Briefing

  • According to a new report released by security firm BlackFog, global enterprises are concealing the vast majority of ransomware attacks.
  • The report, released on Wednesday, shows that in the first quarter of 2026, the number of undisclosed attacks was nearly 10 times that of publicly disclosed attacks.
  • BlackFog's report is based on information from dark web leak sites and also includes data on the most targeted industries and emerging tools in the cybercrime ecosystem.

In-depth Analysis

BlackFog's threat intelligence team identified 264 publicly disclosed ransomware attacks in the first three months of 2026, but also identified 2,160 undisclosed attacks. While the number of publicly disclosed attacks fell 15% year-over-year, the number of undisclosed attacks rose slightly compared to the first quarter of 2025.

The United States is the primary target of hackers, with American organizations accounting for half of all undisclosed attacks (1,070) and 61% of publicly disclosed attacks.

The Qilin ransomware gang was the most active group in both categories, accounting for 16% of undisclosed attacks and 8% of publicly disclosed attacks. However, the second and third most active groups differed between the two categories. A relatively new group called "The Gentlemen" ranked second in undisclosed attacks, followed by Akira; while in publicly disclosed attacks, ShinyHunters ranked second, followed by INC.

In undisclosed attacks, manufacturing was the most frequently targeted industry, accounting for more than one-fifth of such incidents; while in publicly disclosed attacks, the healthcare industry was the most frequently targeted, accounting for 27%. In publicly disclosed attacks, government organizations (12%) and IT companies (11%) were the next most frequently targeted.

BlackFog stated that nearly all (96%) publicly disclosed attacks involved data exfiltration, highlighting attackers' focus on data theft as a source of leverage and profit.

"While the decline in the total number of attacks may suggest some incremental progress," wrote BlackFog's researchers, "the ongoing volume of incidents, high data exfiltration rates, and the large number of unattributed activities indicate that ransomware continues to evolve and poses a significant risk to organizations worldwide."

The report noted that in the first quarter of this year, hackers increasingly favored "more accessible and scalable tools that reduce complexity and shorten the time from intrusion to impact."

One popular tool is the Venom Stealer information-stealing program, distributed by hackers through the ClickFix infection technique, which BlackFog says "turns social engineering into a persistent data exfiltration pipeline." Researchers also discovered a new command-and-control framework called Lotus C2, which provides ready-made infrastructure for managing malware and maintaining access to victim networks. "Its modular design and ease of use lower the entry barrier for less technically capable actors, enabling a broader range of attackers to adopt advanced attack capabilities," BlackFog said.

One of the most concerning new attack surfaces is shadow AI, which has proliferated as employees rush to adopt new AI tools without the necessary permissions or security measures. According to BlackFog's previous research, 49% of employees use AI programs not approved by their companies, 51% connect AI tools to other platforms without approval, and 58% use free AI tools lacking enterprise security protections. Sixty percent of respondents also said that the speed advantage brought by AI is worth the security risk.