May 2026 Ransomware Report: 646 Victims, 61 Active Groups
Originally reported viaBreachsense Ransomware Tracker — May 2026 Monthly ReportBreachsense's ransomware leak site monitoring recorded 646 confirmed victims in May 2026, a 22% increase over April's 529 and the highest monthly figure of 2026. Sixty-one distinct ransomware groups claimed victims — a record for group diversity, reflecting continued fragmentation of the ransomware-as-a-service ecosystem following the disruption of major operations in late 2025.
Most active groups: May 2026
RansomHub led by a significant margin with 94 confirmed victims — its highest monthly count since its emergence. Cl0p returned to the top five with 41 victims, exploiting a newly discovered zero-day in a managed file transfer product. Qilin claimed 38 victims concentrated in healthcare and education. LockBit 4.0 — the successor infrastructure to the disrupted LockBit 3.0 — posted 31 victims in only its second full month of operation.
Sector and geography breakdown
Manufacturing led all sectors with 112 victims (17%), followed by healthcare (98 victims, 15%) and professional services (87 victims, 13%). The United States accounted for 38% of victims — consistent with prior months. The UK (9%), Germany (7%), and Canada (6%) round out the top five geographies. Notable is a 67% increase in Latin American victims versus April, attributed primarily to Cl0p's expansion of targeting outside its traditional focus areas.
- Monitor Breachsense and similar threat intelligence feeds for your organisation's name and associated domains.
- Treat any infostealer infection — regardless of apparent impact — as a potential ransomware precursor. Reset all credentials on the affected system and any services accessed from it.
- Deploy network segmentation specifically designed to isolate backup infrastructure from production networks.
- Test backup restoration procedures quarterly. Cl0p and RansomHub both target and encrypt backup repositories before deploying the main encryptor.
Stay ahead of the threat curve
Get the latest CVE advisories, threat actor intelligence, and detection engineering posts delivered to your inbox.