A Record Number of Ransomware Groups, But Victim Counts Aren't Rising

Ransomware activity reached a new milestone this quarter, not because attacks slowed down, but because the field of attackers got more crowded. Data leak sites tracked 93 active ransomware crews during the period, a record high, according to new figures reported by ITBrief. Yet despite this surge in operators, the total number of victims stayed largely flat compared to the previous quarter.

That might sound like good news at first glance. It isn't, at least not in the way it appears. Data leak sites recorded 2,139 ransomware victims for the quarter, essentially unchanged from the prior three months but still 33% higher than the same period a year earlier. In other words, the ransomware ecosystem hasn't cooled off. It has simply spread out across more groups, each claiming a smaller slice of a still-growing pie.

Why More Groups Doesn't Mean Less Risk

The record number of active ransomware operations points to a meaningful shift in how the criminal ecosystem is structured. For years, a handful of dominant ransomware brands controlled most of the attack volume. When law enforcement disrupted one of those major operations, victim counts would often dip noticeably before rebounding.

That pattern appears to be breaking down. With 93 groups now competing for targets, the ransomware economy looks less like a small number of criminal monopolies and more like a fragmented marketplace. Smaller, newer, or rebranded groups can absorb the attack volume that larger operations used to generate on their own. This makes the overall threat more resilient. Taking down one or two prominent groups no longer meaningfully dents total attack activity, because dozens of others are ready to fill the gap.

This fragmentation also has practical consequences for defenders and privacy-conscious organizations alike. More groups mean more variation in tactics, tooling, and ransom negotiation behavior, which makes it harder to build a single defensive playbook. Some crews rely on well-worn phishing and remote access exploitation, while others move quickly to exploit newly disclosed vulnerabilities in enterprise software. A recent example is Storm-1175's exploitation of an N-central flaw to deploy StormEncryptor, which shows how quickly a single unpatched vulnerability in widely used IT management software can become the entry point for a full-blown ransomware incident.

The Privacy Fallout of a Flat-But-Steady Attack Rate

When ransomware victim counts stay flat, it's tempting to read that as stabilization. But flat numbers built on a 33% year-over-year increase and a record number of active groups tell a different story: the baseline of risk has simply moved higher and settled there.

Every ransomware incident carries a data exposure component that goes beyond locked files. Most modern ransomware operations pair encryption with data theft, publishing stolen records on leak sites when victims refuse to pay. That means personal information, financial records, health data, and internal communications are increasingly at risk of public exposure, not just operational downtime. With more groups running independent leak sites and negotiation infrastructure, tracking where compromised data ends up becomes harder for both victims and researchers.

For consumers, this fragmentation matters because it multiplies the paths through which their personal data can end up exposed. A breach at a healthcare provider, a school district, or a small business vendor can just as easily result in a public data dump as a breach at a large enterprise. The record number of active groups suggests attackers are increasingly willing to target smaller or mid-sized organizations that may have weaker security budgets but still hold sensitive personal data.

What This Means For You

If you're an individual, the practical risk hasn't changed dramatically, but the odds that some organization holding your data will be hit by ransomware have quietly increased. If you run a business, especially a small or mid-sized one, the record number of active groups means you can no longer assume you're too small to be a target. Attackers are diversifying, and that diversification is filling in the gaps that used to protect smaller organizations from serious ransomware crews.

The key takeaway is that the ransomware threat isn't defined by a handful of infamous group names anymore. It's a broad, fragmented ecosystem where dozens of operators are actively hunting for vulnerable entry points, from unpatched software to exposed remote access tools.

Actionable Takeaways

  • Treat vendor and third-party software patching as a priority, not an afterthought. Vulnerabilities in widely used IT tools remain a common entry point for ransomware crews.
  • Assume any organization holding your personal data, regardless of size, could be a target. Monitor breach notifications and consider credit or identity monitoring if you're notified of an incident.
  • Businesses should maintain offline, tested backups and an incident response plan that accounts for data theft and leak-site exposure, not just system encryption.
  • Stay informed about specific ransomware campaigns and exploited vulnerabilities affecting the software your organization relies on, since new groups are adopting these tactics faster than ever.

The record number of active ransomware groups this quarter is a signal that the threat landscape is becoming more distributed and harder to disrupt through single takedowns. Flat victim numbers don't mean flat risk. They mean the pressure has simply found new ways to spread.