Ransomware groups named more victims on their leak sites over the past year than in any period previously tracked, with a single operation responsible for close to a fifth of them.

 

What happened

Ransomware operators publicly named 7,551 victims between April 2025 and March 2026, a 24.9% increase over the preceding twelve months, according to CyberPress reporting on newly published research. Qilin, also tracked as Agenda, accounted for much of the growth with 1,358 claimed victims, up 443% year over year. The pace quickened sharply in the back half of the period, with 2,904 victims counted in the first six months against 4,647 in the second. March 2026 alone produced 861 named organizations, the highest single month in the dataset. Because the numbers come from leak-site postings and public disclosures, they capture what attackers chose to advertise rather than every incident that occurred, which leaves out organizations that paid quietly or were never listed.

 

Going deeper

Qilin runs what is known as a ransomware-as-a-service operation, where the core group builds and maintains the malware while affiliates carry out the intrusions and split the proceeds. Those affiliates get in through phishing, exposed remote access services, compromised virtual private network (VPN) accounts, credentials harvested by information-stealing malware, and remote monitoring and management (RMM) tools, the software IT teams use to administer machines from a distance. Once inside, they encrypt files and steal copies of the data beforehand, threatening publication if payment does not arrive, a pressure tactic called double extortion. Growth was not limited to one name. The report behind counted 127 active operations at the close of the period and 146 by June 2026, including 61 that surfaced for the first time during the year. Concentration held despite the crowding, with the five largest operations claiming 43.6% of all named victims. A rescan of victim organizations after their incidents became public found 43.5% still carrying a vulnerability scored 9.0 or higher on the industry severity scale, and 30.8% still exposed through a flaw listed on the federal catalog of vulnerabilities known to be under active exploitation. Disclosure closed the incident without closing the hole that allowed it.

 

What was said

The HHS Health Sector Cybersecurity Coordination Center reached a similar read on the group two years ago, describing its victim selection in its threat profile on Qilin as "opportunistic rather than targeted." The same profile counted at least fifteen incidents against healthcare and public health organizations, roughly half of them in the United States.

 

In the know

The victim profile changed downmarket over the year. Organizations earning between $50 million and $100 million made up 29.3% of victims whose revenue could be identified, up from 25.1%, and the $1 million to $5 million band grew its share as well, according to CyberPress. That range covers most physician groups, regional labs, and billing companies. Researchers also flagged trusted business platforms as a route worth watching, including software-as-a-service integrations and OAuth connections, the permission grants that let one cloud application reach data inside another. One compromise there can touch dozens of downstream organizations at once.

 

The big picture

Healthcare does not top this particular dataset, where manufacturing led for a fourth consecutive year at 1,660 victims, yet the sector carries risks the raw counts do not capture. Ransomware against a hospital or clinic interrupts care, not just revenue, which is why the Cybersecurity and Infrastructure Security Agency (CISA), the Federal Bureau of Investigation, and the Department of Health and Human Services have issued joint guidance aimed squarely at healthcare providers. Ransomware attacks on healthcare organizations have grown 264% since 2018, according to the HHS Office for Civil Rights, cited in Paubox's State of Email Security Report, which also found that 60% of healthcare IT leaders had dealt with an email-related breach or security incident. Email is where a large share of these intrusions begin, whether through a phishing message that harvests a login or an attachment that delivers the first stage of an attack. Stopping the message before anyone opens it does more to prevent an encryption event than any recovery plan written afterward, and the finding that so many victims remained exposed months later suggests prevention still gets less attention than it should.

 

FAQs

Does paying a ransom remove the reporting duty under HIPAA?

No. Paying for a decryption key or a promised deletion does nothing to change whether protected health information was accessed or acquired without authorization. The Office for Civil Rights presumes a breach occurred once ransomware reaches systems holding electronic PHI unless a risk assessment demonstrates a low probability of compromise, and notification duties stand regardless of any payment.

 

Are leak-site victim counts reliable enough to base decisions on?

They are useful for spotting direction and pace, less so for absolute totals. Groups sometimes post organizations they never successfully encrypted, list the same victim twice under different names, or omit victims who paid before publication. Treat the numbers as a floor on activity rather than a full accounting.

 

What is the difference between a severity score and an actively exploited vulnerability listing?

A severity score rates how damaging a flaw could be if exploited, based on technical characteristics. The federal catalog of known exploited vulnerabilities records which flaws attackers are actually using in the wild. A moderately scored flaw under active exploitation often deserves patching ahead of a higher-scored one nobody has weaponized.

 

How should a healthcare organization vet a vendor's ransomware exposure?

Ask what the vendor's recovery time objective is for the systems you depend on, whether backups are stored offline and tested through full restores, and how quickly they commit to notifying you after an incident. Contract language on notification timelines matters more than a completed security questionnaire, because business associate agreements set the clock for your own reporting duties.

 

Why do attackers target organizations in the middle revenue range?

Companies in that band hold data and operational dependencies worth extorting while running leaner security teams than large enterprises. Many also serve as suppliers or service providers to bigger organizations, which makes them a practical route into networks that would be harder to breach directly.