Incident Response & Threat Intelligence

GRIT Q3 2026 Ransomware & Cyber Threat Insights Report

Trends and threats from the past quarter, with insights to protect your organization.

Get the latest report from the GuidePoint Research & Intelligence Team (GRIT), which digs into findings from the third quarter of 2026. Dive into insights like these:

  • Ransomware victim volume reached a record high. GRIT recorded 2,760 victims in Q3 2026, up 21% from Q2 2026 and 75% from Q3 2025.
  • The number of threat groups continues to grow. Active ransomware groups numbered 112 in Q3 2026, a 23% quarter-over-quarter increase and a 47% year-over-year increase.
  • Payment rates fell, but average payments increased. Analysis of internal data found that ransomware payment rates fell by more than half year over year, while the average payment among organizations that paid rose 34% and ransomware case volume increased 61%.
  • TheGentlemen narrowly overtook Qilin as the most active threat group. TheGentlemen accounted for 12.9% of observed victims in Q3 2026, compared with 12.6% for Qilin. Together, the two groups claimed about one in four victims.
  • Ransomware targeting is broadening geographically. Victims spanned 115 countries, up from 108 in Q2 2026 and 90 in Q3 2025. The United States remained the most targeted country, accounting for 42% of victims.
  • Manufacturing remains the most impacted industry. Manufacturing continued to lead all industries in observed victim volume, followed by technology and healthcare. Banking and finance returned to the top 10 after dropping out in Q2 2026, driven in part by a sustained social-engineering campaign targeting private equity firms.

Download the report now.

Download Now

FAQs

GRIT analysts track ransomware insights using publicly available resources, vendor threat research and internal incident response case data. The team also collects open-source intelligence from illicit forums and marketplaces.

Payment rates fell from 50% to just under 21%, but the average payment among organizations that paid rose 34% to $321,000. More groups are active and accepting smaller ransoms, which lowers the overall rate without reducing the financial threat.

AI is now orchestrating parts of the intrusion phase for affiliate-tier and access-broker actors. In one observed case, an AI agent achieved remote code execution in under four hours and compromised 11 organizations in 26 seconds.

ShinyHunters attacked Instructure, the parent company of Canvas, in May 2026. Over the following months, six additional education-technology platforms were targeted by independent threat actors using the same approach.

Clop’s PTC Windchill campaign produced zero confirmed ransom payments. A credibility dispute with ShinyHunters further weakened the brand. GRIT assesses that Clop’s operations under their current brand may be approaching end of life.

Security leaders, threat intelligence analysts, incident response teams and risk or compliance teams. Anyone who needs current data to benchmark their organization’s ransomware exposure and prioritize defensive investments.