TD SYNNEX Newsflash

Ransomware rises 43% in Q2 2026 as AI boosts cybercriminal productivity

Cybersecurity
By TD SYNNEX Newsflash 13th August 2026

Ransomware attacks surged 43% year on year in Q2 2026, with threat actors increasingly using artificial intelligence (AI) to scale operations, personalise attacks and intensify pressure on victims, highlighting a more efficient and targeted threat landscape for organisations and partners to address.


► AI is being used to analyse stolen data and strengthen ransom negotiations

► Data extortion is overtaking encryption as a primary attack method


According to a recent report from US-based cybersecurity consultancy GuidePoint Security, 2,279 victims were recorded during the quarter – a 7% increase compared to Q1. The report also identified a record 91 active ransomware groups operating across 108 countries, highlighting a threat landscape that continues to expand in scale, reach and operational sophistication.

Ransomware rises 43% in Q2 2026 as AI boosts cybercriminal productivity

AI is playing a growing role in this evolution. Threat actors are using large language model (LLMs) to examine exfiltrated data, tailor communications and apply targeted psychological pressure during negotiations – making attacks faster, more scalable and increasingly difficult to counter.

At the same time, the report points to a shift away from traditional encryption-based ransomware towards data extortion. Attackers are increasingly focused on stealing sensitive information and threatening exposure, rather than disrupting systems alone. There is also a rise in supply chain and SaaS-related attacks, alongside the emergence of threat actors focused purely on cloud and data-centric environments.

For organisations, this reinforces the need to understand what sensitive data could be exposed, how it could be weaponised, and where controls can reduce that risk, particularly as data becomes central to modern ransomware tactics.

The Q2 2026 Ransomware and Cyber Threat Insights Report draws on publicly available data, vendor research, incident response cases and intelligence gathered from cybercriminal forums and marketplaces, providing a broad view of how ransomware tactics are evolving in 2026.