Ransomware attacks are climbing, and the latest ransomware report highlights how VPNs and edge devices are now prime targets. As threat actors leverage new techniques, including AI and sophisticated endpoint attacks, organisations face mounting challenges to defend their networks.
Ransomware surge: VPNs and edge devices in attackers’ sights
The ransomware report from NCC Group reveals a continued increase in global ransomware attacks, marking the fourth consecutive month of year-over-year growth as of June 2026. While the second quarter saw a modest 3 percent rise compared to Q1 2026, the consistent upward trend remains clear. Attackers are focusing on exploiting VPNs and network edge devices to gain initial access, with products from Fortinet, Citrix, and Check Point featuring prominently among targeted systems.
Ransomware groups have shifted their tactics, exploiting network edge vulnerabilities and compromised credentials to infiltrate corporate environments. Akira, Qilin, and The Gentlemen have all been observed using these methods to breach defences. The report highlights that VPNs, once considered a secure remote access solution, are now a significant attack vector, particularly when unpatched or misconfigured. Edge devices from major vendors are being scanned and exploited en masse, making them high-priority targets for cybercriminals.
Affected industries and attack impact
The ransomware report breaks down sector-specific targeting in Q2 2026:
- Industrials: 30 percent of attacks, the most targeted sector
- Consumer discretionary: 24 percent
- Information technology: 11 percent
- Healthcare: 10 percent, including a severe April attack on Signature Healthcare in Massachusetts that disrupted ambulance services and delayed cancer treatments
Government entities are also under sustained assault. Comparitech reports 89 confirmed and 98 unconfirmed attacks on government agencies in the first half of 2026, with US agencies accounting for 31 percent of those incidents. However, this marks a 23 percent decrease compared to late 2025. Notably, the report identifies sharp increases in attacks on transportation (52 percent), healthcare (35 percent), retail (28 percent), and technology (23 percent) over the past six months.
Threat actors: Qilin, The Gentlemen, and emerging risks
Two ransomware groups, Qilin and The Gentlemen, dominate both the NCC Group and Comparitech rankings for most active threat actors in the first half of 2026. The Gentlemen, reportedly a splinter group from Qilin, even surpassed Qilin in the number of claimed victims on data leak sites in June. Halcyon, a cyber resilience platform vendor, has called The Gentlemen one of the fastest-scaling ransomware threats currently tracked.
Other groups such as Akira, DragonForce, Lockbit, and INC also feature in the top six most active ransomware actors. A notable emerging threat is KryBit, first identified in March 2026. KryBit operates as ransomware-as-a-service, targeting Windows, Linux, VMware ESXi, and NAS devices, signalling growing technical sophistication among new entrants.
- Top ransomware groups in 2026:
- Qilin
- The Gentlemen
- Akira
- DragonForce
- Lockbit
- INC
- KryBit (emerging)
Technical developments: EDR killers and AI threats
The ransomware report notes a significant trend: the deployment of “EDR killer” tools by groups like Qilin and The Gentlemen. According to research from Cisco Talos and ESET, these tools are designed to bypass or disable endpoint detection and response (EDR) solutions, allowing ransomware to operate undetected. While such techniques are not new, their increasing use demonstrates the growing sophistication of ransomware operations. Affiliates are now required to develop or obtain their own EDR bypass tools, reflecting a broader technical capability within these groups.
In addition, the report highlights the emergence of autonomous AI agents that can assist in attacks, increasing the speed and scale at which ransomware groups can operate. While details remain limited, the entry of AI into the ransomware ecosystem is a concerning development that may accelerate the evolution of attack techniques.
Attack methodologies observed:
- Exploitation of unpatched VPNs and edge devices (Fortinet, Citrix, Check Point)
- Use of stolen credentials for remote access
- Deployment of EDR killer tools to disable endpoint defences
- Potential use of AI-driven attack automation
Why this ransomware report matters
This ransomware report underscores how attackers are adapting quickly, targeting the technologies that enable remote and hybrid work. The focus on VPNs and network edge devices means that even organisations with strong endpoint controls are vulnerable if edge defences are neglected. The use of AI and advanced EDR bypass tools further increases the risk, making traditional security strategies less effective.
Actions for organisations
Organisations should prioritise patching and monitoring of VPNs and edge devices, particularly those from Fortinet, Citrix, and Check Point. It is crucial to monitor for EDR tampering and review remote access policies to ensure only authorised users can connect. The findings from this ransomware report highlight the need for vigilance around network edge exposure and endpoint security.
Originally reported by csoonline.com.






