Ransomware Report: VPNs Targeted Amid AI and EDR Threats

Ransomware trends spotlight VPN exploits and EDR bypass

Ransomware attacks are climbing, and the latest ransomware report highlights how VPNs and edge devices are now prime targets. As threat actors leverage new techniques, including AI and sophisticated endpoint attacks, organisations face mounting challenges to defend their networks.

Ransomware surge: VPNs and edge devices in attackers’ sights

The ransomware report from NCC Group reveals a continued increase in global ransomware attacks, marking the fourth consecutive month of year-over-year growth as of June 2026. While the second quarter saw a modest 3 percent rise compared to Q1 2026, the consistent upward trend remains clear. Attackers are focusing on exploiting VPNs and network edge devices to gain initial access, with products from Fortinet, Citrix, and Check Point featuring prominently among targeted systems.

Ransomware groups have shifted their tactics, exploiting network edge vulnerabilities and compromised credentials to infiltrate corporate environments. Akira, Qilin, and The Gentlemen have all been observed using these methods to breach defences. The report highlights that VPNs, once considered a secure remote access solution, are now a significant attack vector, particularly when unpatched or misconfigured. Edge devices from major vendors are being scanned and exploited en masse, making them high-priority targets for cybercriminals.

Affected industries and attack impact

The ransomware report breaks down sector-specific targeting in Q2 2026:

  • Industrials: 30 percent of attacks, the most targeted sector
  • Consumer discretionary: 24 percent
  • Information technology: 11 percent
  • Healthcare: 10 percent, including a severe April attack on Signature Healthcare in Massachusetts that disrupted ambulance services and delayed cancer treatments

Government entities are also under sustained assault. Comparitech reports 89 confirmed and 98 unconfirmed attacks on government agencies in the first half of 2026, with US agencies accounting for 31 percent of those incidents. However, this marks a 23 percent decrease compared to late 2025. Notably, the report identifies sharp increases in attacks on transportation (52 percent), healthcare (35 percent), retail (28 percent), and technology (23 percent) over the past six months.

Threat actors: Qilin, The Gentlemen, and emerging risks

Two ransomware groups, Qilin and The Gentlemen, dominate both the NCC Group and Comparitech rankings for most active threat actors in the first half of 2026. The Gentlemen, reportedly a splinter group from Qilin, even surpassed Qilin in the number of claimed victims on data leak sites in June. Halcyon, a cyber resilience platform vendor, has called The Gentlemen one of the fastest-scaling ransomware threats currently tracked.

Other groups such as Akira, DragonForce, Lockbit, and INC also feature in the top six most active ransomware actors. A notable emerging threat is KryBit, first identified in March 2026. KryBit operates as ransomware-as-a-service, targeting Windows, Linux, VMware ESXi, and NAS devices, signalling growing technical sophistication among new entrants.

  • Top ransomware groups in 2026:
    • Qilin
    • The Gentlemen
    • Akira
    • DragonForce
    • Lockbit
    • INC
    • KryBit (emerging)

Technical developments: EDR killers and AI threats

The ransomware report notes a significant trend: the deployment of “EDR killer” tools by groups like Qilin and The Gentlemen. According to research from Cisco Talos and ESET, these tools are designed to bypass or disable endpoint detection and response (EDR) solutions, allowing ransomware to operate undetected. While such techniques are not new, their increasing use demonstrates the growing sophistication of ransomware operations. Affiliates are now required to develop or obtain their own EDR bypass tools, reflecting a broader technical capability within these groups.

In addition, the report highlights the emergence of autonomous AI agents that can assist in attacks, increasing the speed and scale at which ransomware groups can operate. While details remain limited, the entry of AI into the ransomware ecosystem is a concerning development that may accelerate the evolution of attack techniques.

Attack methodologies observed:

  • Exploitation of unpatched VPNs and edge devices (Fortinet, Citrix, Check Point)
  • Use of stolen credentials for remote access
  • Deployment of EDR killer tools to disable endpoint defences
  • Potential use of AI-driven attack automation

Why this ransomware report matters

This ransomware report underscores how attackers are adapting quickly, targeting the technologies that enable remote and hybrid work. The focus on VPNs and network edge devices means that even organisations with strong endpoint controls are vulnerable if edge defences are neglected. The use of AI and advanced EDR bypass tools further increases the risk, making traditional security strategies less effective.

Actions for organisations

Organisations should prioritise patching and monitoring of VPNs and edge devices, particularly those from Fortinet, Citrix, and Check Point. It is crucial to monitor for EDR tampering and review remote access policies to ensure only authorised users can connect. The findings from this ransomware report highlight the need for vigilance around network edge exposure and endpoint security.

Originally reported by csoonline.com.

Share this bulletin

About the Author

Rob McBride Headshot - CyPro Partner and leading cyber security expert

Rob McBride

Partner

  • CISSP
  • ACA Chartered Accountant
  • MPhil
  • BSc
  • SOC 2
  • ISO 27001

Rob McBride

Rob is a Founding Partner at CyPro and a highly experienced CISO. Beginning his career with a successful tenure at Deloitte, Rob has since amassed a wealth of experience, notably serving as a cyber security advisor to the UK government and spearheading cloud security transformations for several global banks.

At CyPro, Rob leads the managed service business line, working extensively across multiple sectors including telecommunications, technology, higher education, travel, and retail. He is passionate about equipping small and medium-sized businesses (SMBs) with robust cyber security strategies to fuel their growth.

View Profile
Back to Bulletins

Related CyPro Services

  • Managed Detection and Response (MDR)

    Managed Detection and Response (MDR) is an end-to-end managed service designed to help organisations detect, analyse and respond to cyber threats quickly and effectively. It...
    View Service
CyPro Cookie Consent

Hmmm cookies...

Our delicious cookies make your experience smooth and secure.

Privacy PolicyOkay, got it!

We use cookies to enhance your experience, analyse site traffic, and for marketing purposes. For more information on how we handle your personal data, please see our Privacy Policy.

Schedule a Call