U.S. Ransomware Threat Landscape: H1 2026
- Ransomware
- Threat Intelligence
- Threat Landscape
Executive Summary
The United States remained the most frequently represented victim country in the Phantom Threat Intelligence Platform dataset during the first half of 2026. Between January 1 and June 30, Phantom recorded 3,668 ransomware and data extortion victim disclosures across 107 countries. Of these, 1,515 were associated with U.S. organizations, representing 41.3% of all victim records analyzed.
These figures should be interpreted carefully. They represent victim records identified and normalized by Phantom, not a complete census of all ransomware incidents.
This terminology is important because modern ransomware operations are not limited to file encryption. Threat actors may steal credentials, gain unauthorized access, exfiltrate sensitive data, disrupt operations, publish stolen information, or use encryption to increase pressure on the victim.
NIST recognizes that ransomware incidents may involve both encryption and data theft for extortion. CISA also addresses ransomware and data extortion together in its prevention and response guidance.
TL;DR — Key Takeaways
- Phantom recorded 3,668 ransomware and data extortion victim records worldwide during H1 2026.
- 1,515 records were associated with organizations in the United States, representing 41.3% of the dataset.
- The next four countries were Canada (161), the United Kingdom (129), Germany (125), and Italy (102).
- Phantom recorded 26.5% fewer U.S. victim disclosures in H1 2026 than in H1 2025. However, this difference reflects observed records and does not necessarily indicate an equivalent decline in overall ransomware activity.
- Globally recognized enterprises also appeared in victim disclosures, demonstrating that large organizations remain exposed to identity compromise, third-party risk, exploitable internet-facing systems, and data extortion.
- Cyber threat intelligence can improve prioritization by connecting external victimology, adversary activity, infrastructure, vulnerabilities, malware, TTPs, sectors, and geography with an organization’s internal telemetry and risk profile.
Methodology and Scope
This analysis is based on ransomware and data extortion victim records collected, normalized, and analyzed by Phantom TIP. The reporting period covers records identified between January 1 and June 30, 2026, inclusive.
The following methodological limitations apply:
- The discovery date reflects when a record was identified by Phantom. It may not correspond to the date of the initial compromise, data theft, encryption, public disclosure, or notification by the affected organization.
- A victim listing or threat actor claim does not automatically constitute an independently verified breach.
- Not every ransomware incident becomes public, and disclosure practices vary by actor, country, sector, victim, and reporting source.
- A record may relate to a subsidiary, local business unit, service provider, or third party rather than the organization as a whole.
- The dataset may include encryption-based ransomware, data extortion involving stolen information, or operations that combine both. For this reason, the article generally uses the term “ransomware and data extortion victim records” rather than stating that every listed organization was encrypted.
- Counts may change as records are validated, enriched, deduplicated, reclassified, or added retrospectively.
H1 2026 Ransomware Snapshot
| Metric | Phantom TIP result |
| Reporting period | January 1-June 30, 2026 |
| Global victim records | 3,668 |
| Countries represented | 107 |
| U.S. victim records | 1,515 |
| U.S. share of all records | 41.3% |
| U.S. victim records in H1 2025 | 2,062 |
The U.S. count was more than nine times the Canadian count and exceeded the combined total of the next nine countries in the ranking. This does not mean that U.S. organizations are inherently nine times more vulnerable. The difference may reflect the size of the U.S. economy, the number of potential targets, attacker monetization incentives, public visibility, disclosure practices, data availability, and threat actor targeting preferences.
Top Five Countries by Recorded Victim Volume
| Rank | Country | Victim records | Share of dataset |
| 1 | United States | 1515 | 41.3% |
| 2 | Canada | 161 | 4.4% |
| 3 | United Kingdom | 129 | 3.5% |
| 4 | Germany | 125 | 3.4% |
| 5 | Italy | 102 | 2.8% |
Together, these five countries accounted for 55.4% of the records in the H1 2026 dataset. The United States alone accounted for nearly three quarters of that top-five volume.
How H1 2026 Compares with H1 2025
Phantom recorded 2,062 U.S.-associated victim disclosures in H1 2025 and 1,515 in H1 2026. This represents 547 fewer observed victim disclosures, or a 26.5% year-over-year decrease.
This comparison should not be interpreted as proof of a corresponding decline in overall ransomware activity. The figures reflect victim disclosures identified through Phantom’s collection and normalization process. Observed volumes may be affected by changes in leak-site availability, actor disruptions, delayed publication, retrospective enrichment, source coverage, and batch releases.
Monthly Distribution in the United States
| Month | All countries | United States | U.S. share |
| January | 689 | 322 | 46.7% |
| February | 740 | 348 | 47.0% |
| March | 308 | 138 | 44.8% |
| April | 645 | 240 | 37.2% |
| May | 629 | 273 | 43.4% |
| June | 657 | 194 | 29.5% |
The Most Active Ransomware Groups Affecting U.S. Organizations in H1 2026
The following table shows the ten ransomware groups most frequently associated with U.S. victim records in the Phantom dataset during H1 2026.
| Rank | Threat Actor | Victim Records | Share of U.S. Records |
|---|---|---|---|
| 1 | Qilin | 261 | 17.2% |
| 2 | Akira | 204 | 13.5% |
| 3 | Play | 105 | 6.9% |
| 4 | INC Ransom | 72 | 4.8% |
| 5 | Cl0p | 64 | 4.2% |
| 6 | Thegentlemen | 64 | 4.2% |
| 7 | Sinobi | 63 | 4.2% |
| 8 | DragonForce | 55 | 3.6% |
| 9 | NightSpire | 46 | 3.0% |
| 10 | Genesis | 40 | 2.6% |
Together, the top 10 groups were associated with 974 victim records, representing 64.3% of the U.S. total for the reporting period.
The Most Affected U.S. Sectors in H1 2026
The following table shows the ten sectors most frequently associated with U.S. victim records in the Phantom dataset during H1 2026.
| Rank | Sector | Victim Records | Share of U.S. Records |
|---|---|---|---|
| 1 | Consulting & Professional Services | 336 | 22.2% |
| 2 | Manufacturing & Engineering | 221 | 14.6% |
| 3 | Healthcare | 147 | 9.7% |
| 4 | Construction | 107 | 7.1% |
| 5 | Science & Technology | 103 | 6.8% |
| 6 | Retail | 54 | 3.6% |
| 7 | Finance | 53 | 3.5% |
| 8 | Logistics | 51 | 3.4% |
| 9 | Real Estate | 49 | 3.2% |
| 10 | Education | 45 | 3.0% |
Together, the top 10 sectors were associated with 1,166 victim records, representing 77.0% of the U.S. total for the reporting period.
These figures reflect victim volume in the dataset and should not be interpreted as a direct measure of sector-specific vulnerability.
Enterprise Scale Does Not Eliminate Ransomware Exposure
The H1 2026 dataset includes victim disclosures associated with numerous globally recognized organizations and brands across technology, healthcare, manufacturing, retail, telecommunications, and other sectors. Their presence highlights that organizational scale and mature security programs do not eliminate exposure to ransomware and data extortion.
Large enterprises often operate complex identity environments, extensive supplier ecosystems, internet-facing infrastructure, cloud platforms, remote-access services, and geographically distributed business units. This complexity creates multiple potential attack paths. Adversaries do not need to defeat every defensive layer. They need only one viable route through compromised credentials, an exposed service, a vulnerable edge device, a third party, social engineering, or a misconfigured cloud resource.
Resilience therefore requires continuous adaptation as threat actors change their tooling, infrastructure, affiliate relationships, initial-access methods, and extortion models. Defensive programs should combine prevention with external visibility, detection engineering, threat hunting, incident readiness, recovery testing, and intelligence-led prioritization.
Ransomware Is an Operation, Not Just an Encryptor
MITRE ATT&CK maps file encryption to Data Encrypted for Impact (T1486), but encryption may be only one stage of a broader intrusion. Depending on the operation, adversaries may gain access through compromised accounts or exploitable public-facing applications, escalate privileges, discover systems, move laterally, collect and exfiltrate data, impair security controls, and inhibit recovery before causing operational impact.
For defenders, relying only on indicators of large-scale encryption leaves many earlier opportunities for detection and disruption unused. Relevant signals may appear throughout the intrusion lifecycle:
- Initial access: exploitation of public-facing applications, compromised credentials, phishing, exposed remote services, and third-party access.
- Execution and persistence: suspicious scripting, unexpected remote management tools, newly created services, scheduled tasks, and unauthorized software deployment.
- Credential and identity abuse: anomalous authentication, token or session misuse, privilege escalation, and access from unusual infrastructure.
- Discovery and lateral movement: system and account enumeration, unusual remote-service activity, SMB and administrative-share access, hypervisor access, and abnormal east-west network activity.
- Collection and exfiltration: unusual archive creation, transfers to public cloud-storage services, outbound data spikes, and unexpected access to sensitive repositories.
- Impact and recovery inhibition: high-frequency file modification, uncommon file extensions, ransom-note creation, shadow-copy deletion, backup tampering, and service disruption.
MITRE’s detection guidance for T1486 includes patterns such as high-frequency file writes involving uncommon extensions, combined with ransom-note creation, registry tampering, or shadow-copy deletion. More broadly, defenders should also monitor for attempts to modify system configurations or delete local snapshots and backups across Windows, Linux, virtualization, and cloud environments. In practice, detection can be improved by correlating these signals with related activity across endpoint, identity, network, cloud, and backup environments rather than evaluating them as isolated alerts.
Where Threat Intelligence Changes the Defensive Equation
Cyber threat intelligence is most useful when it changes a decision. Indicators without context may support blocking, detection, or enrichment, but they do not automatically explain relevance, urgency, confidence, or the action a security team should take.
An intelligence-led ransomware program connects external observations to internal risk:
- Prioritize relevant threat actors and campaigns based on the organization’s geography, sector, technology stack, suppliers, and business profile.
- Track changes in actor infrastructure, leak sites, malware, initial-access methods, exploited vulnerabilities, and victimology.
- Integrate current threat intelligence into SIEM, SOAR, and EDR/XDR platforms to enrich security events, improve detection accuracy, and provide additional context for alert triage and investigations.
- Translate observed TTPs into threat-hunting hypotheses, detection logic, attack-surface reviews, and response playbooks.
- Identify exposed credentials, impersonation infrastructure, internet-facing assets, third-party compromise signals, and relevant activity across leak sites, criminal forums, marketplaces, and messaging platforms before related activity is detected internally.
- Use findings from incidents, threat hunting, and investigations to refine intelligence priorities, collection, detection, and response.
This is the difference between consuming a threat feed and operating a threat intelligence capability. The objective is not to maximize the number of indicators delivered. It is to create a decision advantage through earlier awareness, better prioritization, faster investigation, and more relevant defensive action.
Be Proactive Against Ransomware
Phantom Threat Intelligence Platform turns external ransomware activity into actionable intelligence for proactive hunting, detection, and response.
Recommended Actions for Organizations
1. Define Priority Intelligence Requirements
Define the ransomware-related questions that matter most to the organization: which actors and campaigns are relevant to its sector and geography, which initial-access methods they use, which technologies and vulnerabilities they exploit, which suppliers and other third parties create concentration risk, and which external signals should trigger defensive action. Collection should follow these requirements, not the other way around.
2. Protect Identity and Remote Access
Enforce phishing-resistant MFA where feasible, reduce standing privileges, monitor anomalous sign-ins and session activity, control remote administration, reset exposed passwords, revoke compromised tokens or sessions, and remove dormant or unnecessary accounts. Correlate identity and endpoint telemetry and enrich it with relevant threat intelligence context.
3. Reduce Internet-Facing and Edge Exposure
Maintain an accurate inventory of external assets, prioritize actively exploited vulnerabilities, harden VPNs and other edge systems, restrict access to management interfaces, and identify shadow IT or abandoned infrastructure that remains reachable. Risk-based vulnerability prioritization should consider exploitability, exposure, observed adversary activity, and business criticality, not CVSS scores alone.
4. Detect Pre-Encryption Activity
Build detections for credential access, unexpected remote administration, unusual privileged activity, lateral movement, unusual archive creation, data staging, backup manipulation, tampering with or disabling security controls, and high-volume file changes. Test these detections against realistic attack paths and refine them using current actor TTPs.
5. Protect Recovery Paths
Maintain tested and isolated backups with appropriate immutability controls, restrict administrative access to backup systems, monitor attempts to delete backups or alter recovery configurations, and regularly test restoration procedures. MITRE ATT&CK identifies the deletion or disabling of recovery mechanisms as Inhibit System Recovery (T1490), a technique adversaries use to prevent recovery and increase operational impact.
6. Prepare for Both Encryption and Data Extortion
Incident response plans should address containment, evidence preservation, applicable legal, regulatory, and contractual obligations, internal and external communications, credential and session resets, third-party coordination, assessment of potential data exposure, recovery, and business continuity. CISA’s #StopRansomware guidance includes prevention practices and a response checklist for both ransomware and data extortion incidents.
7. Measure Intelligence Outcomes
Measure whether intelligence improves triage time, detection coverage, vulnerability prioritization, response to exposed credentials, incident scoping, and executive risk decisions. The number of indicators collected or delivered is not, by itself, a meaningful measure of intelligence effectiveness.
Compliance and Governance: Threat Intelligence in ISO/IEC 27001:2022
ISO/IEC 27001:2022 includes Annex A control 5.7, Threat intelligence, which calls for collecting and analyzing information about information security threats to produce actionable intelligence. In practice, organizations should define relevant intelligence requirements, use appropriate sources, assess the quality and relevance of collected information, analyze threats in the context of their environment, and distribute intelligence to the stakeholders who need it.
A threat intelligence platform does not make an organization compliant by itself. Compliance depends on governance, ownership, documented processes, risk assessment, evidence, and the effective operation of applicable controls. Phantom can support control 5.7 by helping teams collect, normalize, analyze, prioritize, and distribute threat information, and by integrating relevant intelligence into security monitoring, vulnerability management, threat hunting, and response workflows.
See Your External Exposure
Find out whether your brand, credentials, or public-facing assets appear across channels used by threat actors.
FAQ
What does a ransomware victim record represent?
A victim record may reflect file encryption, data theft, extortion, a threat actor claim, or an incident involving a subsidiary or business unit. Inclusion in the dataset does not independently confirm the scope or impact of an incident.
Does the decline in U.S. victim disclosures mean ransomware activity decreased?
Not necessarily. Phantom recorded 26.5% fewer U.S.-associated victim disclosures in H1 2026 than in H1 2025, but observed totals may be affected by disclosure timing, source availability, actor behavior, delayed publication, and retrospective data updates.
How can threat intelligence help reduce ransomware risk?
Threat intelligence helps organizations identify relevant actors and attack patterns, prioritize exposed assets and vulnerabilities, improve detection and threat hunting, assess third-party risk, and act on external risk signals before or during an incident.
References and Sources
- NIST IR 8374 Rev. 1: Ransomware Risk Management: A Cybersecurity Framework 2.0 Community Profile
- NIST SP 800-150: Guide to Cyber Threat Information Sharing
- CISA: #StopRansomware Guide
- MITRE ATT&CK: T1486: Data Encrypted for Impact
- MITRE ATT&CK: T1490: Inhibit System Recovery
- MITRE ATT&CK: DET0215: Detection of Multi-Platform File Encryption for Impact
- ISO/IEC 27001:2022
News & Insights
More from our security team
Deep dives, incident analysis, and threat intelligence.
