The Numbers Just Got Worse: What the 2026 Ransomware Surge Means for Your Board
I spent most of last week reading two reports that should be on every board member's desk by Monday morning.
Black Kite's 2026 Ransomware Report, released this week, tracked 7,551 publicly disclosed ransomware victims between April 2025 and March 2026. That's a 24.9% increase over the prior year — and the fourth consecutive annual record. NCC Group's Q2 2026 analysis, published July 22, added another layer: 2,229 attacks in the second quarter alone, with 665 in June. Those aren't projections. Those are confirmed incidents.
But the raw numbers aren't the story. The acceleration is.
The 60% Problem
The first six months of Black Kite's reporting period produced 2,904 victims. The second half surged to 4,647 — a 60% jump. March 2026 closed at 861 victims, the highest single month Black Kite has ever recorded.
That kind of acceleration doesn't happen because attackers suddenly got smarter. It happens because the economics changed. Sixty-one new ransomware groups entered the market during the reporting period — more than one per week. By June 2026, 146 groups were actively operating. The average lifespan of these groups dropped to 4.9 months, down from over a year in 2024.
In my experience, that pattern tells you something important: ransomware has become a low-barrier, high-turnover business. Groups spin up, hit targets, collect what they can, and disappear before law enforcement can respond. The threat isn't a few sophisticated adversaries anymore — it's an industry with a franchise model.
Your Supply Chain Is the Front Door
Here's where it gets worse for executives trying to manage this risk.
The same week NCC Group published its Q2 numbers, researchers at Phoenix Security documented that the first half of 2026 produced 37 supply chain attack campaigns and 497 malicious packages across npm, PyPI, and other developer ecosystems. That's 2.6 times the campaign count and 4.5 times the package volume of the entire previous year. May 2026 alone saw 14 campaigns and 346 packages — more than the four months before it combined.
One of those campaigns, dubbed ViteVenom by Checkmarx, planted seven malicious packages in the npm registry targeting the popular Vite development framework. The packages used a four-tier blockchain-based command-and-control infrastructure spanning Tron, Aptos, and Binance Smart Chain — making the malicious infrastructure nearly impossible to take down through traditional means.
What does this mean for a board member who doesn't manage npm packages? It means that the software your development teams rely on to build your products and internal tools is being weaponized. A single compromised open-source component can cascade through your entire software portfolio before anyone notices. NCC Group flagged the ongoing "Shai-Hulud" supply chain attack waves — campaigns that compromise development tools used across large numbers of businesses, allowing one breach to spread to dozens of downstream victims.
This is exactly the kind of third-party risk I describe in Cyber Risk Is Business Risk. Your organization might have excellent internal controls, but if your vendors, your SaaS platforms, or even your development dependencies are compromised, those controls don't help.
The Three Questions Your Board Should Ask This Week
I keep coming back to the Three Questions framework whenever I see numbers like these. Every board member should be able to answer them:
What can go wrong? Ransomware groups are proliferating faster than at any point in the history of cybercrime. Supply chain attacks are industrializing alongside them. Your organization doesn't need to be directly targeted — a compromised vendor, a poisoned software library, or a breached SaaS platform can pull you into an incident you never saw coming.
How likely is it? Black Kite found that 43.5% of previously-breached organizations still carried a critical unpatched vulnerability when rescanned. Stealer log exposure on those same victims came back 175% higher on rescan. If your organization has been breached before — or if your third-party vendors have — the probability of a repeat incident is measurably higher than it was twelve months ago.
How bad could it be? North America absorbed 44% of all Q2 2026 ransomware attacks. The industrials sector accounted for 30%. Organizations with annual revenue between $50 million and $100 million were the most frequently targeted revenue band. If your company fits any of those profiles, you're in the crosshairs of a market that just posted record numbers for the fourth year running.
What to Do About It
The temptation is to treat these reports as background noise — another quarter, another set of scary numbers. That's precisely the wrong response.
First, ask your CISO for a third-party risk assessment that goes beyond questionnaires. Black Kite's data shows that SaaS platforms, ERP systems, CRM applications, OAuth tokens, and remote access tools are now common attack paths. Your vendor management program needs to account for software supply chain risk, not just whether your law firm has a SOC 2.
Second, pressure-test your incident response plan against the current threat velocity. When new ransomware groups are spinning up weekly and the average group lifespan is under five months, the adversary you planned for six months ago may not exist anymore — but three new ones have taken its place. Your plan needs to be tested against fast-moving, unfamiliar attackers, not just the well-known groups in last year's threat briefing.
Third, revisit your board's cyber risk reporting cadence. If your CISO presents to the board once a quarter, that reporting cycle now spans roughly 2,000 ransomware attacks. The SEC's disclosure rules already treat cyber incidents as material events. Your board shouldn't be learning about shifts in the threat picture from the news.
The ransomware economy isn't slowing down. It's accelerating, fragmenting, and professionalizing all at once. The organizations that survive this environment will be the ones whose leadership treated these numbers as a call to action — not a data point in someone else's report.
