Ransomware Victims Keep Climbing, and the Pace Is Quickening
Ransomware isn't slowing down. According to new figures reported by The National CIO Review, 7,551 publicly disclosed ransomware victims were recorded between April 2025 and March 2026, a 24.9% jump from the year before. That alone would be notable, but the more telling detail is where the growth happened: the increase wasn't spread evenly across the year. It was concentrated in the second half, when the monthly average of victims nearly doubled, rising from 484 to 775.
That kind of acceleration matters more than the annual total. A steady climb suggests a persistent problem organizations are gradually adapting to. A sharp mid-year spike suggests something changed, whether that's more ransomware groups entering the field, existing groups scaling up operations, or victims simply being outed publicly at a faster clip as extortion tactics evolve.
Why the Second-Half Spike Is the Real Story
Modern ransomware operations increasingly rely on "double extortion," where attackers not only encrypt a victim's systems but also steal data and threaten to leak it publicly if a ransom isn't paid. That threat of exposure is often what lands an organization on a public list of victims in the first place, since ransomware gangs frequently maintain leak sites specifically to pressure targets into paying.
This dynamic has played out repeatedly across sectors. Construction and engineering firms, government bodies, airlines, and retailers have all found themselves named on ransomware leak sites after attackers claimed to have exfiltrated sensitive data. For example, the Play ransomware group's claimed attack on Kreysler & Associates followed this exact playbook: a leak threat used as leverage, with the victim named publicly before any ransom demand was resolved. Similarly, a single ransomware operation was linked to breaches at South Africa's ANC, SAA, and Pick n Pay, showing how one group can rack up a wide range of high-profile victims across unrelated industries in a short span.
The growing number of active ransomware groups referenced in the National CIO Review's reporting fits this pattern. More groups operating simultaneously means more leak sites, more claimed victims, and more pressure campaigns running in parallel, which helps explain why the monthly victim count nearly doubled rather than climbing gradually.
The Privacy Fallout for Everyday Users
While ransomware headlines tend to focus on the organizations that get hit, the privacy consequences trickle down to the people whose data those organizations hold. When a ransomware group steals data before encrypting a network, that stolen data often includes customer records, employee information, financial details, or health data, depending on the victim's industry. Even if a company refuses to pay and restores from backups, the stolen data can still end up published or sold if the attackers follow through on their leak threats.
This is why rising victim counts aren't just a corporate IT problem. Every new name added to a leak site potentially represents thousands of individuals whose personal information is now at risk of exposure, identity theft, or targeted phishing. The scale documented in this report, with victim counts climbing from an average of 484 to 775 per month, translates into a meaningfully larger pool of people who may need to worry about their data circulating outside their control.
What This Means For You
You don't need to run a corporate network to be affected by this trend. If you're a customer, employee, or patient of any organization, your data could be swept up in a breach you had no part in causing. A few practical steps can reduce your exposure:
- Assume any account tied to an organization you interact with could eventually be part of a breach, and use unique passwords for every service so one leak doesn't cascade into others.
- Enable multi-factor authentication wherever it's offered, since stolen credentials are far less useful to attackers if a second verification step is required.
- Monitor for notification emails from companies you do business with, and take breach notices seriously rather than dismissing them as routine.
- Consider a credit freeze or fraud alert if you're notified that your data was involved in a ransomware incident, particularly if financial or identity information was included.
The Bottom Line
The rise in publicly disclosed ransomware victims, and especially the sharp acceleration in the back half of the reporting period, signals that extortion-based cybercrime is becoming more organized and more frequent rather than plateauing. For organizations, that means renewed pressure to shore up defenses and incident response plans. For individuals, it's a reminder that data protection is no longer just a corporate responsibility; it's a shared one. Staying informed about which sectors are being targeted and practicing basic account hygiene remains one of the most effective ways to limit personal fallout when the next batch of ransomware victims makes headlines.




