AI in cybercrime: Ransomware is evolving instead of receding

According to Check Point Research ’s latest ransomware report for Q2 2026, the number of victims worldwide remains at historically high levels. At the same time, researchers identified a significant shift in attackers toward data theft rather than file encryption, changing the economics and future of ransomware attacks.

Key findings of Check Point Research:ransomware

See more articles from iGuRu.gr when you search for news on Google.

A record 93 ransomware groups are now active

Check Point Research recorded 2.139 ransomware victims worldwide in the second quarter of 2026, a 33% increase year-over-year. At the same time, the number of active ransomware groups increased from 71 to 93, the highest level ever recorded. The findings show that ransomware activity is spreading across multiple players rather than being concentrated in a few dominant groups.

Indications that the AI accelerates growth ransomware

Leaked dialogues revealed that the administrator team's ransomware The Gentlemen created the team management infrastructure in about three days, leveraging AI-based scheduling assistants such as DeepSeek and QwenAlthough it was not found that the AI carries out autonomous attacks, the Check Point Research found clear evidence that it is already accelerating the development of tools for cybercriminals and reducing the level of expertise required to carry out complex attacks.

The ransomware turns into a data theft "business"

According to the data presented in the report, ransom payment rates have decreased from 85% in 2019 to around 23% today. However, payments related to ransomware attacks exceeded $820 million in 2025. This development is pushing cybercriminals to abandon attacks based solely on system encryption and turn to extortion models that are mainly based on data extraction and theft.

Η AI drastically reduces the time window between vulnerability discovery and exploitation

Check Point Research has found that the time between a vulnerability being publicly disclosed and being actively exploited is shrinking, now measured in hours or days rather than weeks. One of the main reasons is the use of artificial intelligence to develop exploits , allowing attackers to exploit new vulnerabilities faster than organizations can patch them.

A team of just nine people created one of the three largest ransomware operations in the world

Analysis of leaks from internal systems and conversations of The Gentlemen revealed that a core group of around nine individuals ran one of the most active ransomware operations in the world. The group leveraged a wider network of affiliates to expand the scale of its attacks, while maintaining a remarkably small operational core.

The evolution of the ecosystem ransomware

In the past, successful ransomware attacks required significant technical expertise, infrastructure, and human resources. Today, AI-assisted development, ransomware - as - a - service models , and specialized criminal supply chains are drastically reducing these barriers, creating a cybercrime economy where smaller groups can gain disproportionate global influence.

For organizations, the implications are equally significant. Data protection is now becoming as critical as backup and recovery strategies. At the same time, businesses must assume that AI will continue to accelerate attacker innovation, reducing the time available to identify and address exploitable vulnerabilities.

Above all, ransomware should no longer be treated solely as a malware problem. It has evolved into a mature criminal ecosystem that relies on front-end intermediaries, credential theft, partner networks, AI- powered tools , and data theft operations.

Sergey Shykevich, Director of Threat Intelligence, Check Point Software, said:

“The most important finding of this quarter is not the number of ransomware victims , but how dramatically the barriers to entry have now fallen. We now have evidence that a small team, supported by AI-powered tools and partner networks, can build a world-class ransomware operation in a matter of months. As AI continues to accelerate both software development and exploit creation , we are likely to see more threat actors emerge, act faster, and expand their reach more than ever before. Organizations must shift from a reactive security model to a proactive strategy, emphasizing reducing exploitable vulnerabilities, protecting credentials and sensitive data, and recognizing that attackers will increasingly leverage AI at every stage of the attack lifecycle.”


Google preferences

Leave a Comment

Your email address will not be published. Required fields are marked *

Your message will not be published if:
1. Contains insulting, defamatory, racist, offensive or inappropriate comments.
2. Causes harm to minors.
3. It interferes with the privacy and individual and social rights of other users.
4. Advertises products or services or websites.
5. Contains personal information (address, phone, etc.).