Blog

10 of the most notorious ransomware groups in 2026 


ransomware-groups

Ransomware groups have become more organized, more disciplined, and more effective over time. A decade ago, many attacks were noisy smash-and-grab operations. Today, the groups behind major ransomware campaigns often work through affiliate models, run leak sites, recruit partners, and refine their playbooks as they go.  
 
Access to victim environments can be bought, and negotiations can be handled by specialists. The technical side of the attack is often just one part of a much broader criminal operation. Threat reporting and law enforcement updates continue to describe a ransomware ecosystem that adapts quickly even after takedowns and arrests.  
 
That matters because the names may change, but the methods tend to persist. One group fades, another appears, and the same pressures remain: stolen data, operational disruption, reputational damage, and intense time pressure inside the victim organization.  
The groups below are among the most notorious to watch in 2026. Some are still highly active. Others remain important because they shaped the tactics that continue to define ransomware campaigns today. Let’s dive into it. 

1. LockBit

LockBit has been one of the defining ransomware names of the last several years. At its peak, it operated with the scale and confidence of a mature criminal business, using a ransomware-as-a-service model that let affiliates conduct attacks while the core operators maintained infrastructure and tooling. LockBit has also been described as the most deployed ransomware variant worldwide
 
What makes LockBit so important in a 2026 article is its resilience. Law enforcement pressure damaged the brand, but it did not erase the model. Variants, imitators, and offshoot behavior have continued to appear, which says a great deal about how durable successful ransomware operations can be. Once a playbook proves effective, it rarely disappears with one takedown.  
 
LockBit also helped normalize a more industrial approach to ransomware. The group became known for speed, aggressive extortion, and a structure that allowed multiple attacks to unfold in parallel. That legacy still matters because so many groups now follow a similar path.  

2. Cl0p 

Cl0p built its reputation through large-scale campaigns tied to vulnerabilities in widely used enterprise software and file transfer products. Rather than approaching victims one by one, the group repeatedly found ways to exploit a single trusted platform and then reach a huge number of organizations through that single weakness.  
 
That operating style makes Cl0p especially dangerous and has led to many people warning about their ties to mass exploitation campaigns. A company can do a reasonable job protecting its own environment and still be exposed through a product it depends on. When a widely used platform becomes the entry point, the impact spreads fast and far.  
 
Cl0p also illustrates how ransomware groups increasingly blur the line between classic encryption attacks and pure extortion. In some campaigns, the pressure comes less from locked systems and more from the threat of public data exposure. For many victims, that distinction changes very little. The crisis still lands all at once.  

3. Akira 

Akira has become one of the most prominent ransomware operations in the current threat landscape. CISA, the FBI, and partner agencies updated their advisory on Akira in November 2025, describing continued threat activity and evolution in the group’s methods. The advisory says Akira has impacted more than 250 organizations and has targeted a wide range of sectors. 
 
Akira stands out because it has combined consistency with adaptability. The group has shown a willingness to target modern infrastructure, including virtualized environments, which gives it a stronger operational impact once it gains access. Experts have also tied them to the updated advisory also noted Akira activity against Nutanix virtual machines, adding to earlier focus on VMware ESXi and Hyper-V environments.  
 
In practical terms, Akira represents the sort of ransomware threat many defenders now worry about most: active, current, technically capable, and still refining its methods rather than relying on an old reputation alone.  

4. Play 

Play does not always receive the same level of mainstream attention as LockBit or Cl0p, but it has remained highly relevant. The FBI had identified approximately 900 entities allegedly exploited by the group as of May 2025. That is a striking figure and a reminder that visibility in headlines is not the same thing as operational significance. Broadcom’s 2026 ransomware report also noted multiple Play attacks targeting U.S. organizations during 2025.  
 
Play has built its reputation through steady execution. The group is associated with methods defenders now recognize all too well: gaining access, moving laterally, stealing data, and then using encryption and extortion together to maximize pressure.  

5. Black Basta 

Black Basta emerged as a serious ransomware threat by leaning into a model that already worked well: compromise the environment, move with care, steal sensitive data, and make downtime as painful as possible. In 2024, Black Basta affiliates had already impacted more than 500 organizations globally
 
One reason Black Basta remains worth highlighting is that it shows how little novelty is required for a ransomware group to succeed. A refined version of familiar tactics can still produce serious outcomes. That is part of what makes the ransomware problem so persistent. Criminal groups do not need a revolutionary new method every few months. They need access, discipline, and enough technical fluency to exploit the weak points that already exist. 
 
Black Basta also became part of a broader pattern in which groups learned from one another, borrowed working techniques, and shifted branding over time. That fluidity makes attribution harder and long-term defense more complicated. 

6. Medusa 

Medusa moved higher into the spotlight after a March 2025 advisory that said the group had impacted more than 300 victims across critical infrastructure sectors as of February 2025. The advisory described tactics including phishing and exploitation of unpatched vulnerabilities, both of which remain among the most common routes into victim environments.  
 
Medusa deserves a place on this list because it reflects a central truth about ransomware in 2026: old access methods still work. There is a tendency to imagine major ransomware incidents beginning with something highly exotic. But in reality, a great deal of damage still begins with a known weakness, a successful credential theft, or a phishing campaign that catches someone at the wrong moment.  
 
There is also a psychological element to Medusa’s style. Public leak sites, countdown timers, and escalating pressure tactics are designed to force rapid decisions inside the victim organization. That pressure can be as consequential as the technical compromise itself.  

7. Qilin 

Qilin has become increasingly important in the 2025 to 2026 ransomware picture. In March of 2026, Qilin was labeled one of the most active groups of 2025, driven by a turnkey ransomware-as-a-service model and a dramatic increase in attacks. 
 
Qilin is a good example of how fast the field moves. A group can go from being one name among many to becoming a major operator in a relatively short period. The rise is often fueled by business logic as much as technical innovation. If the affiliate model is attractive, if the tooling is usable, and if the group builds enough credibility in criminal circles, growth can come quickly.  
 
For defenders, Qilin is a reminder that current threat intelligence matters. A list built around only the best-known legacy names would miss where some of the most relevant pressure is coming from right now.  

8. RansomHub 

RansomHub is another group that has become difficult to ignore. It surfaced in 2024 and quickly attracted attention from multiple threat intelligence teams. It has been described as a young ransomware-as-a-service group that moved boldly against larger enterprises.  
 
Part of what makes RansomHub noteworthy is speed. In ransomware, rapid emergence often signals that experienced operators or affiliates have found a new home and a viable new platform. The banner may be new, but the hands behind it often are not.  
 
RansomHub also helps explain why takedowns alone rarely solve the problem. When one operation is disrupted, talent and affiliates move. Infrastructure changes. New names appear. The market continues.  

9. DragonForce 

DragonForce has drawn increasing attention as part of the newer generation of active ransomware operations. Reporting in mid-2025 described a turf war between DragonForce and RansomHub, with both groups competing for affiliates and influence in the ransomware-as-a-service space. 
 
That kind of internal conflict might sound like criminal drama, but it also reveals something important about the structure of the ecosystem: ransomware groups are competing businesses in an illicit market.  
 
DragonForce matters because it shows how the threat keeps evolving around recruitment, branding, and affiliate relationships. The most successful groups are no longer simply writing malware and launching attacks. They are also trying to attract operators, build credibility, and position themselves against rivals.  
 
For organizations on the defensive side, that means the ransomware problem has momentum even when one specific group stumbles. Competition inside the criminal ecosystem can produce more attacks, more experimentation, and more pressure on victims.  

10. BlackSuit 

BlackSuit is a strong example of ransomware continuity under a different label. The U.S. Department of Justice announced coordinated disruption actions against BlackSuit in August 2025 and said law enforcement seized servers, domains, and approximately $1 million in laundered proceeds connected to the operation. 
 
That makes BlackSuit important for two reasons. First, it has been active enough to draw major international enforcement attention. Second, it demonstrates how ransomware groups can evolve in public view. The name shifts. The infrastructure changes. The operating logic stays familiar.  
 
When organizations think about ransomware, that continuity is worth understanding. Tracking names is useful, but tracking behavior is more useful. The same techniques can reappear under a different banner with very little warning.  

What makes these groups so effective 

Across all of these groups, several patterns keep showing up. Initial access is often obtained through stolen credentials, unpatched edge devices, or social engineering. Google’s M-Trends 2026 reporting said confirmed or suspected exploitation of vulnerabilities accounted for about a third of ransomware intrusions observed in 2025, with VPNs and firewalls among the most common entry points. Virtualization infrastructure also received more attention from attackers, which raises the operational stakes once they are inside.  
 
After access is established, the focus shifts quickly to understanding the environment. Attackers identify valuable systems, map privileges, and look for ways to weaken recovery options. Data theft commonly takes place before encryption, which gives the attackers leverage even if the victim has solid backups. By the time the ransomware note appears, the real damage is often already underway.  
 
That is part of what makes these groups so dangerous. They are not relying on one trick. They are running a sequence that has been tested repeatedly across many victims.  

Why this matters for organizations in 2026 

A list like this is useful when it helps people think more clearly about risk. The lesson is not that every organization needs to memorize group names. The real value comes from recognizing how these operations function and why they continue to work. Ransomware groups succeed when basic weaknesses remain exposed, when patching lags behind, when identity controls are loose, and when response planning exists mostly on paper.  
 
That is why ransomware preparedness has become a capability issue as much as a tooling issue. Organizations need people who understand how attacks unfold, how adversaries move through environments, and how defensive decisions hold up under pressure.  

Looking to build that capability? 

If you are looking to upskill in cybersecurity and build the practical knowledge needed to understand threats like these, the Cyber Security Specialist program from the Swiss Cyber Institute is a strong next step. The program is designed for people who want a broader and more applied understanding of modern cyber risk, including how attacks happen, how defenses fail, and how organizations can improve their resilience in the real world.  
 
If you’re looking for a free consultation call for your potential upskilling, we’re also happy to help. Just book a slot below. 

Subscribe for updates