
Ransomware operators are becoming faster, more sophisticated and increasingly capable of disabling the very security technologies organisations rely on to stop them, according to Halcyon’s latest Q2 2026 Ransomware Evolution Report.
The report recorded 1,988 publicly claimed ransomware attacks from 89 active groups targeting organisations across 101 countries during the second quarter of 2026. While overall attack claims fell by 5.7% quarter on quarter, the underlying tactics used by attackers became significantly more advanced, signalling a shift towards faster, more automated and harder-to-detect operations.
One of the defining trends of the quarter was the widespread adoption of techniques designed to disable endpoint detection and response (EDR) tools before encryption begins. Once considered a specialist capability, these techniques have rapidly become standard practice among leading ransomware groups, giving defenders even less time to detect and contain attacks.
The report also found that artificial intelligence (AI) is moving beyond experimentation into operational use. Threat actors increasingly leveraged AI throughout the attack chain, from malware disguised as AI productivity tools to AI-assisted victim negotiations and the emergence of what researchers believe to be the first agentic ransomware capable of autonomously conducting key stages of an intrusion.
The ransomware ecosystem itself also continued to evolve. TheGentlemen overtook Qilin as the most active group by June after rapidly scaling operations using custom tooling designed to disable dozens of security products. Meanwhile, DragonForce demonstrated attacks capable of progressing from initial compromise to ransomware deployment in under an hour by exploiting edge infrastructure vulnerabilities.
Manufacturing remained the most targeted sector, accounting for almost one in five attacks, followed by construction, business services, retail and software organisations.
Ross Asquith, Solutions Engineering Director, Europe, Halcyon, said: “What we’re seeing is a ransomware ecosystem that is becoming faster, more automated and far more effective at neutralising the security tools organisations rely on. The widespread use of techniques designed to disable endpoint protection, combined with AI-powered tooling that lowers the barrier to entry for attackers, means organisations can no longer assume traditional controls will buy them the time they need to respond. Resilience today depends on assuming attackers will get in and building the ability, at speed, to detect, contain, recover and continue operating.”
The report also highlights growing evidence of ransomware being used to support state objectives, with Iran-linked actors increasingly disguising espionage campaigns as criminal ransomware operations. At the same time, data theft and extortion continued to inflict significant damage on enterprises, reinforcing the need for organisations to strengthen both prevention and recovery capabilities.
The findings underline the importance of adopting a resilience-first approach to cyber defence, with organisations expected to invest not only in prevention, but also in rapid detection, automated containment and reliable recovery capabilities that minimise operational disruption.
