Ransomware attacks hit SMBs harder than ever as cybercrime gang rivalry heats up
Qilin and The Gentlemen battle for cybercrime supremacy
- NordStellar reports 2,581 ransomware attacks in Q2 2026, with Qilin (299) and The Gentlemen (284) leading activity, far ahead of DragonForce (147)
- US SMBs were hit hardest, suffering 769 incidents; Canada (97), Germany (83), and the UK (74) followed, while attacks on billion‑dollar enterprises surged 74%
- Experts say rivalry between Qilin and The Gentlemen is driving the spike, with major corporate hits seen as reputation‑boosting trophies in the cybercriminal underground
Two ransomware gangs are battling for dominance, and US-based SMBs are the ones suffering most for it, experts have claimed.
Fresh data about the state of ransomware in 2026, compiled by security experts from NordStellar, shows two groups - Qilin and The Gentlemen - being by far the most active ones.
After analyzing more than 200 threat actor blogs, NordStellar concluded that there were 2,581 ransomware attacks in the second quarter of the year - and of that number, 299 belong to Qilin, the most active threat actor out there. Close second are The Gentlemen, with 284 attacks. The third most active group - DragonForce - doesn’t even come close with “just” 147 attacks.
SMBs and enterprises under assault
While it seems like a close race, it’s actually The Gentlemen who have been doing the heavy lifting between April and June 2026. This group experienced a 39% increase in attacks, while Qilin’s activity actually declined somewhat, compared to Q1.
In this morbid race to the bottom, the biggest victims are US-based small and medium-sized businesses (SMB). These companies, with up to 200 employees and revenues under $25 million, experienced 769 attacks in Q2 2026, followed by Canada (97), Germany (83), and the UK (74).
NordStellar also mentioned US enterprises, who are now increasingly being targeted. Attacks against organizations with revenues north of $1 billion surged by 74%, going from 23 incidents in Q1, to 40 in Q2.
“Ransomware actors historically target SMBs because these organizations often lack comprehensive defenses, which can increase the likelihood of a successful attack,” commented Vakaris Noreika, cybersecurity expert at NordStellar.
Sign up to the TechRadar Pro newsletter to get all the top news, opinion, features and guidance your business needs to succeed!
“This recent spike in enterprise targeting is unusual and may be a temporary fluctuation. This shift likely stems from the rivalry between dominant threat actors — a successful hit on a major corporation is a badge of honor that boosts a group’s reputation within the cybercriminal underground."
➡️ Read our full guide to the best antivirus
1. Best overall:
Bitdefender Total Security
2. Best for families:
Norton 360 with LifeLock
3. Best for mobile:
McAfee Mobile Security
Follow TechRadar on Google News and add us as a preferred source to get our expert news, reviews, and opinion in your feeds.
Sead is a seasoned freelance journalist based in Sarajevo, Bosnia and Herzegovina. He writes about IT (cloud, IoT, 5G, VPN) and cybersecurity (ransomware, data breaches, laws and regulations). In his career, spanning more than a decade, he’s written for numerous media outlets, including Al Jazeera Balkans. He’s also held several modules on content writing for Represent Communications.
You must confirm your public display name before commenting
Please logout and then login again, you will then be prompted to enter your display name.