scale, and enriched with strain, industry, and entity metadata before appearing in this tracker.

Dive deeper into the threat landscape with related Rankiteo resources:

Ransomware Tracker & Statistics 2026 | Live Attack Data | Rankiteo | Rankiteo