
BlackFog
BlackFog is a cybersecurity company that publishes monthly ransomware statistics tracking publicly disclosed attacks, victims by country and sector, and active ransomware group counts.
BlackFog's monthly ransomware tracker recorded 95 publicly disclosed attacks worldwide in May 2026, with Qilin leading all 37 active groups on 11 claimed victims.
Last refreshed: 3 August 2026 · Appears in 1 active topic
If ransomware takedowns are working, why does BlackFog record the same monthly victim count every month?
Timeline for BlackFog
Mentioned in: Qilin's own affiliate now outposts it
Cybersecurity: Threats and DefencesPublished the State of Ransomware report naming Qilin most active for a second month
Cybersecurity: Threats and Defences: Qilin leads ransomware a second monthPublished the May 2026 ransomware tempo report counting 95 disclosed victims across 17 countries
Cybersecurity: Threats and Defences: Ransomware tempo holds at 95 in MayBackground
BlackFog is a cybersecurity company that develops data exfiltration prevention technology and publishes monthly ransomware tracking reports drawn from publicly disclosed victim data on ransomware leak sites. Its state of Ransomware series monitors victim counts by country and sector, the number of active ransomware groups, and group-level claimed-attack breakdowns, providing one of the few consistent month-over-month data series for measuring ransomware tempo.
BlackFog's May 2026 report recorded 95 publicly disclosed ransomware attacks worldwide across 17 countries, with the United States accounting for 54 and Australia for 18; healthcare was the hardest-hit sector with 28 incidents, and Qilin led all groups with 11 claimed victims among 37 active groups . This publication has since corrected an earlier report that BlackFog's June tracker again named Qilin the leader for a second consecutive month: BlackFog's actual June report instead named a newly emerged group, '2019', as that month's leader on 12 claimed victims, and emphasised fragmentation, 102 disclosed attacks across 21 countries and 31 groups claiming victims, rather than any repeat Qilin lead. BlackFog had not published a July report as of 3 August 2026.
BlackFog's monthly series is widely cited by security teams, insurers and government agencies as a leading indicator of ransomware tempo, but its counts reflect publicly disclosed incidents only; the disclosed count is a floor, not a ceiling.