Most Active Ransomware Groups in 2026 | The Complete Threat Actor Guide

Knowledge Hub
Most Active Ransomware Groups

The most active ransomware groups in 2026 are Qilin, TheGentlemen, DragonForce, Akira, and LockBit. This shifting lineup dominates leak-site postings even as dozens of smaller crews churn in and out each month. Security researchers tracked 707 companies listed on ransomware leak sites in June 2026 alone, spread across 63 distinct groups, and the ecosystem shows no sign of slowing: the top 10 groups accounted for 71% of all victims in Q1 2026, meaning a small cluster of operators drives most of the damage while the rest fight for scraps.

What makes 2026 different isn’t just volume; it’s turnover. Groups that led the rankings in January can vanish by summer, rebrand under a new name, or get quietly overtaken by an affiliate crew nobody had heard of six months earlier. Tracking “the most active ransomware groups” isn’t a one-time lookup; it’s a moving target that changes on a monthly cadence. This guide breaks down who’s active right now, where each group came from, how they operate, and what to do if your industry shows up in their crosshairs.

What Is a Ransomware Group? (RaaS Model Explained)

A ransomware group is an organized criminal operation that develops, deploys, or leases malware to encrypt or steal a victim’s data and then extorts payment in exchange for restoring access or not leaking it publicly. Most groups active today don’t work like a single hacking crew; they function closer to a criminal franchise, with separate teams handling malware development, negotiation, and the actual break-ins. RaaS operations now underpin roughly 75% of global ransomware attacks, which is why understanding the business model matters as much as knowing the group names.

Ransomware-as-a-Service vs. Lone Operators

Ransomware-as-a-Service (RaaS) is a subscription or profit-share arrangement where a core team builds and maintains the encryption malware, then rents it out to independent operators, called affiliates, who carry out the actual attacks. The model mirrors legitimate SaaS businesses, complete with marketing, user reviews, 24/7 support, and dashboards for tracking infections and payments. Lone operators still exist, but they’re increasingly rare: building and maintaining working ransomware, evading detection, and running negotiation infrastructure takes more overhead than most independent criminals can sustain alone, which is why nearly every major name on a leak-site leaderboard, Qilin, LockBit, Akira, Clop, operates on some version of the RaaS model rather than as a single actor.

Affiliates, Developers, and Initial Access Brokers

A RaaS operation splits into three core roles: developers who build and maintain the ransomware, affiliates who execute the actual intrusions and negotiations, and initial access brokers (IABs) who sell already-compromised network access to affiliates as a separate service. Affiliates typically keep 70% to 80% of ransom proceeds, with the developer team taking the remainder, a split generous enough that affiliates now shop between competing RaaS platforms rather than sticking to one, and can defect en masse when a better commission or more reliable infrastructure comes along. That dynamic explains why the ransomware landscape reshuffles so often: an affiliate crew unhappy with one operator’s payout or reliability can rebrand under a new group name within weeks, taking their access and techniques with them.

Most Active Ransomware Groups Right Now (2026)

The most active ransomware groups in 2026 are Qilin, TheGentlemen, DragonForce, LockBit, and Akira, based on victim counts published across dark web leak sites through the first half of the year. Rankings shift monthly, but this core group has consistently occupied the top of the leaderboard even as smaller crews rotate beneath them.

Ransomware Groups

Q1 2026 Activity Rankings

Qilin held the top spot for a third consecutive quarter in Q1 2026, posting 338 victims and maintaining its position as the most prominent ransomware operation on record. TheGentlemen was the quarter’s standout performer, jumping from 40 victims in Q4 2025 to 166 in Q1 2026 to claim third place, while LockBit confirmed its comeback with 163 victims, climbing to fourth after a period of decline following law enforcement action. The concentration at the top is notable: the top 10 groups accounted for 71.1% of all victims posted to data leak sites in Q1 2026, meaning a small cluster of operators now drives the large majority of confirmed ransomware activity while dozens of smaller groups split what’s left.

Who’s Rising, Who’s Gone Quiet

TheGentlemen’s rise has continued past Q1; the group overtook Qilin in June 2026, ending its five-month run at number one, with a new group, DeadLock, entering the leaderboard in second place the same month. DragonForce has also climbed steadily, holding third place year-to-date behind Qilin and TheGentlemen. On the other side, some groups have disappeared as fast as they rose: RansomHub collapsed from 736 victims to zero within twelve months, a reminder that a group’s leak-site volume can evaporate almost overnight following an internal dispute, a law enforcement action, or a mass affiliate defection to a rival platform. The churn is structural, not incidental; the number of active groups climbed from 54 in February to 65 by March, and new names continue entering the ecosystem faster than old ones get shut down.

Tier-1 Threat Actor Profiles

LockBit, Status, Leak Site, Current Activity

LockBit is a Russia-linked ransomware-as-a-service operation that has claimed more victims than any other group in ransomware history, with its leak sites listing more than 2,700 victims over its six-year history despite a major law enforcement takedown in February 2024. The group has struggled to rebuild fully since that disruption; LockBit 4.0 in early 2025 failed to gain traction, while rivals like Qilin pulled affiliates away with better profit-sharing terms, but it isn’t gone. LockBit 5.0 launched a new leak site in November 2025 and has since claimed new victims, confirming a partial comeback even as it sits well behind current leaders like Qilin and TheGentlemen in monthly volume. (DeXpose maintains a dedicated LockBit deep-dive with full TTP and IOC coverage.)

threat Actor Profiles

BlackCat / ALPHV

BlackCat, also tracked as ALPHV or Noberus, was a Russian-speaking ransomware-as-a-service operation that emerged shortly after the BlackMatter and DarkSide operations shut down in 2021, suggesting a regrouping of the same veteran affiliates under a new brand. It became notorious for the February 2024 attack on Change Healthcare, a UnitedHealth Group subsidiary, and for having its infrastructure seized by the FBI in December 2023 as part of a coordinated law enforcement action. Whether the original operation still exists is genuinely unclear: as of mid-2026, available evidence does not confirm that the original ALPHV RaaS has resumed. Former affiliates operating elsewhere is not proof of a verified rebrand. BlackCat is treated today mostly as a historical reference point, the group whose Rust-based malware and triple-extortion tactics shaped how several current top-tier groups operate.

Akira

Akira is a ransomware-as-a-service group that has been active since March 2023 and targets organizations globally across healthcare, manufacturing, and finance. It’s widely assessed to have ties to Russia or the broader post-Soviet region, and researchers have identified code and operational overlaps between Akira and the defunct Conti ransomware ecosystem, suggesting shared developer tooling or affiliates rather than a formal rebrand. Akira has stayed consistently near the top of the leaderboard through 2026, posting roughly 980 victims on its leak site in 2025 alone while outpacing Qilin in total ransom proceeds, taking in over $150 million.

Qilin

Qilin, also known by its earlier name Agenda, is a Russian-speaking ransomware-as-a-service operation that has been active since roughly July 2022, rebranding from Agenda to Qilin in September of that year alongside the release of a more advanced Rust-based ransomware variant. It became the single most dominant group in the ecosystem through 2025 and into 2026, in part because it offers affiliates a notably high revenue share, reported at up to 85% of ransom payments, a structure aggressive enough to pull experienced affiliates away from rival platforms. That strategy paid off at scale: Qilin’s victim count jumped from 250 to 1,358 year over year, a 443% increase, making it responsible for roughly one in five to six disclosed ransomware cases globally before TheGentlemen finally overtook it in mid-2026.

Clop / Cl0p

Clop (also written Cl0p) is a financially motivated group believed to originate from Russian-speaking regions, first identified in 2019, and best known for a fundamentally different playbook than most groups on this list: rather than encrypting networks one at a time, Clop specializes in exploiting zero-day vulnerabilities in file-transfer software to breach hundreds or thousands of victims in a single campaign, as it did with the 2023 MOVEit Transfer exploitation. Clop overtook LockBit to become the most prolific ransomware group by publicly disclosed breaches in the first quarter of 2025, and it frequently skips file encryption entirely, opting for pure data-theft extortion instead.

Play

Play, also called PlayCrypt, is a financially driven double-extortion group first identified in June 2022 that has grown into one of the most active ransomware operations globally, with a particular focus on large enterprises and critical infrastructure. Its country of origin hasn’t been conclusively established, though its early targeting concentrated heavily on government agencies, police networks, and critical infrastructure across Latin America and Europe. Notably, Play has been observed using EDRKillShifter, a defense-evasion tool associated with RansomHub, suggesting overlapping personnel or a cooperative relationship between the two operations rather than Play being a formal RansomHub affiliate.

Medusa

Medusa is a ransomware-as-a-service operation that emerged in 2022 and gained wider notoriety in 2023, distinguished from nearly every other group on this list by its unusual public relations approach: Medusa runs a public Telegram channel, Facebook profile, and X account under the brand “OSINT Without Borders” to pressure victims and publicize the threat. The group’s exact location is unknown. However, evidence suggests it operates out of Russia or an allied state, based on its avoidance of CIS-region targets and Russian-language dark web activity. Medusa has been a top-ten ransomware actor since 2023, with victims including Toyota Financial Services and the Minneapolis Public School District.

RansomHub

RansomHub was a ransomware-as-a-service operation built off the source code of the earlier Knight ransomware, which was put up for sale in February 2024, and it grew fast by outbidding competitors on affiliate terms: RansomHub advertised that affiliates kept 90% of ransom payments, compared to the typical 80% offered elsewhere. That aggressive recruitment pulled in affiliates from multiple other operations, including members associated with Scattered Spider after ALPHV’s disruption. But the group’s rise ended abruptly; RansomHub collapsed from 736 claimed victims to zero within twelve months, and its leak site has been offline since March 31, 2025, with no public explanation for the shutdown.

Black Basta / BlackSuit

Black Basta is a Russian-speaking ransomware-as-a-service operation first spotted in early 2022, known for double-extortion attacks and a closed affiliate structure that avoids advertising on dark web forums, a level of operational discipline that led researchers to suspect ties to the defunct Conti operation. BlackSuit emerged as a related or successor brand using overlapping tooling and tactics. Internal chat leaks gave researchers rare visibility into the group’s structure, revealing connections between Black Basta operators and several other ransomware teams, including Cactus and Rhysida. Both brands have shown reduced public activity through 2026 compared to their 2023–2024 peak.

Interlock

Interlock is a ransomware group that Cisco Talos assesses with low confidence and likely emerged from Rhysida ransomware operators or developers, based on similarities in tactics and in the ransomware encryptor binaries themselves. Tracked internally by researchers as Hive0163, the group uses a large variety of custom malware including NodeSnake, InterlockRAT, and a downloader called JunkFiction. It has been linked to the broader TAG-124 initial-access infrastructure that several other ransomware brands also draw on.

DragonForce

DragonForce is a ransomware-as-a-service operation first observed in August 2023, which launched a formal affiliate program offering an 80% revenue share before rebranding as a self-styled “ransomware cartel” in 2025. That cartel positioning wasn’t just branding; DragonForce has actively tried to absorb other groups’ infrastructure and affiliates, including a contested arrangement with RansomHub. It gained significant public attention for high-profile attacks on UK retailers Marks & Spencer, Co-op, and Harrods, and has remained a consistent top-three group by victim volume through mid-2026.

Everest

Everest is a Russian-speaking ransomware and initial-access-broker operation active since December 2020 that encrypts Windows systems using the .everest file extension. What sets it apart is its business model diversification: beyond deploying ransomware directly, Everest runs a paid corporate-insider recruitment program, paying employees at target organizations for remote access credentials. The group has increasingly shifted toward data-only extortion without encryption, and claimed a breach of Iron Mountain in early 2026, alleging theft of roughly 1.4 TB of internal and client data.

Hunters International

Hunters International was a Russian-speaking ransomware-as-a-service group that launched around October 2023, with evidence suggesting former Hive operators handed over source code as part of its formation. It no longer operates under its original name: Hunters International shut down its ransomware operation in July 2025, released free decryptors to past victims, and pivoted entirely to a new data-extortion-only brand called World Leaks. World Leaks markets itself as eliminating file encryption, instead using custom exfiltration tooling and a journalist-access portal that gives press early access to stolen data, a template several other groups have since copied as encryption-only extortion becomes harder to monetize.

Scattered Spider

Scattered Spider, also tracked as UNC3944 and more recently folded into the identity ShinyHunters, is a hacking group made up largely of teenagers and young adults believed to be based in the United States and the United Kingdom, making it an outlier among the largely Eastern European ransomware ecosystem. Rather than building its own ransomware, the group specializes in social engineering, particularly help-desk impersonation and SIM-swapping, to gain initial access. Partners with established RaaS platforms to monetize it: Scattered Spider affiliates moved to RansomHub after the disruption of ALPHV/BlackCat, having previously been behind high-profile intrusions at MGM Resorts and Caesars Entertainment.

Warlock, Safepay, TheGentlemen, Sinobi, Global Group, World Leaks

This cluster represents the newest wave of ransomware brands to break into the top rankings, and TheGentlemen is by far the most consequential of the group. TheGentlemen formed in mid-2025 after a payment dispute with the Qilin RaaS operation and immediately raised the affiliate revenue share to a 90/10 split, the most generous terms in the ecosystem. Within months it had claimed nearly 300 victims across 66 countries, and by June 2026 it had overtaken Qilin outright to become the most active group tracked on leak sites. Warlock, Safepay, Sinobi, and Global Group are lower-volume but persistent entrants that appear consistently in monthly leak-site tracking, illustrating the broader pattern across this list: the barrier to standing up a new brand is low enough that the roster of “most active” groups keeps turning over even as the total volume of attacks stays high.

Full Reference Table: Other Known Ransomware Groups

Beyond the groups currently dominating leak-site rankings, the ransomware ecosystem includes both retired brands whose code and tactics still influence today’s attacks, and a long tail of smaller, active operations that rarely make headlines but still account for a meaningful share of victims. Understanding both matters for threat modeling: IBM’s X-Force estimates the average lifespan of a ransomware brand before it disappears and reemerges under a new name is just seventeen months, so today’s dormant group is often tomorrow’s rebrand.

Legacy/Dormant Groups

These groups no longer operate under their original names, but their code, tactics, and, in several cases, their own personnel live on inside currently active operations, which is why they’re worth knowing even though their leak sites are gone.

Active Secondary Groups

Below the top-tier names, dozens of smaller ransomware brands post victims to leak sites every month without ever leading the rankings. Individually they account for modest victim counts; collectively they represent a large and growing share of total activity. The number of distinct active groups climbed from 54 in February 2026 to 65 by March, almost entirely driven by this secondary tier. Tracking them matters because today’s low-volume newcomer is frequently tomorrow’s top-five operator.

This list changes month to month; groups appear, go quiet, or rebrand faster than any static reference can track, which is why leak-site monitoring rather than a fixed list is the only reliable way to know who’s actually targeting your sector right now.

Where These Groups Operate From

Most of the ransomware groups active in 2026 are assessed to be Russian-speaking or based in Russia and the broader post-Soviet region. However, formal government attribution is rare, and most groups deliberately obscure their location. A handful of notable exceptions, like Scattered Spider, break that pattern entirely, operating out of English-speaking countries with a completely different demographic profile than the rest of the ecosystem.

Russian-Linked Groups and Attribution Challenges

Attribution in ransomware is rarely conclusive, but researchers rely on a consistent set of signals: code artifacts written in Russian, leak-site language, and a policy of avoiding targets in Commonwealth of Independent States (CIS) countries, a self-imposed restriction common among Russia-linked groups designed to reduce their legal exposure at home. Qilin, LockBit, Akira, Medusa, Everest, and Clop have all been assessed as Russian-speaking operations using this evidence, even though no formal government attribution has been issued for most of them, and criminal leak-site claims are treated as unverified unless independently confirmed. The pattern isn’t universal, though; Akira’s malware notably lacks the safeguard many Russian-linked groups build in to halt execution when a Russian keyboard layout is detected, a deliberate omission researchers believe may be intended to muddy attribution rather than reflect a different origin. Attribution challenges like this are exactly why “country of origin” for groups like BlackCat, Play, and Medusa is officially listed as unknown even when the circumstantial evidence points one direction.

The geographic split matters less for defense purposes than the operating pattern it reveals: CIS-avoidance targeting means organizations headquartered in Russia and neighboring allied states are rarely on any of these groups’ target lists, while the US, UK, Germany, and Western Europe consistently absorb the largest share of claimed victims regardless of which specific group is behind the attack.

Here’s the section:

Common Tactics, Techniques & Procedures (TTPs)

Modern ransomware groups increasingly share the same playbook regardless of brand name: exploit an exposed remote-access service, turn off endpoint defenses, exfiltrate data before encrypting it, and pressure victims through leak-site threats. That convergence is deliberate; tools and techniques get shared, sold, and copied across groups faster than defenders can build detections for each one individually.

MITRE ATT&CK Mapping for Top Groups

Akira’s documented attack chain, mapped by CISA against the MITRE ATT&CK framework, illustrates the pattern most top-tier groups now follow. Akira actors gain initial access primarily by exploiting known CVEs in VPN services that lack multifactor authentication [T1190], along with phishing [T1566] and abuse of valid credentials [T1078]. Once inside, the group relies heavily on legitimate administrative tools rather than custom malware to blend in with normal network activity; credential-scraping tools like Mimikatz and LaZagne facilitate privilege escalation, making detection dependent on behavioral analytics rather than signature matching alone. A Linux variant expanded Akira’s reach to VMware ESXi, Hyper-V, and Nutanix AHV virtual machine disk files, letting the group encrypt the operational core of an enterprise rather than just individual endpoints, a shift several other top-tier groups have since mirrored.

EDR-Killing Tools and Loader Abuse

Turning off endpoint detection and response software before deploying ransomware has become standard practice, and the tools to do it are now shared infrastructure rather than proprietary weapons. EDRKillShifter, originally built by RansomHub, uses the “Bring Your Own Vulnerable Driver” technique, exploiting legitimate but flawed drivers to kill security software, and has since turned up in attacks by Medusa, BianLian, and Play, groups with no formal affiliation to RansomHub itself. That cross-pollination accelerated further in 2025: a newer EDR-killing tool, believed to be an evolution of EDRKillShifter, has been observed in use by at least eight separate ransomware groups, including BlackSuit, Qilin, DragonForce, and Lynx. TheGentlemen has taken this further still, becoming one of the first groups to centrally build and maintain an entire portfolio of EDR-killing tools in-house rather than relying on a single borrowed utility, giving its affiliates a toolkit few rival RaaS platforms can match.

AI-Assisted Negotiation and Recruitment

Ransomware operators have begun folding generative AI directly into the extortion process itself, not just the technical attack chain. Global Group’s affiliate panel features an AI-driven negotiation chatbot that lets non-English-speaking affiliates communicate directly with victims, automating a task that previously required a skilled human negotiator. The chatbot analyzes encrypted sample files to verify the attack succeeded, then automatically initiates ransom demands and adjusts its tone and messaging frequency based on the victim’s profile to maximize psychological pressure, with human operators stepping in only when a negotiation escalates or gets complicated. Threat intelligence firm Halcyon has also reported the first suspected instance of “agentic ransomware” capable of autonomously conducting key stages of an intrusion, alongside AI-generated malware disguised as productivity software to gain initial access. The direction is clear: AI is compressing both the technical and psychological sides of a ransomware attack, reducing how many skilled humans a group needs to run a profitable operation at scale.

Law Enforcement Actions & Group Takedowns

Law enforcement has disrupted several major ransomware operations over the past two years. Still, the industry’s overall victim count keeps climbing regardless; takedowns remove individual brands without denting the broader criminal ecosystem that produces them. That gap between “groups arrested” and “attacks reduced” is the central fact to understand about ransomware enforcement in 2026.

Recent Arrests and Infrastructure Disruptions

The most significant recent action targeted 8Base, one of the largest ransomware affiliate operations: international law enforcement arrested four suspected leaders and seized 27 servers in February 2025, dealing a serious blow to a gang that had targeted organizations primarily in the US and Brazil. The bust extended further into 8Base’s parent operation; Europol and German authorities disrupted over 100 servers tied to the broader Phobos ransomware network in the same coordinated action. Enforcement has also increasingly targeted the infrastructure that supports ransomware rather than the visible gangs themselves: the FBI and an international coalition took down First VPN in 2026, a service the bureau says was used by at least 25 different ransomware gangs to hide their activity, and a separate operation dismantled 127 servers belonging to a bulletproof hosting provider that had hosted tools from both Conti and LockBit. Europol’s Project Compass has also made 30 arrests and identified 179 suspected members of “The Com,” the loosely organized cybercrime network linked to Scattered Spider and several ransomware-adjacent extortion campaigns.

What Happens When a Group Is Taken Down (Rebrands)

Arrests and server seizures rarely end a ransomware brand’s underlying operation; they just force a name change. Security researchers note plainly that ransomware gangs often bounce back from takedowns, even though the process takes time, and the historical pattern bears that out repeatedly: DarkSide shut down after Colonial Pipeline only to resurface weeks later as BlackMatter, which itself dissolved and is widely believed to have reemerged as BlackCat/ALPHV. IBM’s X-Force estimates the average lifespan of a ransomware brand before it disappears and reemerges under a new identity is just seventeen months, a pattern fast enough that law enforcement pressure functions more like a reset button than an off switch. The practical implication for defenders is that a takedown announcement is good news for exactly one brand name; the affiliates, malware code, and infrastructure behind it are very likely still operating under whatever name comes next.

Is Your Industry Being Targeted?

Whether your organization shows up in a ransomware group’s crosshairs usually comes down to industry and exposed attack surface rather than bad luck, and most companies don’t find out they’re a target until a group has already claimed them on a leak site. The groups covered in this guide don’t attack randomly; Qilin, Akira, and Play in particular have shown consistent, sector-specific targeting patterns that make some industries far more likely to appear on next month’s victim list than others.

Manufacturing, healthcare, professional services, and construction have remained the most heavily targeted sectors across 2026, but which specific group is circling depends heavily on your organization’s size, geography, and exposed remote-access infrastructure- the same VPN and RDP weaknesses that Akira, LockBit, and a dozen smaller groups all actively scan for. Static awareness of “the most active ransomware groups” only goes so far; the more useful question is whether your organization’s specific footprint, leaked credentials, exposed subdomains, vendor access points, already matches what these groups are actively hunting for right now.

Check Your Exposure with DeXpose Monitoring

DeXpose’s Dark Web Monitoring tracks the same leak sites, forums, and Telegram channels referenced throughout this guide, giving your security team continuous visibility into whether your organization, employees, or vendors have already surfaced in a ransomware group’s claims or a credential dump feeding one. Paired with Attack Surface Mapping, it identifies exposed assets, unpatched VPNs, exposed RDP, and stale subdomains that groups like Akira and LockBit specifically scan for before an intrusion even begins, so you can close the gap before it becomes a leak-site listing. For an immediate first read on where you stand, DeXpose’s Free Darkweb Report checks your organization against dark web markets, malware logs, and public breach data in minutes, no commitment required- a practical starting point before deciding whether continuous monitoring makes sense for your risk profile.

Frequently Asked Questions (FAQ’s)

Do ransomware groups have physical offices?

Yes, at least some do. Leaked chat logs from the Conti ransomware group revealed the operation held several physical offices in Russia, with dedicated locations for negotiators, testers, offensive teams, sysadmins, and programmers, each managed by its own internal lead. Conti hired staff for call centers and even brought on people who weren’t computer specialists at all. Disturbingly, some employees weren’t aware they were working for a cybercrime operation, believing they’d taken a job at a legitimate ad company instead. Most groups still operate as fully remote, distributed networks with no physical footprint. Still, Conti’s leak proved that at least the more mature RaaS operations can look less like a hacking crew and more like an actual company with office space, HR, and payroll.

How are ransomware groups different from APTs like Lazarus?

Ransomware groups are financially motivated criminal enterprises, while advanced persistent threats (APTs) like Lazarus are state-sponsored actors whose primary objectives are espionage, sabotage, or funding a government program; the ransomware they occasionally deploy is a means to an end rather than the business itself. Lazarus, linked to North Korea, has used ransomware and cryptocurrency theft largely to generate revenue for a sanctioned regime, not to build a scalable criminal franchise the way Qilin or LockBit do. The distinction matters operationally too: RaaS groups compete for affiliates, rebrand under commercial pressure, and can effectively go out of business, while state-sponsored actors persist regardless of law enforcement action because they’re backed by a government rather than a criminal marketplace.

Are BlackCat and ALPHV the same group?

Yes, BlackCat and ALPHV refer to the same ransomware operation, just named differently depending on who’s talking about it. ALPHV is the name the operators use to market the ransomware on cybercrime forums, while BlackCat is the name security researchers commonly use, derived from the black cat icon that appeared on the group’s leak site. The malware itself is also sometimes referred to as Noberus. All three names point to the same Rust-based ransomware family and the same RaaS operation, which is why threat intelligence reports often list them together as “BlackCat/ALPHV” rather than treating them as separate groups.

What happened to LockBit in 2026?

LockBit spent much of 2024 and 2025 struggling to recover from a major law enforcement takedown, but it hasn’t disappeared. LockBit 5.0 launched a new data leak site in November 2025 and has since claimed new victims, with threat intelligence firm Cyble reporting the group has “fully reactivated its public ransomware operations.” The comeback has been shakier than LockBit’s dominant pre-2024 run; rivals like Qilin captured many of the affiliates LockBit lost after its disruption by offering more favorable profit-sharing terms. Still, by Q1 2026, LockBit had climbed back to fourth place globally with 163 posted victims, confirming it remains an active threat even without the outright market dominance it once held.

Free Dark Web Report

Keep reading

No results found.