The State of Ransomware: Q1 2026
Overview:
The ransomware landscape continues to evolve, with new players emerging and established groups adapting their strategies. Key trends in Q1 2026 include a shift away from traditional US-centric targeting models, the resurgence of previously dominant operations like LockBit, and the challenges faced by cartel-model organizations such as DragonForce.
New Entrants: The Gentlemen
- Origins: Founded by an experienced Qilin affiliate named Hastalamuerte, who left due to a dispute over unpaid commissions.
- FortiGate Stockpile: Possesses a cache of approximately 14,700 pre-exploited FortiGate devices and 969 validated brute-forced credentials, providing a significant initial access advantage.
- Geographic Distribution: A notable departure from the US-centric targeting model, with victims primarily in Thailand (10.8%), Brazil (6.0%), India (4.2%), and other non-Western countries.
Resurgence of LockBit 5.0
- Victim Count: Posted 163 victims in Q1 2026, a significant increase from the
Read the full article at Check Point Research
Want to create content about this topic? Use Nemati AI tools to generate articles, social posts, and more.

![[AINews] The Unreasonable Effectiveness of Closing the Loop](/_next/image?url=https%3A%2F%2Fmedia.nemati.ai%2Fmedia%2Fblog%2Fimages%2Farticles%2F600e22851bc7453b.webp&w=3840&q=75)



