- NordStellar reports 2,581 ransomware attacks in Q2 2026, with Qilin (299) and The Gentlemen (284) leading activity, well ahead of DragonForce (147)
- US SMBs were hardest hit, suffering 769 incidents; Canada (97), Germany (83) and the UK (74) followed, while attacks on billion-dollar companies increased by 74%
- Experts say rivalry between Qilin and The Gentlemen drives the top, with big corporate hits seen as trophies that boost reputation in the cybercriminal underground.
Two ransomware gangs are battling for dominance, and US-based SMBs are the ones suffering the most for it, experts have claimed.
Fresh data on the state of ransomware in 2026, compiled by security experts from NordStellar, shows that two groups – Qilin and The Gentlemen – are by far the most active.
After analyzing more than 200 threat actor blogs, NordStellar concluded that there were 2,581 ransomware attacks in the second quarter of the year – and of that number, 299 belong to Qilin, the most active threat actor out there. Next in second place is The Gentlemen with 284 attacks. The third most active group – DragonForce – doesn’t even come close to “just” 147 attacks.
SMEs and companies under attack
Although it seems like a close race, it’s actually The Gentlemen who did the heavy lifting between April and June 2026. This group saw a 39% increase in attacks, while Qilin’s activity actually decreased somewhat compared to Q1.
In this morbid race to the bottom, the biggest victims are US-based small and medium-sized businesses (SMBs). These companies, with up to 200 employees and revenue below $25 million, experienced 769 attacks in Q2 2026, followed by Canada (97), Germany (83) and the United Kingdom (74).
NordStellar also mentioned American companies, which are now increasingly being targeted. Attacks against organizations with revenues north of $1 billion increased by 74%, from 23 incidents in Q1 to 40 in Q2.
“Ransomware actors historically target SMBs because these organizations often lack comprehensive defenses, which can increase the likelihood of a successful attack,” commented Vakaris Noreika, cyber security expert at NordStellar.
“This recent increase in corporate targeting is unusual and may be a temporary fluctuation. This shift likely stems from the rivalry between dominant threat actors – a successful hit on a major company is a badge of honor that boosts a group’s reputation in the cybercriminal underground.”
The best antivirus for all budgets
Follow TechRadar on Google News and add us as a preferred source to get our expert news, reviews and opinions in your feeds.



