FR
live

Ransomware Surges 48% in May 2026 as Global Attacks Decline

Check Point Research records 698 ransomware attacks worldwide in May 2026, a 48% year-over-year jump, even as overall attack volumes drop 7%. Fewer attacks, more impact — threat actors are getting better at doing more with less.

Le ransomware explose de 48 % en mai 2026 alors que les attaques globales reculent — ETTAYEB illustration

April 2026. Global cyber-attacks rebound after a heavy first quarter. May 2026. They drop 7% month over month to 2,055 weekly attacks per organization. On the surface, things are settling down.

May 2025. 472 ransomware incidents are reported worldwide. May 2026. 698. That’s a 48% surge — the steepest year-over-year acceleration recorded so far in 2026.

Check Point Research’s June 2026 threat report delivers a finding every CISO should sit up and notice: raw attack volume no longer tells the story. What matters is what’s still hitting, and hitting hard.

The May 2026 paradox: fewer attacks, more ransom

At first glance, the numbers look reassuring. 2,055 weekly attacks per organization globally is down 7% from April. Year-over-year growth is capped at a modest 2%. A quick scan could pass for stabilization.

It’s the wrong read.

Underneath the aggregate dip, ransomware is accelerating at a pace Check Point Research describes as its “sharpest year-over-year jump of 2026.” 698 publicly reported incidents, up from 472 the year before. Growth lands across every region: Asia +119%, EMEA +40%, Americas +39%. This is not a regional flare-up. It’s distributed acceleration.

The paradox boils down to one sentence: attackers are extracting more value from fewer operations. The model has shifted from carpet-bombing to surgical strikes, calibrated for maximum financial impact and maximum pressure on the victim.

Business Services: the sector that went +359% in a year

The sector breakdown from Check Point’s report lays out the change in ransomware doctrine with brutal clarity.

Business Services accounted for 35% of all ransomware victims in May 2026. The raw number is even more staggering: 248 incidents reported, up from 54 in May 2025 — a 359% increase in twelve months. Consulting firms, legal services, payroll processors, IT providers — they’ve become the ideal pressure point. One compromise can unlock access to dozens of downstream clients.

Consumer Goods and Services followed the same trajectory with a 223% year-over-year spike. Industrial Manufacturing rose 50%, consistent with the wave of supply-chain incidents documented since 2024.

In terms of total attack volume — not just ransomware — Education holds the unwanted top spot: 4,641 weekly attacks per organization, up 7% year over year. Open networks, constant student turnover, chronically underfunded security teams: the formula has been known for years and nothing has changed. Government follows at 2,620 weekly attacks; Telecommunications at 2,583.

The real surprises sit further down the list. Agriculture surged 51% year over year to 2,243 weekly attacks. Hospitality, Travel and Recreation jumped 24%; Construction and Engineering rose 23%. None of these sectors would have been flagged as prime targets two years ago. The accelerating digitization of their operations, paired with the widespread availability of automated attack tooling, is rewriting that risk calculation in real time.

Three groups dominate, 61 are active

The ransomware market has become a full-fledged economy. In May 2026, 61 distinct groups were simultaneously active. The top three accounted for 39% of published attacks; the remaining 58 groups split the other 61%, a level of fragmentation that reflects just how industrialized and competitive the sector has become.

Qilin led the pack at 14% of claimed attacks. The group continues the expansion it began after RansomHub’s dismantling, powered by an aggressive affiliate recruitment drive running since early 2025. Its dominant position in May 2026 confirms sustained momentum.

The Gentlemen took second place at 10% — a striking position for a group with zero recorded activity in May 2025. Founded in mid-2025 by a former Qilin affiliate, the group built its early reach on self-service access to approximately 14,000 pre-exploited FortiGate appliances. In under a year, it became one of the most serious threats in the ecosystem. Internal communications from May 2026 reveal a tactical pivot: moving away from brute-force EDR-killing toward surgical userland evasion — a clear signal the group is investing in operational longevity.

DragonForce rounds out the podium at 8%. The group climbed five spots since January 2026 by absorbing displaced RansomHub affiliates and running a white-label model that lets each affiliate operate under their own brand on shared infrastructure.

The concentration at the top shouldn’t obscure the bigger picture: ransomware is a deeply competitive ecosystem where the barrier to entry drops as Ransomware-as-a-Service platforms multiply. An emerging group can go from zero to double-digit market share in under twelve months.

United States: 43% of global victims, alone

The geographic distribution is just as concentrated. North America absorbs 49% of reported ransomware incidents, followed by Europe at 22% and APAC at 19%.

The United States alone accounts for 43% of all global victims. Canada follows at 5.6%, the United Kingdom at 4.6%, Germany at 4.0%, and Spain at 3.0%.

This imbalance isn’t new, but it’s deepening: the concentration of headquarters, sensitive data, and payout capacity — both ransom and cyber insurance — makes North American targets the most predictable return on investment for operators.

Encryption is fading, extortion is rising

Check Point’s May 2026 report fits into a broader trend documented since its State of Ransomware Q1 2026: pure data encryption is no longer the primary weapon. Modern ransomware groups increasingly rely on data theft followed by encryption-free extortion, a technique that reduces operational noise while maintaining pressure on the victim.

The logic is straightforward. Encryption triggers immediate incident response procedures, mobilizes insurers, draws in regulators. Silent data exfiltration, by contrast, can go undetected for weeks. The threat of publishing on a data leak site is often enough to force negotiation — no locker deployment required.

This evolution makes traditional metrics — attack volume, number of encrypted machines — increasingly irrelevant for measuring actual risk. What matters now is mean dwell time before detection. And on that front, the numbers are still bad.

GenAI: 1 in 25 prompts expose sensitive data

Check Point’s report also devotes a section to enterprise GenAI risk, and the numbers deserve attention. In May 2026:

  • 1 in every 25 GenAI prompts from enterprise networks carried a high risk of sensitive data leakage.
  • 91% of organizations using GenAI tools were exposed to this risk.
  • 22% of prompts contained potentially sensitive information.
  • The average enterprise user submitted 70 prompts per month, across an average of 9 different GenAI tools.

Every tool adopted without a governance framework is another surface through which credentials, intellectual property, or internal data can escape silently. Exfiltration doesn’t announce itself.

Verdict

Check Point Research’s May 2026 report is a wake-up call dressed as a statistical paradox. Overall attacks are down. Ransomware is exploding. The lesson is blunt: measuring threat by attack volume means looking at the wrong metric.

Organizations need to adjust their posture along three axes:

  • Detect lateral movement and exfiltration, not just encryption. If modern ransomware no longer needs to encrypt to cause damage, defenses built around locker detection are structurally behind.
  • Immediate GenAI governance. A DLP policy and mandatory usage framework — not in six months. Check Point’s numbers show the risk is already materialized inside enterprise networks.
  • Supply chain resilience. The 359% spike in Business Services means an unprotected vendor is now the most likely vector for a major compromise. The annual security questionnaire isn’t enough anymore: you need continuous monitoring.

The threat landscape isn’t pausing. It’s reorganizing faster than defenses can adapt. May 2026 will be remembered as the month the curves diverged for good.

References

The cyber brief, every Tuesday

The flaws that matter and the patches to apply, in a ten-minute read.

No spam. One-click unsubscribe.
read next

On the same topic

API attacks became the number one data breach vector in 2026

99% of organizations experienced an API security incident in 2025. APIs now account for 43% of actively exploited vulnerabilities in CISA’s KEV catalog. Your API gateway is your new firewall — and you probably haven’t configured it.

← Back to the feed

Type at least two characters.

navigate open esc dismiss