2 min read

Ransomware surge hits US SMBs as gang rivalry intensifies

NordStellar counted 2,581 ransomware attacks in Q2 2026, with US SMBs hit hardest as Qilin and The Gentlemen battled for dominance.

Image: TechRadar

Ransomware attacks climbed to 2,581 in Q2 2026, and US small and medium-sized businesses took the brunt of the damage, according to new data from NordStellar.

After reviewing more than 200 threat actor blogs, NordStellar said Qilin was the most active ransomware group in the quarter with 299 attacks, followed closely by The Gentlemen with 284. DragonForce ranked a distant third with 147 attacks.

The company said the apparent neck-and-neck race hides a shift underneath: between April and June 2026, The Gentlemen increased its activity by 39%, while Qilin’s activity declined compared with Q1.

The heaviest impact fell on US-based SMBs — defined here as companies with up to 200 employees and revenue under $25 million — which suffered 769 attacks in Q2 2026. Other countries followed well behind: Canada (97), Germany (83), and the UK (74).

NordStellar also flagged a sharp rise in attacks on much larger companies. Incidents targeting organizations with revenue above $1 billion rose 74%, increasing from 23 in Q1 to 40 in Q2.

Recommended reading

WordPress bugs are now under attack at scale

“Ransomware actors historically target SMBs because these organizations often lack comprehensive defenses, which can increase the likelihood of a successful attack.”

Vakaris Noreika, cybersecurity expert at NordStellar

Noreika said the recent jump in enterprise targeting stands out and may prove temporary. According to him, the shift is likely tied to competition between leading ransomware gangs, where breaching a major corporation acts as a status symbol inside the cybercriminal underground.

“This recent spike in enterprise targeting is unusual and may be a temporary fluctuation. This shift likely stems from the rivalry between dominant threat actors — a successful hit on a major corporation is a badge of honor that boosts a group’s reputation within the cybercriminal underground.”

Vakaris Noreika, cybersecurity expert at NordStellar
Best antivirus software header
Best antivirus software header
Sophia Reynolds

Security Editor

Sophia unpacks the invisible wars happening on our networks. Covering cybersecurity, privacy legislation, and cryptography, she exposes how our data is weaponized and defended. Before joining for(geeks), she spent years as a penetration tester. She's the reason the rest of the team uses physical security keys.

via TechRadar

// Keep reading