Top 10 Active Ransomware Groups to Watch in 2026

Cl0p, BlackCat/ALPHV, RansomHub, Play, Medusa, Hunters International, INC Ransom, BianLian, Rhysida, and REvil are the ten ransomware groups causing the most damage in 2026, operating leak sites, running affiliate networks, and claiming new corporate victims nearly daily. The ransomware landscape this year isn’t as fragmented as it was in 2025: the top 10 ransomware groups accounted for 71% of all victims in Q1 2026 alone, reversing the more scattered activity seen throughout the previous year. That concentration is exactly why tracking this specific list matters more than trying to monitor the long tail of smaller, short-lived operations. Each group below has a distinct playbook, from Cl0p’s mass-exploitation of enterprise software to Medusa’s phishing-driven access, and knowing how they operate is the first step to spotting whether your organization, or a vendor in your supply chain, has already been named on a leak site.
What Makes a Ransomware Group “Active” in 2026
A ransomware group is considered active when it’s currently posting new victims to a public leak site, maintaining working negotiation infrastructure, and has claimed at least one confirmed attack within the past 90 days; dormant leak sites and rebranded shells don’t count. That distinction matters because the ransomware ecosystem now churns faster than most security teams can track manually: 61 new ransomware groups entered the market between April 2025 and March 2026, averaging more than one new brand per week, while older groups quietly go dark, get seized by law enforcement, or rebrand under a new name. A group’s name recognition from a year or two ago doesn’t guarantee it’s still operating, which is why “active” must be verified against current leak-site behavior, not reputation.
How DeXpose Tracks Active Ransomware Operations
DeXpose classifies a group as active by continuously monitoring dark web leak sites, ransomware-dedicated forums, and Telegram channels for new victim postings, infrastructure changes, and negotiation activity, then cross-referencing those signals against known group TTPs and prior claims. This is the same monitoring layer that powers DeXpose’s Dark Web Monitoring service and Free Darkweb Report; when a group listed here claims a new victim, that activity is what gets flagged, not a static profile written once and left unchanged. Because leak sites go up, get seized, and reappear under mirrored .onion addresses constantly, real-time tracking is the only reliable way to tell a currently operating group from one that’s already been dismantled.
Ransomware-as-a-Service (RaaS) vs. Independent Groups
Most of the groups on this list- RansomHub, Play, Medusa, BianLian- operate as Ransomware-as-a-Service (RaaS): a core team builds and maintains the encryption payload, leak site, and negotiation infrastructure, then leases access to affiliates who carry out the actual intrusions in exchange for a cut of each ransom, typically 70–90% going to the affiliate. This model lets RaaS groups scale victim counts quickly and keeps takedowns from stopping activity for long; arresting or sanctioning core operators doesn’t remove affiliates, who simply move to a competing RaaS brand within weeks. A smaller number of groups, like Cl0p, operate closer to a closed, independent model: a single crew handles exploitation, negotiation, and extortion end-to-end, which gives them tighter operational security but caps how many attacks they can run in parallel compared to an affiliate-driven RaaS operation.
1. Cl0p Ransomware Group
Cl0p (also written Clop) is a Russia-speaking ransomware and data-extortion group best known for exploiting zero-day vulnerabilities in widely used enterprise file-transfer and business software to breach dozens of organizations in a single campaign, rather than targeting companies one at a time. The cybercrime collective tracked as TA505/FIN11 has become one of the most financially successful ransomware brands on record: the group has extorted more than $500 million in payments and compromised more than 11,000 organizations worldwide since emerging in February 2019.

Cl0p’s Attack History: MOVEit, GoAnywhere, Cleo, Oracle EBS
Cl0p’s signature move is mass exploitation of enterprise software rather than individual phishing-driven intrusions, and its track record shows the pattern repeating on a roughly annual cycle. Its highest-impact campaign to date exploited the MOVEit Transfer vulnerability in 2023, affecting more than 2,700 organizations globally and remaining one of the largest single-vulnerability breach events ever recorded. The group followed that with exploitation of GoAnywhere MFT, then Cleo’s managed file transfer tools, and most recently a 2025 campaign against Oracle E-Business Suite that has impacted over 100 companies to date, including Harvard University, Logitech, and The Washington Post. Each campaign follows the same structure: identify a platform used by thousands of enterprises, weaponize a fresh vulnerability, quietly exfiltrate data for weeks, then publicly extort victims once the data theft is complete.
Cl0p Leak Site and Known IOCs
Cl0p operates a dark web leak site, historically branded “CL0P^_-LEAKS”, where it names organizations that haven’t paid and publishes samples of stolen data to pressure them into paying a ransom. Consistent with its past campaigns, Cl0p did not immediately list any Oracle EBS victims from the 2025 wave, since it typically delays public naming until negotiations stall. Known indicators of compromise associated with Cl0p campaigns include exploitation of public-facing application vulnerabilities (MITRE ATT&CK T1190), specific C2 infrastructure tied to each campaign, and AES-based encryption payloads in the group’s earlier ransomware-deployment operations, though its more recent campaigns have shifted toward pure data theft and extortion without deploying encryption at all.
Is Cl0p Linked to TA505?
Yes, Cl0p is operated by TA505, a financially motivated, Russian-speaking cybercrime group active since at least 2014 and tracked under the aliases FIN11, Graceful Spider, and Evil Corp-adjacent designations, depending on the research firm. The Canadian Center for Cyber Security assesses TA505 as almost certainly a financially motivated, Russian-speaking ransomware-as-a-service group very likely based in a CIS country. Attribution between TA505 and its FIN11 subset is genuinely contested among researchers; Mandiant treats FIN11 as a related but distinct cluster with its own tactics, while the FBI and CISA have publicly stated that Clop and TA505 are the same. For practical monitoring, you can treat the two names as referring to the same operational threat.
One accuracy flag before the copy: BlackCat/ALPHV is not currently active; it collapsed in a March 2024 exit scam, and as of mid-2026 there’s no verified evidence the original RaaS resumed. I’ve written the section honestly around that (it stays on a “groups to know” list because of its influence and affiliate legacy, not because it’s still operating today) rather than claiming it’s active, since that would be factually wrong and this is the kind of claim that erodes trust in a threat-intel page.
2. BlackCat / ALPHV Ransomware Group
BlackCat, also known as ALPHV or Noberus, was a Russian-speaking ransomware-as-a-service operation that ran from November 2021 until it collapsed in a March 2024 exit scam. It’s included on this list not because it’s still attacking victims today, but because its tooling, affiliates, and playbook still shape the ransomware groups that are active right now. By September 2023, the FBI estimated BlackCat had compromised more than 1,000 victims and collected close to $300 million in ransom payments, making it the second-most prolific ransomware operation of its era after LockBit.

BlackCat’s ESXi and Enterprise Targeting Tactics
BlackCat earned its name from the black-cat icon on its leak site, but its real distinction was technical: it was the first major ransomware family written in Rust. This language choice let its payload evade security tools not yet built to analyze Rust binaries. The group built its ransomware to encrypt Windows, Linux, and VMware ESXi systems in a single operation, which let affiliates take down an organization’s entire virtualized server infrastructure rather than just individual endpoints. BlackCat positioned itself as a professional, well-resourced RaaS platform from the outset, competing directly with LockBit and Conti for top-tier affiliates through 2022 and 2023.
FBI Action and BlackCat’s Current Status in 2026
The Department of Justice disrupted BlackCat’s infrastructure in December 2023, seized its leak site, and released a decryption tool that spared victims an estimated $68 million in ransom payments. The group briefly returned online after the takedown, then executed what became known as ransomware’s most infamous exit scam. After the February 2024 Change Healthcare attack, BlackCat’s operators kept the roughly $22 million ransom payment for themselves. They abandoned the affiliate who carried out the intrusion, torching their reputation on the criminal forums where they recruited. As of mid-2026, there’s no verified evidence the original ALPHV service has resumed under its own name; its former affiliates are scattered to other RaaS platforms, most notably RansomHub, which absorbed much of BlackCat’s affiliate base and became one of the most active groups of 2024–2025 partly as a result.
BlackCat Leak Site and Decryptor Availability
The FBI seized BlackCat’s original leak site as part of the December 2023 disruption, and it is no longer operational under the group’s control. A working decryption tool developed during that law enforcement action was made available to confirmed BlackCat victims through the FBI and international partner agencies, but it only covers encryption keys captured at the time of the takedown; victims hit after that point, including during the Change Healthcare attack, were not covered. Because BlackCat is currently inactive, there’s no live leak site to monitor for new victims; the more relevant monitoring target today is the successor operations, like RansomHub, that inherited its affiliates and techniques.
Good, Everest is actually active in 2026 (no accuracy flag needed here), and the keyword data confirms real search volume around the Fiserv, TSYS, and Iron Mountain claims. One note: there’s no confirmed operational tie between Everest and LockBit; the “lockbit or everest ransomware 2026” query looks like a comparison/confusion search rather than a real affiliation, so I addressed it honestly rather than implying a link not backed by evidence.
3. Everest Ransomware
Everest is a Russian-speaking, financially motivated cybercrime group active since December 2020 that runs three parallel revenue streams: double-extortion ransomware, initial access brokering, and paid corporate insider recruitment, making it more of a hybrid extortion operation than a single-purpose ransomware crew. The group was most active between July and October 2025, and by August 2024 the U.S. Department of Health and Human Services’ HC3 had already attributed 339 claimed victims to Everest across healthcare, government, manufacturing, and financial services.

Everest’s Double-Extortion and Access-Broker Model
Everest’s core ransomware encrypts Windows systems using AES and DES algorithms. It appends the “.everest” extension to affected files. Still, the group has increasingly shifted away from deploying its own encryption in favor of pure data theft and extortion, since selling stolen data or network access carries less operational risk than running a full ransomware deployment. That shift shows up in its second revenue stream: Everest has operated as an initial access broker since November 2021, selling stolen VPN and RDP credentials to other criminal operators on dark web forums, and since October 2023 it has run a paid insider-recruitment program openly soliciting employees at U.S., Canadian, and European companies to sell network access from the inside. Before encryption, the group disables Windows shadow copies and Controlled Folder Access and removes the open-source anti-ransomware tool Raccine, standard defense-evasion steps consistent across its confirmed attacks.
Everest’s Fiserv, TSYS, and Iron Mountain Attacks
Everest’s May 2026 activity illustrates the group’s current targeting pattern: it claimed Fiserv, a major U.S. financial technology provider, on May 3, 2026, and TSYS (Total System Services), a Global Payments payment-processing subsidiary, on May 2, 2026, both financial infrastructure targets claimed within a single week. Neither company has publicly confirmed the scope of data exfiltration. Everest also claimed Iron Mountain in February 2026, alleging theft of 1.4 TB of internal documents and client data. However, Iron Mountain disputed the severity of the claim, stating the incident was limited to a single compromised credential accessing marketing materials on a third-party file-sharing folder, a useful reminder that ransomware leak site claims aren’t always independently verified and can be exaggerated to pressure negotiations.
Is Everest Linked to LockBit? Leak Site and IOCs
No confirmed operational link exists between Everest and LockBit; any overlap in victim sectors or tactics reflects the broader ransomware affiliate ecosystem many groups draw from, not a proven partnership between the two. Everest does have a documented technical connection to the BlackByte ransomware family through shared code, which is a more concrete attribution point than the LockBit comparison. The group maintains a Tor-based leak site where it posts victims and negotiation deadlines, and known IOCs associated with its intrusions include legitimate-but-abused tools like SoftPerfect Network Scanner and ProcDump for credential dumping and reconnaissance, Cobalt Strike for command-and-control, and remote access software such as AnyDesk, Splashtop, and Atera used to maintain persistence and exfiltrate data after initial compromise.
One important accuracy flag before the copy: I can’t substantiate a Play–Ragnar Locker connection. The keyword data shows people searching for it. Still, the actual documented ties researchers have published are to Hive, Nokoyawa, and Quantum (via TTP overlap and shared infrastructure, plus the ShadowSyndicate affiliate cluster), not Ragnar Locker, which is a separate, now-dismantled group with no confirmed link to Play in any source I can find. Rather than invent a connection to match the heading, I’ve written the section around the real one, worth checking whether “Ragnar Locker” was a mix-up with “Ragnar” as a keyword artifact, or if you have a specific source in mind for that link; happy to revisit if so.
4. Play Ransomware (Playcrypt)
Play, also known as Playcrypt for the “.play” extension it appends to encrypted files, is a ransomware-as-a-service operation that’s been active since June 2022 and remains one of the more consistently prolific groups in 2026, with confirmed attacks across 45 countries and a target list weighted toward manufacturing and professional services. A joint FBI, CISA, and ASD advisory had already attributed roughly 300 victim organizations to Play by October 2023, and the group has continued adding new victims steadily since, making it one of the longer-running RaaS operations still active today.

Play’s Low-Profile Operating Style
Unlike groups that court media attention or post aggressive countdown timers on their leak sites, Play has built a reputation for operating quietly and avoiding the kind of high-profile law enforcement crackdowns that have taken down flashier operations. Part of that comes from its technical approach: Play uses intermittent encryption, which encrypts files in alternating chunks rather than in full, a method designed specifically to slip past security tools that look for the complete file-modification patterns typical of standard ransomware. The group also favors attacking managed service providers and using compromised security vendor access as an entry point, a tactic that lets intrusions initially look like legitimate administrative activity rather than an attack in progress.
Play’s Documented Ransomware Connections
Security researchers, including Trend Micro, have found that Play’s attack playbook closely mirrors that of Hive and Nokoyawa; the similarities extend to shared file names, file paths, and overall attack-chain structure, strong enough that researchers assess Play and Nokoyawa are likely operated by overlapping personnel. Play also shares staging infrastructure with the Quantum RaaS group, and its affiliate base overlaps with ShadowSyndicate, a threat actor known for working across at least seven different ransomware families including Play, BlackCat, and Cl0p. One notable technical distinction from its Hive and Nokoyawa lineage is Play’s use of AdFind, a command-line Active Directory query tool used for network discovery that neither related group relies on.
Play Ransomware TTPs and ESXi Targeting
Play expanded its reach significantly in July 2024 with a Linux variant built specifically to target VMware ESXi virtual machine environments, letting affiliates take down an organization’s entire virtualized infrastructure in one attack rather than individual endpoints. Its more recent tooling includes EDR-killer drivers deployed ahead of Active Directory reconnaissance and credential-access techniques like HandleKatz and Nanodump used for stealthy LSASS memory access, both aimed at disabling or evading endpoint detection before encryption begins. Play’s targeting data shows a clear sector concentration: manufacturing and professional services account for the largest share of its victims, with the United States representing by far the most-targeted country, followed by Canada, the UK, Germany, and the Netherlands.
One important 2026 development worth flagging: Storm-1175 appears to be moving away from Medusa. As of August 2026, Microsoft reported Storm-1175 deploying a new, separate ransomware strain called StormEncryptor rather than Medusa, its first activity using that new payload. I’ve noted this in the copy since a “top groups to know” page should reflect that the Medusa-Storm-1175 relationship may be shifting, not static.
5. Medusa Ransomware
Medusa is a ransomware-as-a-service platform that has operated since June 2021 and has become one of the most aggressive groups targeting critical infrastructure, with confirmed victims spanning healthcare, education, legal, insurance, technology, and manufacturing sectors. A joint CISA, FBI, and HHS advisory updated in August 2026 puts the confirmed victim count at more than 500 organizations, up from roughly 300 documented as of early 2025, nearly doubling in about a year, and making it one of the fastest-growing ransomware operations tracked by U.S. authorities.

Storm-1175 and Medusa’s Phishing Campaigns
Storm-1175, a China-based, financially motivated threat actor Microsoft has tracked since at least mid-2024, became one of Medusa’s most active affiliates, known for exploiting newly disclosed vulnerabilities within 24 hours of public release and sometimes up to a week before disclosure. Beyond exploiting software flaws in tools like Fortra’s GoAnywhere MFT, SmarterTools SmarterMail, and Ivanti Connect Secure, Storm-1175 has used credential phishing to gain footholds, then moved from initial access to full network encryption in under 24 hours in some documented cases. As of August 2026, however, Microsoft observed Storm-1175 deploying a new ransomware strain of its own, StormEncryptor, rather than Medusa, a shift worth watching, since it may signal the affiliate branching out from the Medusa platform rather than remaining exclusively tied to it.
Medusa’s Country of Origin and Attribution
There’s no single confirmed nation-state origin for Medusa, because its RaaS structure means the platform is built and maintained independently of whichever affiliates are actively deploying it at a given time. That affiliate roster has included groups with very different backgrounds: Storm-1175 is assessed as China-based, while separate reporting identified the North Korean state-linked group Lazarus deploying Medusa against U.S. healthcare and nonprofit targets in February 2026. This mix of Chinese, North Korean, and other affiliates using the same ransomware platform shows how mature the RaaS model has become; the brand persists and grows regardless of which actor is behind any individual attack, a pattern shared with other affiliate-driven platforms like DragonForce.
Medusa Leak Site and Known Variants
Medusa runs a Tor-based leak site where it publishes stolen data under a countdown timer as part of its double-extortion model, and researchers have documented at least one case of triple extortion, where a second, unrelated actor re-extorted a victim that had already negotiated and paid the original ransom. One important distinction for anyone monitoring this threat: the FBI has explicitly clarified that Medusa ransomware is unrelated to two similarly-named threats, the MedusaLocker ransomware family and the Medusa Android banking trojan, despite the shared name causing regular confusion in incident reports and open-source research.
6. Hunters International
Hunters International was a ransomware-as-a-service operation widely suspected to be a rebrand of the dismantled Hive ransomware gang, and it officially shut down on July 4, 2025, after roughly two years of activity. It earns a spot on this list because its successor operation, World Leaks, remains active and its victim data is still working its way through breach notifications in 2026. Comparitech researchers confirmed 55 successful attacks by the group, with another 199 claimed but unverified, compromising at least 3.25 million personal records, nearly 2.9 million of them from just 19 hospitals and clinics, making healthcare the hardest-hit sector by a wide margin.

Hunters International’s 2025–2026 Shutdown/Closure
Hunters International announced its shutdown directly, stating the decision followed “careful consideration” of recent developments, and offered free decryption keys to any victim that hadn’t yet paid a ransom. However, researchers were skeptical the gesture mattered much, since the group hadn’t claimed a new victim since late May 2025 and most affected organizations had likely already restored their systems by other means. The shutdown wasn’t so much a retirement as a rebrand: threat intelligence firm Group-IB had already reported in April 2025 that the group was transitioning to a new, encryption-free extortion operation called World Leaks, which had launched in January 2025 and claimed 33 attacks by the time Hunters International’s closure was announced. In a further twist, some Hunters International operators reportedly signaled an intent to resume file-encryption attacks after finding World Leaks’ new tooling too buggy, splitting the group’s remaining members between the two operating models rather than a clean transition.
What Happened to Hunters International’s Victims
Victims who hadn’t paid by the July 2025 shutdown were offered free decryptors. However, the practical impact was limited since ransomware victims typically restore from backups or pay within weeks of an attack rather than waiting months for a goodwill gesture. Organizations previously named on Hunters International’s leak site, including the London subsidiary of ICBC, AutoCanada, and Tata Technologies, remain part of the historical breach record, even though the original leak site no longer actively adds new victims under that name. Anyone tracking exposure tied to this group in 2026 needs to monitor both identities: Hunters International for legacy incidents from 2023–2025, and World Leaks for current activity, since the same infrastructure patterns, negotiation portal architecture, and victim-notification methods connect the two operations despite the rebrand.
7. INC Ransom
INC Ransom is a ransomware-as-a-service operation that emerged in mid-2023 and has grown into one of the most prolific active ransomware groups of 2026, having claimed more than 900 victims on its leak site as of August 2026, including 33 in the preceding 30 days alone. Much of that growth came from opportunity rather than innovation: INC absorbed a significant share of affiliates displaced by the disruption of LockBit and the collapse of BlackCat/ALPHV, and by Q1 2026 it ranked as the fourth most active ransomware group globally, behind only Qilin, Akira, and The Gentlemen.

INC Ransom’s Targeting Patterns
INC’s top five targeted sectors in 2026 are legal services, manufacturing, technology, healthcare, and construction, with the United States accounting for more than 65% of all listed victims and a long tail of activity in Australia, Canada, Germany, and Taiwan. The group has shown a particular pattern of targeting organizations where operational downtime creates strong financial pressure to pay; healthcare providers running active patient care and law firms managing time-sensitive, privileged case materials are both recurring targets for that reason. That focus intensified sharply in early 2026: INC claimed ten law firms and legal services organizations within a single 48-hour period, a pace unusual even for a prolific RaaS operation and one researchers suspect points to a shared upstream compromise, such as a breach at a common legal technology or managed services vendor, rather than ten unrelated intrusions. Notably, INC’s affiliate program appears to avoid targeting organizations within the Commonwealth of Independent States explicitly, a pattern consistent with many Eastern European-linked ransomware operations and one of the stronger (if indirect) attribution signals available for the group.
INC Ransom Leak Site and Decryptor Status
INC Ransom maintains a Tor-based leak site where affiliates publish stolen data from organizations that decline to pay, consistent with its double-extortion model of encrypting systems while separately using stolen data as leverage. No publicly available free decryptor exists for INC Ransom victims, and the group has actively worked to keep it that way: both its Windows and Linux/ESXi encryptors have been rewritten in Rust, a language choice that improves cross-platform compatibility and deliberately makes reverse engineering and decryptor development significantly harder for security researchers. One additional wrinkle worth tracking is Lynx, a ransomware variant that emerged in mid-2024 with roughly 48% overall code similarity to INC and up to 70% similarity in shared functions, strong enough overlap that researchers consider Lynx a likely successor or closely related offshoot of the INC codebase, meaning organizations monitoring for INC-linked risk should watch Lynx activity as part of the same threat picture.
8. BianLian
BianLian is a data-extortion cybercriminal group, assessed by the FBI as likely Russia-based, that abandoned ransomware encryption entirely in favor of pure data-theft extortion, a shift confirmed in a joint CISA, FBI, and Australian Cyber Security Center advisory. Active since June 2022, the group has affected organizations across multiple U.S. critical infrastructure sectors and listed 154 victims on its dark web extortion portal in a single recent year, with most targets being small to mid-sized organizations alongside occasional high-profile breaches like Air Canada and Boston Children’s Health Physicians.

BianLian’s Country of Origin and Attribution
The FBI assesses BianLian as likely based in Russia, with multiple Russia-based affiliates, though the group has deliberately worked to complicate that attribution. Investigating agencies specifically flagged that BianLian, like several other ransomware operations, chose a foreign-language-sounding name almost certainly to misattribute its location and nationality, a pattern common among Russia-based groups seeking to obscure their true origin from investigators and victims alike. That naming strategy hasn’t stopped joint U.S. and Australian law enforcement from directly attributing the group’s infrastructure and affiliate network to Russia in their most recent advisory updates.
BianLian’s Shift Away from Encryption to Pure Extortion
BianLian originally ran a standard double-extortion model, encrypting victim systems after exfiltrating their data, but that changed once a free decryptor for BianLian’s ransomware became publicly available in January 2023; encryption stopped being useful leverage the moment victims had a way around it. The group shifted primarily to exfiltration-based extortion soon after that decryptor’s release, and by January 2024 had abandoned file encryption exclusively, relying entirely on stolen data and the threat of public exposure to pressure payment. This mirrors a broader trend across the ransomware ecosystem: data exfiltration now drives the overwhelming majority of extortion activity industry-wide, since stolen data gives attackers more leverage points, direct extortion of the victim, and separately of anyone whose personal data was exposed, than encryption alone ever provided. BianLian backs that pressure with unusually aggressive tactics beyond the leak site itself, including printing ransom notes directly to printers on a compromised network and making threatening phone calls to employees at breached organizations.
9. Rhysida
Rhysida is a ransomware-as-a-service operation that emerged in May 2023 and remains active in 2026, having named 296 victims on its leak site as of early September 2026, including 8 in the previous 30 days alone, a steady, if modest, pace compared to higher-volume operations like LockBit or Akira. The group markets itself unusually for a ransomware operation, presenting as a “cybersecurity team” that claims to help victims identify security weaknesses, a framing researchers view as a thin justification for standard double-extortion attacks rather than any genuine security service.

Rhysida’s Leak Site and Recent Decryptor Release
Rhysida runs a Tor-based leak site where it posts PDF ransom notes and threatens to publicly distribute exfiltrated data unless victims pay in Bitcoin, with demands historically ranging from a few hundred thousand euros to several million depending on the target. Victims caught by Rhysida got a genuine reprieve in early 2024: security researchers identified a flaw in the random number generator Rhysida’s encryption relied on, which made it possible to reconstruct encryption keys and release a free decryptor for affected healthcare organizations and other victims without paying a ransom. Ransomware groups sometimes patch these flaws once a decryptor becomes public, so the free decryptor’s effectiveness against more recent Rhysida variants isn’t guaranteed; victims should verify against current builds rather than assume blanket coverage.
Rhysida’s Sector Targeting Patterns
Since it emerged, Rhysida’s primary targets have consistently been education, government, manufacturing, information technology, and managed service provider organizations, with education accounting for the largest share of identifiable victims (56 organizations), followed by healthcare at 41. The group expanded into healthcare more deliberately in mid-2023, a shift researchers attribute to the sector’s high sensitivity to downtime and the strong pressure that creates to pay quickly rather than risk patient care disruption, a pattern that culminated in an attack on Prospect Medical Holdings that caused a system-wide outage across 16 hospitals and more than 160 clinics in the U.S. Open-source research has also identified tactical similarities between Rhysida and the previously disrupted Vice Society group, suggesting at least some operational or personnel overlap. However, this remains an assessed connection, not a confirmed one.
10. REvil / Sodinokibi
REvil, also known as Sodinokibi, was one of the most damaging ransomware-as-a-service operations in history before Russian authorities dismantled its core infrastructure in January 2022; it closes out this list not as a currently operating threat, but as the group whose business model, affiliate structure, and eventual takedown still shape how today’s active groups operate and get pursued by law enforcement. At its peak in 2021, REvil’s victims ranged from a U.S. nuclear weapons contractor to the managed service provider Kaseya, whose July 2021 breach cascaded ransomware to an estimated 1,500 downstream businesses in a single supply-chain attack.

REvil’s Russian Origin and Law Enforcement Arrests
REvil operated as a Russian-speaking ransomware-as-a-service group, first discovered in 2019, where its developers built and maintained the malware while affiliates carried out intrusions in exchange for a cut of each ransom. U.S. authorities took it down at the request of Russia’s Federal Security Service (FSB): in January 2022, the FSB arrested 14 individuals suspected of REvil membership across five cities, acting on intelligence shared by U.S. law enforcement, including the identity of the group’s alleged ringleader. Separately, U.S. authorities arrested REvil affiliates Yaroslav Vasinskyi and Yevgeniy Polyanin, tying Vasinskyi directly to the Kaseya attack and seizing $6.1 million in ransomware-linked funds, one of the more concrete cross-border enforcement wins against any major ransomware operation to date.
REvil’s Legacy and Rebrand Rumors
REvil’s brand attempted a brief resurgence in April 2022, when its old leak site came back online with a mix of new and old victim listings. Still, threat intelligence firms including Palo Alto Networks’ Unit 42 and Cisco Talos couldn’t confirm this represented a legitimate operational return rather than a reused name or a law enforcement-monitored honeypot. What’s better documented is where REvil’s people and methods went next: several REvil-linked affiliates are believed to have moved on to other active RaaS platforms after the brand’s reputation was damaged by repeated law enforcement attention, and a suspected spinoff calling itself “Ransom Cartel” emerged shortly after the arrests using tooling with notable similarities to REvil’s original codebase. That pattern, a dismantled group’s affiliates and techniques resurfacing under new names, is the same one that shaped BlackCat’s transition into RansomHub and RansomHub’s absorption into DragonForce, making REvil less a currently active threat and more the founding case study for how the modern ransomware ecosystem regenerates itself after a takedown.
How to Check If Your Organization Is a Named Victim
The fastest way to check whether your organization has been named by one of these ransomware groups is to search current leak site listings and dark web monitoring feeds directly, rather than waiting for a breach notification; by the time a formal notification arrives, a group has often already had the data for weeks. Every group covered above maintains (or maintained) a leak site where claimed victims are posted publicly, which means this information is technically accessible, but checking it safely and interpreting what you find both require some care.
Monitoring Ransomware Leak Sites Safely
Visiting a ransomware group’s leak site directly is not recommended. These sites live on the Tor network, require specialized browsing precautions to access safely, and expose anyone who visits to security risks and the possibility of law enforcement scrutiny, depending on jurisdiction. Beyond the access risk, leak site claims aren’t always reliable; as the Everest-Iron Mountain incident earlier in this guide shows, groups routinely exaggerate the scope or sensitivity of what they’ve stolen to pressure faster payment, so a listing alone doesn’t confirm the extent of a breach. A safer approach is to use a monitoring platform that ingests and verifies leak-site activity across dozens of active and historical groups, rather than checking each group’s site manually.
How DeXpose’s Dark Web Monitoring Flags Group Claims Early
DeXpose’s Dark Web Monitoring service continuously tracks leak site postings, negotiation activity, and dark web forum chatter across the ransomware groups covered in this guide, flagging new claims against your organization or your vendors as they appear rather than after they’ve already circulated publicly. For a fast, no-cost first check, the Free Darkweb Report scans dark web markets, malware logs, and public breach data for your organization’s exposure in minutes, and the Email Data Breach Scan checks whether specific company email addresses have already surfaced in a breach. Given how many groups on this list- RansomHub, BlackCat, and Everest among them- sell or resell stolen access rather than acting alone, monitoring needs to cover initial access broker activity as well as leak site claims; a named victim on a leak site is often the last stage of a compromise that started weeks earlier through a credential sale most organizations never see.
Ransomware Group Comparison Table (2026 Snapshot)
Of the ten groups covered in this guide, only seven maintain a currently active leak site in 2026; BlackCat, RansomHub-era tools aside, REvil, and the original Hunters International brand are all defunct or absorbed into successor operations, which is exactly the kind of distinction a side-by-side comparison makes clear at a glance.
RaaS Model vs. Closed Group
Most groups on this list run a ransomware-as-a-service model, where a core team builds the malware and leak site infrastructure, then leases access to affiliates who carry out intrusions for a cut of each ransom. This is how Play, Medusa, INC Ransom, and Rhysida all operate, and it’s the structural reason RaaS groups can scale victim counts faster than closed operations. Cl0p and BianLian are the clearer exceptions, running tighter, closed structures where a single crew handles the full attack chain rather than distributing it across affiliates; Everest sits in between, running its own ransomware while separately selling stolen network access as a distinct revenue stream. The practical takeaway for monitoring purposes: RaaS groups are harder to fully dismantle because taking down the core operators doesn’t remove the affiliates, who move to a competing platform. In contrast, closed groups tend to disappear more completely when their core team is disrupted.
Primary Targeting Sector by Group
Healthcare shows up as a target across more groups on this list than any other single sector; Medusa, BlackCat historically, Hunters International, and Rhysida have all concentrated significant attack volume there, largely because hospitals face intense pressure to restore operations quickly and are statistically more likely to pay to avoid patient-care disruption. Manufacturing and professional/legal services form the next most common cluster, driven by Play and INC Ransom, respectively. At the same time, Cl0p stands apart by not really targeting a sector at all; its mass-exploitation approach hits whichever industries happen to run the enterprise software it’s currently exploiting, which is why its victim list spans everything from universities to airlines in a single campaign.
Leak Site Status (Active / Seized / Shut Down)
Leak site status is the single fastest way to tell whether a group is a live monitoring priority or a historical reference point: seven of the ten groups covered here have an active leak site as of 2026, while BlackCat’s was seized by the FBI in December 2023, REvil’s was dismantled following the 2022 FSB arrests, and Hunters International’s original site went dark in July 2025 when the group rebranded as World Leaks. That status can change quickly and without warning; RansomHub’s leak site, for example, went offline in March 2025 with no explanation after barely a year of high-volume activity, which is why leak site status needs to be checked against current data rather than treated as a fixed fact once documented.
Frequently Asked Questions (FAQ)
Are all ten groups in this guide still actively attacking organizations?
No, three of the ten (BlackCat, RansomHub-derived tools aside, and REvil) are currently defunct or dismantled. They’re included because their tools, affiliates, and takedowns still influence the groups active today.
How can I tell if a ransomware group’s leak site claim about my organization is accurate?
Leak site postings aren’t independently verified and are sometimes exaggerated to pressure faster payment. Treat any claim as unconfirmed until your own investigation, or a monitoring service, corroborates what was actually accessed.
Is it safe to check a ransomware group’s leak site myself?
It’s not recommended. These sites run on the Tor network and carry both security and legal exposure risks depending on your jurisdiction, so a monitoring platform that already tracks this activity is the safer route.
Why do so many ransomware groups target healthcare organizations?
Hospitals and clinics face intense pressure to restore systems quickly to protect patient care, which has historically made them more likely to pay a ransom quickly rather than risk prolonged downtime.
What happens to a ransomware group’s victims after it shuts down?
Some groups release free decryptors when they shut down, though many victims have already recovered by other means. The bigger risk is that the same operators often resurface under a new name, so monitoring shouldn’t stop just because a brand goes dark.
Does paying a ransom guarantee my data won’t be leaked?
No. Law enforcement agencies, including the FBI and CISA, consistently advise against paying, since payment doesn’t guarantee data deletion or recovery and can encourage further targeting.


