HomeNewsBreachesAbout
Account

RansomWho? Inside the Great Ransomware Splintering of 2026

DataBreach.com Team · · August 9th 2026, 7:56 am EDT

RansomWho? Inside the Great Ransomware Splintering of 2026

The ransomware economy is not simply growing. It is breaking into smaller, faster-moving pieces - and the names are multiplying more quickly than defenders can investigate them.

This meme posted on X by @solostalking aptly captures how much of the community is feeling right now:

Image credit: @solostalking on X.

That is not a fictional roll call. On August 9, the open-source tracker RansomLook showed roughly 315 victim posts from 40 active groups during the previous seven days-and marked all eight of those names as new to its weekly view. L Group arrived with 26 posts. Orova had 25. Dark Project had 19. Even the smaller newcomers appeared with functioning leak sites and several alleged victims. RansomLook’s live dashboard looked less like a list of organized-crime syndicates than an app store accepting new submissions.

But here is the first rule of writing about ransomware in 2026: a new name is not necessarily a new gang, and a leak-site post is not necessarily a verified breach.

A new brand may be a genuine start-up, a veteran affiliate going independent, a rebrand of an older crew, a label placed over someone else’s infrastructure, a data broker pretending to be a ransomware operation-or simply a fraud (0apt, I'm looking at you). The website proves that a website exists. It does not prove who operates it, whether encryption occurred or even whether every listed victim was compromised.

That caveat does not make the explosion any less real. It makes it more interesting.

The Numbers Behind the Splintering

Every major dataset draws the boundary differently, but the direction is remarkably consistent.

IBM X-Force counted 109 distinct extortion groups in 2025, up from 73 in 2024-a 49 percent increase. At the same time, the share of activity attributed to the ten largest groups fell by 25 percent, suggesting that smaller operators were taking more of the market.

Black Kite tracked 7,551 publicly disclosed victims between April 2025 and March 2026, 24.9 percent more than in its previous reporting period. It counted 61 new groups during those 12 months-more than one per week-and said the number of active groups had reached 146 by June 2026, more than double its 2023 count.

Emsisoft, using two independent leak-site datasets, found that the number of claimed victims in the first half of the year had more than doubled between 2023 and 2026, from just over 2,000 to well over 4,500.

These numbers should not be blended into one grand total. Some researchers count brands, some count active leak sites and some count distinct criminal clusters. Victim totals are often based on attacker claims.

In July, for example, Comparitech logged 799 confirmed and unconfirmed attacks, but only 51 had been publicly confirmed by the affected entities. The gap exists partly because companies may disclose later or not at all-but also because criminals lie.

The defensible conclusion is narrower and stronger: there are far more extortion brands, more public victim claims and more actor churn than there were only a few years ago.

The Old Cartel Model Did Not Disappear. It Fractured.

For years, the ransomware business was dominated by a few recognizable franchises. LockBit, ALPHV/BlackCat and Conti supplied the malware, payment infrastructure, leak sites and brand recognition. Affiliates supplied the intrusions and split the ransom with the platform operator.

That model created scale, but it also created a single point of failure-and a single party that affiliates had to trust.

Law enforcement exploited the first weakness. In February 2024, the multinational Operation Cronos seized LockBit infrastructure, source code and decryption keys. The operation was designed not only to interrupt attacks but to damage the secrecy and credibility on which the affiliate program depended.

The U.S. Department of Justice and the U.K. National Crime Agency publicly turned LockBit’s own platform against it.

The criminals exposed the second weakness themselves. ALPHV was accused by one of its affiliates of taking the reported $22 million Change Healthcare payment and disappearing without sharing the proceeds.

The allegation was never judicially established, but the apparent exit scam became an unforgettable lesson in counterparty risk: even a criminal with a multimillion-dollar intrusion could be cheated by the criminal running the platform.

The result was not the death of Ransomware-as-a-Service. It was a loss of confidence in the biggest franchises. Experienced affiliates began asking why they should surrender control of a victim, a negotiation and a payment to a brand that could be seized, hacked or simply steal from them.

That is how a cartel becomes a diaspora.

Four Forces Making It Easier to Launch a Ransomware Brand

1. The Tools Escaped

Leaked ransomware builders and source code turned premium criminal tooling into reusable raw material.

A crew no longer needs to create every component from scratch. It can modify an existing encryptor, copy an established ransom-note format and launch a leak site around it. IBM attributes part of the increase in transient operators to reused leaked tooling, established playbooks and AI-assisted automation.

Global Secret Group is an unusually clean example. Arete says the operation began in June 2026, emerged publicly in July and used leaked LockBit 3.0 code. Its operators paired that inherited technology with Tor negotiation portals and qTox communications, then quickly populated a leak site with alleged victims.

A different tracker dates the name to January, which illustrates another problem: even “first seen” can mean first malware sample, first underground advertisement, first victim or first working leak site.

The barrier to entry has not vanished. Breaking into a company, moving through its network and extracting money without getting caught still requires some skill. But the operator no longer needs to build the entire criminal company before opening for business.

2. Access Became a Product

The ransomware ecosystem increasingly resembles a supply chain.

Infostealers harvest passwords, cookies and session tokens. Initial-access brokers package compromised VPNs, remote-desktop accounts, edge devices and cloud identities. Affiliates buy access instead of earning it.

The public access market can even look quieter while the real trade grows. Group-IB reported that openly advertised access sales fell 27 percent in 2025 as premium credentials moved into private, pre-vetted channels.

In other words, the storefront shrank while the wholesale business went behind closed doors. Group-IB’s 2026 assessment describes a market split between opportunistic public listings and private partnerships for higher-value access.

This specialization lets a small extortion crew concentrate on the last mile: stealing data, applying pressure and collecting payment.

3. Encryption Became Optional

Backups and incident-response planning weakened the old proposition: “Pay us or never see your files again.”

Attackers responded by changing the product. If a victim can restore its systems, the attacker can still threaten patients, employees, customers, regulators and business partners with the data it stole first.

Palo Alto Networks’ 2026 incident-response report describes a shift away from encryption and toward data theft and extortion. Encryption increasingly functions as an optional pressure tactic, not the defining feature of the crime. Group-IB says data exfiltration appeared in 83 percent of the cases it examined.

Dropping encryption has obvious advantages for a small crew. There is no encryptor to develop or safely deploy, no decryptor to support and less risk of accidentally destroying the data that gives the criminal leverage.

The group only needs access, a way to move files and a believable threat to publish them.

4. A Brand Can Now Be Disposable

A leak site can be launched quickly, filled with backdated victims and abandoned when it becomes inconvenient. That makes the economics of a short-lived brand viable-and attribution miserable.

Vect shows how fleeting these projects can be. First observed in January 2026, it advertised Windows, Linux and ESXi builders and experimented with mass affiliate recruitment.

By mid-April, its leak site was offline. Researchers found that its flawed encryption could make files over 128 KB permanently unrecoverable, turning the supposed ransomware into something closer to a wiper. The brand appears to have lasted about one quarter.

Failure is cheap when the operators can return under a different name.

The New Roster: Five Models Worth Watching

The most revealing newcomers are not necessarily the groups with the scariest logos. They are the ones testing different ways to assemble the same criminal supply chain.

The Gentlemen: The Affiliate Becomes the Platform

The Gentlemen is the breakout story of the past year-and the biggest omission from most “new group” lists.

The operation emerged in mid-2025 from ArmCorp, described by researchers as a former Qilin affiliate. Group-IB links the split to an alleged $48,000 unpaid commission.

Whatever the precise origin, this was not a group of beginners learning ransomware in public. It arrived with experienced operators, mature tooling and an understanding of how to attract other affiliates.

By July 7, 2026, Unit 42 reported that The Gentlemen had claimed 580 victims across 77 countries. Its claimed volume in the first half of 2026 was more than six times its total during its active months in 2025.

The rapid rise captures the splintering thesis perfectly: the old platform did not merely lose an affiliate; it produced a competitor.

Global Secret Group: Inherited Code, Instant Infrastructure

Global Secret Group demonstrates the speed advantage created by leaked tooling.

Rather than introduce a clearly original technical stack, it appears to have paired LockBit 3.0-derived code with a polished extortion workflow. By July, Arete ranked it among the month’s most active groups in its incident-response observations.

The group’s claims-including claims involving healthcare organizations-should still be treated as claims. Its importance is not that every number on its leak site is true.

It is that a new brand could move from obscurity to a prominent place on monthly dashboards in weeks.

CRPx0: The Experimental Full Stack

CRPx0 is technically stranger than the average leak-site start-up.

Aryaka Threat Research Labs documented a campaign using a malicious ZIP file disguised as a collection of free OnlyFans accounts. A hidden shortcut and VBScript loader installed a Python-based environment that could support remote control, credential and data theft, cryptocurrency clipboard hijacking and eventual ransomware deployment.

Researchers reported Windows and macOS targeting, with possible Linux support under development.

CRPx0’s operators also made grandiose claims about their victim count and the volume of stolen data. Those numbers remain unverified and should not be repeated as fact.

What is substantiated is the malware chain-and the way it bundles several forms of monetization into one adaptable framework.

ExfilSquad and Helix: Ransomware Without Ransomware

ExfilSquad does not normally encrypt systems. It steals data and threatens to publish it.

In late July, the group claimed breaches involving the U.K. Department for Education and the Police National Legal Database.

PNLD confirmed that the incident exposed names, organizations and email addresses associated with more than 100,000 police and criminal-justice professionals, while saying it found no evidence that passwords or victim, witness or offender information were compromised.

The Department for Education said the affected information was limited to customer-service contact details and clarified that the group’s “600,000” figure referred to lines of data, not people. The Record reported that no encryption was claimed.

Members told The Times that many of them were teenagers living with their parents. That is a self-description, not a verified membership roll, but it fits a broader pattern: socially skilled, identity-focused attackers can now create national-level incidents without developing malware.

Helix follows the same logic with a more focused playbook.

ReliaQuest documented vishing, device-code phishing, MFA abuse and automated SharePoint downloads. In some cases, one compromised identity was used for exfiltration and another for sending the extortion demand through the victim’s own Microsoft Teams and email accounts.

Researchers found substantial overlap with the BlackFile and ShinyHunters ecosystem, but stopped short of confirmed attribution.

Helix is therefore a useful warning against obsessing over the logo. Its durable indicators are the identity abuse and SharePoint exfiltration-not the name on the leak site.

The August Flash Mob: Names First, Evidence Later

The early-August arrivals-L Group, Orova, Dark Project, Storm, Helix, Barracuda, Panzer and Sovcali-show what the bottom of the market looks like in real time.

RansomLook first observed 26 L Group posts on August 6, all published on the same day. Orova appeared with 25 posts, some describing alleged intrusions from earlier dates. Dark Project posted 19 alleged victims, including healthcare, automotive and manufacturing organizations. Storm’s first cluster included banks and industrial companies.

The smaller brands posted between one and five alleged victims.

That burst does not prove that eight competent criminal organizations were born in a week. It could include backfilled claims, rebrands, shared infrastructure and opportunistic data sellers.

It does prove that defenders and investigators suddenly had eight more labels to triage.

That is the operational cost of splintering: even weak or fraudulent brands consume analyst time.

Stop Defending Against Names

The ransomware boom is real, but the most important unit of analysis is no longer the gang. It is the supply chain and the behavior.

A company cannot predict which logo will be attached to its stolen files. It can make the underlying playbook harder to execute:

  • Patch internet-facing firewalls, VPNs, remote-management tools and hypervisors as emergency infrastructure, not ordinary monthly maintenance.

  • Use phishing-resistant MFA for privileged and high-value accounts, restrict device-code authentication and monitor new MFA or device registrations.

  • Revoke exposed sessions and credentials-not only passwords-when infostealer activity is discovered.

  • Detect bulk SharePoint and OneDrive downloads, unusual archive creation, data staging and large outbound transfers before an extortion note appears.

  • Segment and test immutable backups, while assuming that successful restoration will not erase the data-theft problem.

  • Treat MSPs, SaaS platforms and other trusted vendors as part of the attack surface.

  • Build an incident plan that covers encryption, pure data theft, regulatory exposure and direct pressure on customers or employees.

The great ransomware splintering does not mean the giants are gone. The largest groups still control a substantial share of the market.

What changed is everything below them: more entrants, shorter lifespans, cheaper tooling, purchasable access and a growing willingness to extort without encrypting anything.

The logos are multiplying because the criminal business underneath them has become modular. Take down a brand and the developers, access brokers, affiliates, negotiators and stolen credentials do not vanish.

They reconnect under a new name.

Tomorrow, the cat will wake up to another hot dog.


For media inquiries, contact us at contact@databreach.com