Ninety-three active ransomware groups sounds like bad news. Most coverage of Check Point Research’s Q2 2026 report has treated it that way. Read the numbers differently and this ransomware market fragmentation looks less like an escalation. It looks more like a criminal industry losing its grip on efficiency. That is worth saying plainly, because it changes what businesses should actually worry about.

A year ago, ransomware was consolidating around a small number of highly professional operations. Check Point’s report shows the top ten groups’ share of victims falling from 71% to 57.6% in a single quarter. The number of active groups climbed from 71 to 93, the highest on record. Two names, Qilin and The Gentlemen, still dominate the headlines. Together they account for roughly a quarter of victims, according to GuidePoint Security’s tracking. But a quarter is not a majority. The other three-quarters are being fought over by dozens of smaller, less capable crews.
Table of Contents
Ransomware market fragmentation is a sign of pressure, not strength
Lotem Finkelstein, Check Point’s VP of research, described this pattern to Infosecurity Magazine as a familiar cycle. Operators scatter under law enforcement pressure. Then they slowly regroup around whichever operations prove resilient. The past year has seen exactly that pressure. Check Point’s report credits takedowns of cryptocurrency laundering platforms, cash-out exchanges, malware signing services, infostealer networks and criminal VPN infrastructure. Ninety-three groups is not ninety-three well-run businesses. It is ninety-three attempts to rebuild something that keeps getting knocked down.
The payment data backs this up better than the victim count does. Check Point puts the current ransom payment rate at around 23%, down from 85% in 2019 and a multi-year low. Fewer than one in four victims are paying at all. A criminal business model where three-quarters of targets refuse to transact is not a business model in good health, whatever the headline victim numbers suggest.
The real risk is not the group count
None of this means the threat is shrinking. Total on-chain ransomware payments still topped $820 million in 2025. Nord Security researchers told Security Boulevard that the market has settled at “a new alarming baseline of about 2,500 attacks per quarter.” Aiden Sinnott of Sophos X-Ops made the sharper point to Infosecurity. Qilin’s current dominance is largely inherited, he said, the direct result of law enforcement clearing out its rivals rather than any special skill on Qilin’s part. Take away that clearing effect and the next eighteen months look like more of the same churn.
The detail that should worry a defender is not the group count. It is the exploitation window Check Point flags in its report. Vulnerabilities are being weaponised within hours to days of disclosure, not weeks. That trend holds regardless of whether the market consolidates around two groups or fragments across ninety. A smaller, scrappier crew with a working exploit for an unpatched system does just as much damage as a large, professional one.
Churn, not conquest
Look at the turnover and the “ninety-three groups” figure gets smaller still. GuidePoint Security’s tracking for the same quarter counted 25 new ransomware groups launching, against only five going defunct. But the firm’s own research notes that historically only around one in three emerging groups ever reaches sustained, established activity. Most of the ninety-three will not be around in a year. That is churn, not conquest: a criminal ecosystem throwing new attempts at the wall faster than any of them can prove durable. Check Point’s report adds a matching data point. The United States’ share of victims fell from 50% to 42% quarter on quarter. That reads less like disciplined global expansion and more like opportunists chasing soft targets as the old, easier hunting grounds get harder. It is another data point for the same ransomware market fragmentation story.
What businesses should take from this ransomware market fragmentation
Do not read a rising group count as a reason to panic. Do not read a falling payment rate as a reason to relax either. Both numbers describe the same underlying story: an industry under real pressure, still doing real damage, and increasingly opportunistic about where it finds a way in. The Gentlemen’s own leaked operations, cited in Check Point’s report, showed a team of roughly nine people. They built their management panel with AI coding assistants in about three days. That is not the profile of an elite operation. It is the profile of a small, agile group that only needs one unpatched server to make the news.
The sensible response to this ransomware market fragmentation is unglamorous and unchanged by any of this quarter’s drama. Patch fast. Back up properly. Assume the group that gets in will be one nobody has heard of yet.
Subscribe to our newsletter
Honest updates, straight to your inbox. Unsubscribe any time.