Skip to content
You can now search across every topic, entity and event.What's new
Cybersecurity: Threats and Defences
5SEP

Ransomware tempo holds at 95 in May

3 min read
12:09UTC

BlackFog counted 95 publicly disclosed ransomware attacks in May across 17 countries, the US taking 54 and Australia 18. Qilin led with 11 victims among 37 active groups, with no sign of consolidation.

TechnologyDeveloping
Key takeaway

May ran 95 disclosed ransomware attacks across 37 active groups, with healthcare hit hardest and no consolidation in sight.

BlackFog counted 95 publicly disclosed ransomware attacks worldwide in May 2026 across 17 countries, the United States taking 54 and Australia 18, so the monthly tempo held even as enforcement intensified 1. The security vendor compiles its figures from leak-site postings and public disclosures, which capture the visible floor of activity rather than the full total.

Healthcare was the hardest-hit sector with 28 incidents, because care delivery cannot tolerate downtime, so hospitals pay faster and crews target them first 2. Qilin led all crews with 11 claimed victims, but the more telling figure is the 37 active groups running in a single month with no sign of consolidation 3.

That group count is why the takedown headlines do not translate into falling risk. When US prosecutors unsealed Scattered Spider charges against Peter Stokes in April , they took an individual actor off the board without thinning the ecosystem around him. The bottleneck on the criminal side is the supply of affiliates, the freelance operators who rent a crew's tooling and split the proceeds, and neither an arrest nor a server seizure reduces that pool. For a defender, the lesson is that enforcement wins should not be read as a drop in operational threat; the tempo is the planning baseline, not the takedown.

Deep Analysis

In plain English

Ransomware attacks happen when criminals break into an organisation's computer systems, scramble all the files so the organisation cannot access them, and then demand money to restore access. Sometimes they also steal the files first and threaten to publish sensitive information if the ransom is not paid. BlackFog, a security company that tracks these attacks, counted 95 publicly known ransomware incidents in May 2026 across 17 countries. Healthcare was the hardest hit sector, with 28 hospitals and medical organisations affected. The US accounted for more than half of all known victims. A group called Qilin led all criminal ransomware operators with 11 claimed attacks, one of 37 active groups operating during the month.

What could happen next?
  • Risk

    Healthcare organisations running unpatched legacy infrastructure in the US and Australia face near-term ransomware targeting by Qilin affiliates, given the group's documented sector preference and the disproportionate victim counts in both countries.

  • Consequence

    The absence of consolidation in the 37-group ecosystem means law-enforcement takedowns of individual groups, including the Operation Saffron disruption of First VPN, redistribute affiliates rather than reducing attack volume.

First Reported In

Update #6 · The 2024 patch that is breaking now

BlackFog· 7 Jun 2026
Read original
Different Perspectives
ENISA
ENISA
ENISA published an SME cyber-resilience maturity model on 6 August and updated the Cyber Resilience Act reporting-platform FAQ on 31 August. The agency supplies common implementation tools for smaller operators, but it cannot fine organisations that do not use them.
UAE Cyber Security Council
UAE Cyber Security Council
On 10 August, the UAE Cyber Security Council said national teams contained attacks on aviation, energy and education before objectives were reached. Its second monthly statement, after a 3 July financial-sector disclosure, makes public reporting of stopped attacks part of its operating posture.
South African authorities
South African authorities
INTERPOL said on 25 August that South African authorities made 39 arrests, seized US$2.67 million and blocked 257 accounts during Operation Jackal IV. Their share of the 23-country operation shows the material enforcement burden in a cross-border fraud case.
Europol
Europol
On 2 September, Europol announced the sinkholing of Sality after a 31 August operation involving US, Bulgarian, Hungarian and Romanian authorities. Its more than 11 million linked IP addresses measure infrastructure contact, not confirmed victims, and show why technical partners joined the action.
CISA
CISA
From 3 August to 2 September, CISA recorded three-day deadlines for 24 of 37 KEV additions, compared with 34 of 39 from 10 June to 29 July. The falling share changes the urgency signal that US federal agencies and private-sector tooling draw from the catalogue.
Beacon
Beacon
On 3 September, Beacon said its final report found that an intruder likely exported its customer database during roughly one hour and 27 minutes on 27 July. Charities using the CRM now have a named exposure route, a compromised AWS access key in public build artefacts.