EEP || Cybersecurity Investing Trendjacking (7d) v2

Ransomware Threat Landscape Escalates

Ransomware Threat Landscape Escalates

Key Questions

How much did ransomware attacks increase in the first half of 2026?

Ransomware attacks rose 20% in H1 2026, reaching a total of 5,275 incidents according to NordStellar data.

What is now the leading initial access method for ransomware?

Identity compromise has overtaken vulnerabilities as the top entry vector, based on Sophos findings.

Which new ransomware groups are using Rust for faster encryption?

New groups like Spirals are employing Rust and fast encryption techniques, with one attack on an Asian IT firm completing in 24 hours using tools like Chisel and Cloudflare Tunnel.

How are Qilin and The Gentlemen competing in the ransomware space?

Qilin and The Gentlemen rivalry drove 583 Q2 attacks, with The Gentlemen impacting over 200 victims in critical infrastructure through double extortion and specific CVEs.

What landmark event marked the first fully automated AI ransomware attack?

The first fully automated AI ransomware attack was documented with JadePuffer, where AI agents autonomously chained vulnerabilities.

Which high-profile companies were hit by ransomware recently?

Coca-Cola fairlife halted U.S. production after a ransomware attack, and Deutsche Bank suffered a third-party breach via Unsafe ransomware, as noted in SEC filings.

Why did MFA fail in most ransomware breaches?

MFA failed in 97% of ransomware breaches due to coverage gaps rather than technology failure, per Sophos data, underscoring identity as the critical perimeter.

What new cloud ransomware recovery pathways were identified?

Analysis maps four attack pathways including sync clients, credential compromise, IaaS attacks, and cross-environment spread, challenging assumptions that cloud data is safe from ransomware.

Ransomware activity remains elevated, with July attacks reportedly doubling year over year and 73% of victims concentrated in the mid-market. Medusa has surpassed 500 victims, Clop's PTC Windchill campaign affected 40+ organizations, and recent Azure, vCenter, healthcare, logistics, and water-utility incidents reinforce identity compromise, cloud control-plane hijacking, and OT response gaps as the main investment and CISO themes. The ATF/Qilin case offers a positive segmentation lesson, but the broader trend remains intensifying.

Sources (5)
Updated Sep 1, 2026