Ransomware attacks speed up as hackers use AI tools
Tue, 28th Jul 2026 (Today)
Halcyon has published new findings on ransomware activity in the second quarter of 2026, showing that attackers used AI tools more widely and moved more quickly through intrusions.
The report recorded 1,988 publicly claimed ransomware attacks from 89 active groups across 101 countries during the quarter. Although the total fell 5.7% from the previous quarter, the methods used became more advanced.
A central finding was the wider use of techniques designed to disable endpoint detection and response tools before encryption began. Methods once associated with specialist operators have spread across leading ransomware groups, reducing the time available for defenders to detect and contain an attack.
The study also pointed to broader operational use of AI by threat actors. Researchers observed malware disguised as AI productivity tools, AI-assisted negotiation with victims and what they described as the first agentic ransomware capable of carrying out key stages of an intrusion autonomously.
The quarter also saw a rapid shift in the ranking of the most active groups. By June, TheGentlemen had overtaken Qilin after expanding its operations with custom tooling designed to disable dozens of security products, according to the findings.
Another group, DragonForce, showed how quickly an attack can now unfold. Halcyon identified attacks that moved from initial compromise to ransomware deployment in under an hour by exploiting vulnerabilities in edge infrastructure.
Sector impact
Manufacturing remained the most targeted industry, accounting for almost one in five attacks during the quarter. Construction, business services, retail and software followed.
The findings also linked some ransomware activity to state interests. Halcyon found growing evidence that Iran-linked actors are disguising espionage campaigns as criminal ransomware operations.
That trend adds to pressure on companies already dealing with the financial and operational impact of data theft and extortion. These tactics continued to cause significant damage for large organisations, even when disruption extended beyond file encryption.
Ross Asquith, Solutions Engineering Director, Europe, at Halcyon, described a market in which the practical barriers facing attackers are falling. He focused on the speed of attacks and the reduced protection offered by conventional security tools once intruders have gained access.
"What we're seeing is a ransomware ecosystem that is becoming faster, more automated and far more effective at neutralising the security tools organisations rely on. The widespread use of techniques designed to disable endpoint protection, combined with AI-powered tooling that lowers the barrier to entry for attackers, means organisations can no longer assume traditional controls will buy them the time they need to respond. Resilience today depends on assuming attackers will get in and building the ability, at speed, to detect, contain, recover and continue operating," said Ross Asquith, Solutions Engineering Director, Europe, at Halcyon.
Changing landscape
The figures suggest a ransomware market that is fragmenting and reshuffling quickly, even as overall claim volumes fluctuate. A newcomer displacing an established leader within months points to a more fluid competitive environment among criminal groups, especially where custom tools can bypass common defences.
For defenders, the spread of EDR-disabling techniques is significant because endpoint products are often a core layer in incident detection and response. If those systems are neutralised early, security teams may have little warning before encryption, data theft or extortion begins.
The use of AI also appears to be broad rather than confined to a single stage of an attack. By supporting initial deception, elements of the intrusion and victim communications, the technology could allow less experienced operators to carry out attacks that previously required more specialist knowledge.
The pattern supports a shift in cyber defence planning away from prevention alone. Halcyon's analysis argued that organisations need rapid detection, automated containment and reliable recovery processes to limit operational disruption when attackers breach their networks.
The report covers ransomware activity observed between April and June and examines attack volumes, active groups, exploited vulnerabilities and industry patterns. Manufacturing accounted for the largest share of attacks during the period, underlining the sector's continued exposure to operational disruption and extortion.