A New Ransomware Leaderboard for Q2 2026

Ransomware hasn't slowed down, it's just reshuffled its cast of characters. A new report from threat intelligence firm Brandefense identifies the top five ransomware groups dominating Q2 2026: Qilin, TheGentlemen, Akira, DragonForce, and LockBit5. The analysis, built on Brandefense's own cyber threat intelligence (CTI) tracking, gives security teams and everyday users a snapshot of which groups are currently the most active, and by extension, which organizations and individuals are most likely to feel the fallout.

While the names on this list will sound familiar to anyone following ransomware news over the past few years, their persistence says something important: takedowns and law enforcement pressure rarely eliminate these operations outright. Instead, brands get rebuilt, affiliates migrate to new platforms, and the ransomware-as-a-service (RaaS) model keeps churning out fresh campaigns under old or rebranded names, LockBit5 being a clear example of a franchise that keeps resurfacing despite prior disruption efforts.

The Five Groups Behind the Numbers

Each of the five groups Brandefense tracked operates with its own affiliate network, target preferences, and negotiation style, but they share the broader playbook that has come to define modern ransomware: gain access, exfiltrate data, encrypt systems, and pressure victims into paying before information gets leaked or operations grind to a halt.

This is where the privacy implications become impossible to ignore. Ransomware today is rarely just about locked files. Groups increasingly rely on data theft as leverage, and some have pushed even further into what's known as triple extortion, layering additional pressure tactics such as contacting a victim's customers or partners directly. If you want a deeper look at how this escalation works in practice, our earlier coverage of triple extortion ransomware breaks down exactly how attackers weaponize stolen data beyond a simple ransom demand.

Not every group follows the same formula, though. Some campaigns have reverted to encryption-only approaches without a data theft component at all, a variation covered in our report on Jadepuffer's return to encryption-only ransomware. The diversity among the five leading groups in Brandefense's Q2 2026 findings reflects this same reality: there's no single ransomware template anymore, just a shared toolkit that different operators mix and match.

Why Privacy Is the Real Battleground

The common thread across nearly all top-tier ransomware operations right now is initial access. Attackers rarely need to write novel exploits when stolen credentials will do the job. Recent industry analysis has pointed to compromised logins overtaking software vulnerabilities as ransomware's preferred entry point, a shift we detailed in our coverage of Sophos's findings on compromised logins. Alongside that trend, infostealer malware has become a quiet but critical supply chain for attackers, harvesting login credentials in bulk that later surface in the exact intrusions these ransomware groups carry out. Our piece on infostealer logs overtaking phishing as the top breach cause explains how this pipeline works.

This matters for privacy because it reframes ransomware as fundamentally a credential and data protection problem, not just an endpoint security one. Every password reused across accounts, every session token left exposed on an infected device, becomes a potential foothold for groups like Qilin, Akira, or DragonForce to exploit. The victims aren't limited to large enterprises either; when ransomware groups exfiltrate data before encrypting it, personal information belonging to employees, customers, and patients often ends up part of the leverage, regardless of whether the ransom gets paid.

What This Means For You

Most readers won't be defending a corporate network against LockBit5 or TheGentlemen directly, but the downstream effects reach everyone. If a company you do business with gets hit by one of these groups, your personal data, from account credentials to financial details, could be exposed or leaked as part of the extortion process. Some victims, as seen in past incidents like Stadler Rail's refusal to pay a ransom demand, choose not to pay, which means stolen data can end up published regardless of the outcome.

The practical takeaway is that ransomware defense increasingly starts with basic credential hygiene, both for organizations and individuals. Unique, strong passwords, multi-factor authentication, and vigilance around infostealer malware (often delivered through pirated software or malicious downloads) reduce the odds of becoming an entry point for these groups.

Actionable Takeaways

  • Assume any account reused across multiple services is a liability; ransomware crews increasingly buy or harvest credentials rather than hack their way in.
  • Enable multi-factor authentication everywhere it's offered, since compromised logins remain the leading entry point for these attacks.
  • Watch for breach notifications from any organization you interact with, and treat them seriously given how often stolen data becomes part of a ransomware negotiation.
  • Stay informed on which ransomware groups are currently active, since knowing the landscape helps organizations and individuals alike anticipate risk rather than react to it after the fact.

The Q2 2026 ransomware landscape, as mapped by Brandefense, confirms that this threat isn't going away, it's evolving. Staying ahead of it means paying attention to how these groups operate, not just their names.