Frontline Insights - Ransomware Q2 2026 Report

 

Frontline Insights - Ransomware Q2 2026 Report Excerpt:

Our latest Frontline Insights | Ransomware Q2 2026 Report, produced by the NSB Cyber Intelligence Centre, recorded 2,074 global ransomware claims in Q2, 44.6% above the same quarter of 2025 and 6.6% below Q1. Our assessment is that the annual rise, not the slight quarterly dip, is the meaningful figure: activity has settled onto a structurally higher plateau rather than retreating toward the lower tempo of mid-2025.

The sharper story this quarter is what the counts no longer capture. Extortion is decoupling from encryption. Legal Services nearly doubled to 98 claims and Real Estate entered the top twelve for the first time, yet much of the quarter's most damaging activity came from groups that steal data and deploy no encryptor at all, running through social engineering and stolen credentials that leave no leak-site trace. Identity compromise, not malware, is now the dominant way in, and a group that locks nothing can still inflict a sector's heaviest harm.

Oceania moved the opposite way to the world, rising 23.8% to 52 claims, overwhelmingly Australian and led by Qilin. Our full report sets out what this means for Australian organisations, and why defending data, identity and third-party access now matters more than defending against encryption alone.

This document will cover:

  • Overview

  • Ransomware Operations Q2 2026

  • Targeted Sectors

    • Manufacturing & Industrial Products

    • Professional Services

    • Engineering & Construction

    • Consumer & Retail

    • Healthcare & Life Sciences

    • Technology

    • Legal Services

    • Government & Public Sector

    • Education

    • Financial Services

    • Transport & Logistics

    • Real Estate

  • Closing Remark

Authors:

  • Evan Vougdis - Head of Cyber Intelligence and Response of NSB Cyber

  • Dimitri Dubuc - Cyber Associate of NSB Cyber

 
 
 
Next
Next

Frontline Insights - Ransomware Q1 2026 Report