White Paper
Ransomware 2026: New Actors and Threats Emerge as the Threat Landscape Evolves
Ransomware activity reached record highs in 2025, with 4,737 attacks and a broader 23% increase in extortion incidents when including data-theft-only attacks. Despite disruptions to major groups like LockBit and RansomHub, affiliates quickly migrated to other operations, sustaining overall activity. A key shift is the rise of “encryptionless extortion,” where attackers steal data and demand payment without deploying ransomware, signaling an evolution in tactics. New threats like Warlock show links to espionage activity and highlight blurred lines between cybercrime and state-backed operations. Attackers increasingly use legitimate tools (“living off the land”) and social engineering to evade detection. Overall, ransomware remains resilient, but tactics are evolving toward more flexible, scalable, and covert forms of extortion.
