
Recommended Reading
Notice
This article was written based on Black Kite’s 2026 Ransomware Report and related cybersecurity materials publicly available as of July 22, 2026. It also includes analysis by DANA NOTES.
What This Article Covers
Ransomware Victim Numbers Surge…Expansion of the Criminal Ecosystem, Not AI, Is the Main Cause
Notice
This article is based on Black Kite’s “2026 Ransomware Report” and related security materials publicly available as of July 22, 2026. It also includes analysis by DANA NOTES.
Ransomware Victim Numbers Are Rising Rapidly Again
Ransomware is not a new cyber threat. Attacks that encrypt corporate systems or steal data and then demand money have been repeated for many years. However, as the number of ransomware victims has begun rising rapidly again, there is also growing interest in attributing the increase to generative AI.
Security company Black Kite identified 7,551 organizations publicly disclosed as ransomware victims between April 2025 and March 2026. This was a 24.9% increase from the 6,046 organizations identified during the previous reporting period.
The increase was particularly concentrated in the most recent six months. From April to September 2025, 2,904 victim organizations were identified, while the number rose to 4,647 between October 2025 and March 2026. The number of victims in the most recent half-year increased by approximately 60% compared with the preceding half-year.
In March 2026 alone, 861 organizations were publicly disclosed as ransomware victims. This was the highest monthly figure Black Kite had recorded over the previous four years. This suggests that the overall statistics were not driven upward by a single large-scale incident, but that ransomware attacks were continuing at a faster pace.
Does this mean that the rapid increase in ransomware victims was caused by generative AI?
Black Kite’s analysis points in a somewhat different direction. It is true that AI increases the speed of attackers’ work and lowers the technical burden involved in preparing attacks. However, the more fundamental factors behind the recent increase include the growing number of organizations participating in the ransomware market, the division of the attack process into specialized roles, the growth of ransomware as a service, and new intrusion routes that exploit trusted external platforms.
Rather than creating an entirely new form of ransomware crime, AI has enabled an already industrialized criminal ecosystem to operate more quickly and efficiently.
How Much Has Ransomware Increased?
Black Kite identified 7,551 organizations publicly disclosed as ransomware victims over the most recent year. This was a 24.9% increase from the previous reporting period and the highest number of victims recorded over the past four years.
The monthly average also rose from approximately 504 victim organizations to 629. However, annual averages alone do not fully reveal how sharply the situation changed in the most recent period.
During the first half of the reporting period, from April to September 2025, 2,904 organizations were identified. During the second half, from October 2025 to March 2026, 4,647 organizations were identified. This represented an increase of approximately 60% in the most recent six months compared with the preceding six months.
In particular, more than 700 victim organizations were publicly disclosed every month from October 2025 through March 2026. This indicates that ransomware incidents did not merely spike temporarily at a particular point, but continued at a higher rate for several months.
However, these figures were compiled mainly from cases identified through ransomware groups’ data leak sites and other public sources. Incidents that were not publicly disclosed, or cases in which negotiations ended before the victim was listed on a data leak site, may not have been included.
The actual scale of ransomware compromise may therefore be larger than the publicly available statistics suggest.
New Groups Increased, but Attacks Remained Concentrated Among the Largest Groups
The number of ransomware victims was not the only figure that increased. During the same reporting period, 61 new ransomware groups emerged. This means that, on average, more than one new group entered the market each week.
At the end of the reporting period in March 2026, 127 groups were active. As new groups continued to emerge, the number increased to 146 by June 2026. Compared with the 61 groups identified in 2023, this was more than double.
However, not every newly observed name necessarily represents a completely independent organization. Some may be rebranded versions of existing groups seeking to avoid law enforcement tracking or reset their reputation. Affiliates of existing organizations may also move to other brands or form new groups.
Even so, the increase in new groups is important. It indicates that the market is moving away from a structure led by only a few major organizations and toward an environment in which smaller groups and short-lived operators can continue to enter.
However, the increase in market participants did not mean that attacks were evenly distributed across all groups. The top five ransomware groups accounted for 43.6% of all publicly disclosed victim organizations.
Qilin’s growth was particularly notable.
The number of victim organizations disclosed by Qilin increased from 250 during the previous reporting period to 1,358 during the current period. This represented a 443% increase. Qilin operated in more than 50 countries and expanded its influence to the point that it accounted for approximately one out of every five to six publicly disclosed victim organizations.
This shows that two changes are taking place simultaneously in the current ransomware market.
At the lower end of the market, new organizations and smaller groups are increasing rapidly. At the upper end, major groups such as Qilin continue to expand large-scale attack activity.
In other words, the ransomware market is neither simply fragmented across many organizations nor concentrated only among a few groups. It is shifting toward a dual structure in which the market base is expanding while actual victimization remains concentrated among several major groups.
How Has RaaS Changed Ransomware Attacks?
Ransomware as a Service, or RaaS, is a criminal model in which ransomware developers provide attack tools and operational systems, while other criminals use them to carry out attacks and then share the proceeds.
In the legitimate software market, SaaS allows users to access software functions without directly installing and managing the programs. In a similar way, RaaS provides the functions required for ransomware attacks as a criminal service.
RaaS operators do not merely distribute malicious software files. They may also provide dashboards for managing attack campaigns, payment pages for individual victims, cryptocurrency wallet management, data leak sites, functions for negotiating with victim companies, malware updates, and technical support.
As a result, attackers do not need to develop ransomware themselves. They can use existing tools to attack companies and then share part of the proceeds with the RaaS operator after a successful attack.
This structure has significantly lowered the barriers to entry in the ransomware market.
In the past, attackers needed specialized technical skills to develop malware, bypass security products, and implement file encryption and decryption functions. They also had to prepare their own attack servers, payment systems, and data leak sites.
Today, attackers can use already established attack tools and operational infrastructure by paying a fee or agreeing to revenue-sharing terms. Even criminals without advanced malware development skills can participate in ransomware attacks.
RaaS has transformed ransomware from a single type of malware into a criminal service that can be purchased and used.
Why Have Development, Intrusion, Data Theft, and Negotiation Been Separated?
Modern ransomware organizations are moving away from a model in which a single group handles every stage of an attack. As the attack process becomes more specialized, each organization and participant increasingly handles only the work in which it is most capable.
Ransomware developers create malware and management systems. Intrusion groups exploit vulnerabilities or use stolen accounts to enter corporate networks. Data theft groups locate important information and transfer it outside the organization.
Ransomware affiliates encrypt internal systems and pressure victim companies. Negotiation teams contact victims and coordinate payment amounts and conditions, while separate money-laundering groups make cryptocurrency flows more complex and more difficult to trace.
When roles are divided in this way, each organization does not need to understand the entire attack process.
Groups that are skilled at creating malware can focus on development, while groups experienced in vulnerability exploitation or social engineering can focus on intrusion. Organizations that identify valuable internal data and groups that negotiate with victim companies can also apply different areas of expertise.
Specialization also increases the speed of attacks.
If one organization must identify a target, gain access, steal data, and conduct negotiations, it requires considerable time and personnel. By contrast, when each stage is handled by a specialized organization, multiple attacks can be conducted simultaneously.
Even when a particular organization is disrupted by law enforcement, the entire criminal ecosystem does not immediately collapse. If one ransomware developer disappears, other RaaS tools can be used. If one intrusion group is blocked, access can be obtained through another route.
As ransomware has shifted from crime carried out by a single organization to supply-chain-style crime involving multiple connected participants, the persistence and resilience of attacks have also increased.
How Is Initial Access Traded?
An Initial Access Broker, or IAB, is an organization or individual that first gains access to the internal systems of a company or institution and then sells that access to other criminals.
What they trade is not limited to simple usernames and passwords.
VPN accounts, remote desktop access, administrator accounts, internal server access, cloud accounts, and domain administrator privileges are among the various types of access that can be sold and directly used in an attack.
After entering a company’s internal systems, an IAB does not necessarily deploy ransomware directly. It may handle only the stage of obtaining internal access and then sell that access to ransomware affiliates or other criminals.
Conversely, ransomware groups can purchase access that has already been obtained instead of operating their own phishing campaigns or spending a long time searching for vulnerable servers.
Attackers can reduce the time and risk of failure involved in initial intrusion and move directly to internal reconnaissance, privilege escalation, data theft, and encryption.
If RaaS lowered the barrier to obtaining attack tools, IABs lower the barrier to entering corporate networks.
However, Black Kite’s report did not identify IABs alone as the new primary cause of ransomware growth. IABs are an important component of the existing criminal supply chain. The new development highlighted in the report is that trusted external platforms and service connections are increasingly being used as attack routes.
Why Is a Single VPN Account Traded at a High Price?
A VPN account may appear to be nothing more than basic login information. To an attacker, however, it can serve as an entry point into a company’s internal systems.
By connecting through a legitimate VPN account, an attacker may be more likely to avoid detection by security systems than by launching random attacks from the internet. If the account has sufficient privileges or does not require multi-factor authentication, the attacker may also gain access to internal systems, file servers, and administrative tools.
The price of an account can vary depending on the size of the company, its industry, estimated revenue, level of access, whether the account has administrator privileges, and the range of networks that can be reached.
The greater the potential profit from data theft or extortion, the more valuable the access may become.
The price of a VPN account therefore reflects not simply the value of the login information itself, but the degree of internal access and future extortion opportunities that the account may provide.
Which Intrusion Routes Are Receiving Attention Recently?
Ransomware attackers are increasingly targeting not only corporate systems directly, but also external services and connection structures that companies already trust.
Black Kite analyzed that a significant portion of major attacks during the reporting period occurred through trusted vendor platforms, including SaaS integrations, enterprise applications, OAuth connections, and customer support procedures.
A representative example is the abuse of OAuth tokens connected to the Salesforce ecosystem.
OAuth is a method that allows companies to connect the services they use with external applications and share login or data access permissions. If the permissions granted to an external service are stolen, an attacker may gain access to internal information without directly stealing a password.
The Salesloft Drift-related attack mentioned by Black Kite spread by abusing OAuth tokens belonging to a third-party application connected to Salesforce, rather than by directly breaching each customer’s external systems.
In the Oracle E-Business Suite case, a vulnerability in a business platform used by many companies became an attack route affecting multiple victim organizations. The more widely a platform or connected service is used, the greater the potential scope of damage caused by a single vulnerability.
These attacks are dangerous because they may appear to involve connections and accounts that have already been authorized within the company.
Even if a company strengthens the security of its own systems, attackers may still use existing trust relationships to access internal data when permissions connected to external SaaS providers, suppliers, maintenance companies, or remote support tools are compromised.
Supply chain security is no longer limited to checking whether a partner holds a security certification. Companies must also examine which permissions external applications have, which OAuth tokens remain active, and how user identities are verified during customer support procedures.
How Is the Criminal Supply Chain Formed?
Today’s ransomware attacks are increasingly moving away from the model in which one hacker performs every stage from beginning to end.
An organization that has obtained initial access may sell internal access rights to a ransomware affiliate. Internal reconnaissance and privilege escalation then take place, after which a data theft group transfers important information outside the organization.
Ransomware may encrypt internal systems or disrupt corporate operations. Negotiation teams contact the victim company to coordinate payment amounts and conditions, while criminal proceeds may pass through multiple cryptocurrency wallets and money-laundering channels.
The malware used in the attack may be provided by a RaaS operator. Initial intrusion may be handled by an IAB or an affiliate, while trusted external applications or permissions connected to suppliers may also be used as attack routes.
Each participant receives a share of the proceeds according to the stage for which they are responsible.
Under this structure, criminals without the ability to develop ransomware can still participate in attacks. Organizations that cannot conduct their own intrusions can purchase access, while attackers without negotiation capabilities can use specialized negotiators.
The increase in ransomware victims is therefore linked not only to improvements in malware performance, but also to the growth of a market in which the tools, access rights, data, personnel, and operational functions required to prepare and carry out attacks can all be traded.
How Is AI Actually Changing Ransomware Attacks?
Since the emergence of generative AI, there has been frequent discussion about how cyberattacks have changed significantly. AI can, in fact, automate or assist with various tasks involved in preparing attacks.
However, AI did not create ransomware as a new type of attack. Ransomware, phishing, account theft, and vulnerability exploitation had already been used for many years before generative AI emerged.
Black Kite also did not view AI as the direct cause of the recent increase in ransomware victims. AI may increase the speed of attackers’ work and reduce the costs required, but the more fundamental factors behind the rise in victims are the expansion of criminal organizations and the specialization of attack structures.
Rather than being a technology that fully automates ransomware operations, AI is closer to a tool that helps complete tasks more quickly that previously required more people and time.
A representative example is target research.
Attackers collect publicly available corporate information, technical documents, job postings, organizational charts, email addresses, and information about software in use to analyze potential targets. Generative AI can be used to summarize and categorize the collected information and organize the details needed for an attack.
Attackers can more quickly determine which systems a particular company uses, which departments and employees could be targeted, and what type of approach would appear natural.
How Does AI Accelerate Existing Attacks?
Rather than transforming existing attacks into entirely different forms, AI reduces the time and cost required during the attack process.
It Can Make Phishing Emails More Natural
In the past, attackers wrote phishing emails themselves or used translation tools. If the grammar or wording was awkward, recipients could become suspicious.
Generative AI can write emails in a natural style and quickly create content tailored to the circumstances of a company and its employees. Phishing messages in multiple languages can also be produced within a short period.
For example, emails impersonating human resources departments, business partners, executives, or cloud service administrators can be written differently for each company. Instead of repeatedly sending the same wording, attackers can create large volumes of messages tailored to the role and circumstances of each target.
Voice and Identity Impersonation Can Become More Sophisticated
AI voice cloning and deepfake technology can be used to imitate the voices of corporate executives or representatives of partner companies.
Attackers may call help desks or customer support staff and request password resets, changes to multi-factor authentication methods, or account recovery.
In such cases, system vulnerabilities are not the only targets. Human judgment and business procedures also become attack routes.
This is why established identity verification procedures should not be skipped, even when someone claims to be an executive or an important customer.
Vulnerability Information Can Be Analyzed More Quickly
When a new vulnerability is disclosed, security advisories and technical documents are usually released at the same time. Attackers analyze these materials to determine which products and versions are affected.
AI can be used to summarize lengthy documents and organize the characteristics of vulnerable systems and the likelihood of exploitation. Attackers can then more quickly identify internet-exposed systems that are more likely to be successfully attacked.
AI does not create new vulnerabilities, but it can shorten the time required to use publicly disclosed vulnerability information in an attack.
It Can Be Used to Modify Existing Malware
Rather than developing entirely new malware from the beginning, attackers may create variants by making small changes to existing code or fixing errors.
AI can be used to explain code structures, modify certain functions, or automate repetitive tasks.
However, AI-generated code is not always accurate or immediately usable. Technical review and modification are still required before it can be used in an actual attack.
Even so, the ability to reduce the time needed to modify and test code compared with the past can increase attacker productivity.
Paradoxically, Existing Attacks Have Become Stronger
Many people believe that AI will create entirely new cyberattacks that did not previously exist.
However, the more direct change currently taking place is that repeatedly modifying and reusing existing attacks has become much easier.
Phishing emails have become more natural and can be quickly translated into multiple languages. Publicly available corporate information can also be used to produce large volumes of messages targeting specific employees or departments.
Vulnerability information can be summarized more quickly, allowing attackers to identify relatively vulnerable targets more efficiently among many companies. Malware can also be repeatedly modified in small ways instead of being developed as an entirely new type.
In other words, attack techniques have not been completely transformed. Rather, the speed and scale of existing attacks have increased.
For this reason, security teams should not focus only on new AI-based attacks. Long-standing attack routes such as account theft, phishing, vulnerability exploitation, and failures in remote access management must be managed more thoroughly.
AI is not the sole cause of the increase in ransomware victims. It is closer to an accelerator that increases the productivity of an already expanding criminal ecosystem.
Security Risks Do Not Disappear When a Ransomware Incident Ends
When a ransomware incident occurs, companies isolate infected systems, restore servers, and change the passwords of accounts used in the attack.
Once systems begin operating normally again, it is easy to assume that incident response has ended. However, restoring systems and eliminating intrusion routes that attackers could use again are separate tasks.
When Black Kite reassessed the security posture of ransomware victim organizations, stealer log exposure levels after the incident were 175% higher than at the previous point of analysis.
Stealer logs refer to login information and authentication data collected from devices infected with information-stealing malware.
They may include not only email addresses and passwords, but also login information stored in browsers, cookies, session information, and service access records.
Even after a company restores its servers, new authentication information may continue to leak if employees’ or partners’ computers remain infected with information-stealing malware.
Even if passwords are changed, attackers may still continue to gain access through other methods if sessions or tokens that preserve existing login states remain active.
For this reason, incident response should not end with password changes alone. All login sessions and authentication tokens should be reset, and devices belonging to employees and external partners should also be checked for infection.
Serious Vulnerabilities Also Remained
Black Kite’s latest reassessment found that 43.5% of victim organizations still had serious security vulnerabilities that could cause significant damage if exploited.
These vulnerabilities had a score of 9.0 or higher under CVSS, a system that evaluates vulnerability severity on a scale of 10.
In addition, 30.8% of victim organizations had not properly addressed vulnerabilities that had been confirmed as used in actual cyberattacks. These vulnerabilities are included in the KEV catalog maintained by the U.S. Cybersecurity and Infrastructure Security Agency.
KEV is not simply a list of vulnerabilities that are theoretically dangerous. It tracks vulnerabilities that have been confirmed as used by attackers to compromise systems.
The fact that these vulnerabilities remained after an incident means that companies had restored disrupted systems but had not fully removed the routes that attackers could use to enter again.
Restoring files encrypted by ransomware and returning servers to normal operation is not enough.
Stolen accounts and authentication information must be replaced, infected devices must be identified, and unpatched systems and external access permissions must be reassessed.
Otherwise, the same company may remain vulnerable to another attack.
Why Strengthening AI Security Alone Is Not Enough
Many companies are paying increasing attention to generative AI security policies and the protection of AI models.
The leakage of internal corporate information to external AI services, the misuse of permissions by AI, and attacks targeting AI models are also important security issues.
However, actual ransomware incidents can still begin with basic weaknesses such as outdated vulnerabilities, stolen accounts, and poor remote access management.
If security patches for operating systems or VPN equipment are delayed, or if an administrator account without multi-factor authentication is stolen, attackers can enter corporate networks without using AI.
Problems can also arise when login or data access permissions connected to external SaaS services are set too broadly. If unused external application connections remain active, attackers may abuse those permissions to access internal information.
The same applies when the accounts of partner companies or maintenance providers are not properly managed. Attackers can steal an external provider’s account and access internal systems while appearing to be legitimate partner personnel.
AI can increase the speed and efficiency of attackers’ work. However, if there are no accounts, vulnerabilities, or external connections available for exploitation, the advantage attackers can gain is also reduced.
For this reason, adopting AI security technology alone is not enough to respond to ransomware.
Basic security capabilities for managing accounts, permissions, patches, remote access, external service connections, and data access must also be strengthened.
What Should Companies Check First?
Ransomware response strategies also need to change in line with the evolving criminal ecosystem.
1. Multi-Factor Authentication Should Be Applied to VPN and Administrator Accounts
Multi-factor authentication should be prioritized for VPNs, remote desktops, cloud management accounts, and administrator accounts.
Even if a password is stolen, access should not be possible without an additional authentication step.
However, methods that rely only on text messages or simple approval notifications can be abused through phishing or repeated approval request attacks. Where possible, phishing-resistant authentication methods such as security keys should be used.
2. Patching Should Be Prioritized for VPN and Externally Connected Equipment
Vulnerabilities should be prioritized not only in operating systems, but also in VPN appliances, firewalls, remote access solutions, and devices directly connected to the internet.
Rather than treating all vulnerabilities equally, organizations should first address KEV vulnerabilities that have been used in actual attacks and serious vulnerabilities exposed to the internet.
3. Unused Accounts and Permissions Should Be Removed
Accounts belonging to employees who have left the company or changed departments, administrator accounts that have not been used for long periods, and temporary accounts issued to external providers should be reviewed immediately.
Organizations should also confirm that users have not been granted administrator privileges beyond what they need.
To prevent damage from spreading throughout the entire system when a single account is stolen, each user should receive only the permissions necessary for their work.
4. SaaS and External Service Connections Should Be Reviewed
Companies should create an inventory of external applications connected to the SaaS services they use.
They should review which data and functions each application can access and disconnect unused integrations.
If excessive permissions have been granted to external services, they should be reduced to the minimum necessary scope.
5. Accounts Belonging to External Partners and Suppliers Should Be Controlled
When partner companies or maintenance providers access internal systems, the permitted access times, target systems, and user privileges should be restricted.
Multi-factor authentication should also be applied to external accounts, and accounts and access permissions should be revoked immediately when contracts or maintenance work ends.
6. Help Desk Identity Verification Procedures Should Be Strengthened
Attackers target not only technical vulnerabilities, but also password reset and authentication method change procedures.
Administrator passwords should not be reset, and multi-factor authentication methods should not be changed, based only on requests made by phone or messenger.
The same established identity verification procedures should apply even when someone claims to be a senior executive, an important customer, or a representative of a partner company.
7. Abnormal Logins and Privilege Escalation Should Be Detected
Organizations should monitor logins from unusual countries and time zones, repeated authentication attempts within a short period, and cases in which ordinary user accounts obtain administrator privileges.
Activity should not be assumed to be legitimate simply because a valid account was used.
When an account is stolen, an attacker can access systems while appearing to be a legitimate user.
8. Access to Important Data and External Transfers Should Be Monitored
Recent ransomware groups often steal important data before encrypting systems.
Organizations must therefore be able to detect large-scale file access, the compression of many files at once, unusual cloud uploads, and transfers of data to external storage locations.
The assumption that good backups alone are enough to respond to ransomware must also change. If data has already been leaked externally, extortion may continue even after systems are restored.
9. Backup and Actual Recovery Capabilities Should Be Tested
Simply storing backup data is not enough.
Backup environments should be separated so that attackers cannot delete or encrypt backups together with operational systems.
Organizations should also regularly test whether systems and data can be restored within the required time when an actual incident occurs.
The personnel and procedures required for recovery, as well as the systems that should be restored first, should also be determined in advance.
10. Exposure Should Continue to Be Reviewed After an Incident
Even after the initial emergency response has ended, organizations should continue reviewing their security posture for a certain period.
Stealer logs, compromised accounts, active login sessions and authentication tokens, vulnerabilities used in actual attacks, external application connections, and partner accounts should all be reassessed.
The end of incident response should not be determined simply by whether systems are operating normally.
It should be determined by whether the accounts, vulnerabilities, and external connections that attackers could use again have all been removed.
Changes to Watch Going Forward
Several changes are likely to become increasingly important in the ransomware environment.
First, the current dual structure may continue, with the number of new ransomware groups increasing while actual attacks remain concentrated among several leading organizations.
It will also be necessary to continue examining whether newly emerging groups are completely new organizations, existing groups operating under new names, or groups formed by affiliates who moved from other organizations.
Attacks through trusted external services and enterprise platforms may also become more important.
In addition to VPNs and externally connected equipment, SaaS applications, login permissions, data access permissions, remote support tools, help desks, and accounts belonging to external suppliers may be used as initial intrusion routes.
Attacks that steal data first and threaten to disclose it without encrypting systems may also continue.
Such attacks are difficult to address with backups alone. Systems that detect who accessed important information and whether large volumes of data are moving outside the organization will become increasingly important.
The role of AI may also continue to expand.
At present, AI is mainly being used to reduce the costs of target research, phishing and voice impersonation, translation, vulnerability analysis, code modification, and the creation of extortion messages.
In the future, it may be used more actively to shorten the time required for vulnerability discovery and attack preparation, or to conduct large-scale social engineering attacks against multiple companies.
However, tracking only new AI-based attacks is not enough to explain the current ransomware threat.
Attackers using AI still target accounts, vulnerabilities, external service connections, and human business procedures. The fundamental attack routes that companies need to manage have not disappeared.
DANA NOTES Commentary
Ransomware can no longer be viewed as a crime carried out independently from beginning to end by a specific group of hackers.
Through RaaS, attackers can use attack tools and operational systems, while initial access rights and stolen authentication information are traded. Intrusion, data theft, encryption, and negotiation can also be divided among different organizations.
This specialized structure lowers the barrier to entry for attackers. Criminals without the technical ability to carry out the entire attack process can still participate in the ransomware market by handling only a specific stage or purchasing the functions they need.
One of the most important points in Black Kite’s report is that the ransomware market is expanding at the lower end while becoming concentrated at the upper end.
Although 61 new groups emerged during the reporting period, the top five organizations accounted for 43.6% of all publicly disclosed victims. Qilin increased the number of victim organizations from 250 to 1,358, representing a 443% rise.
Smaller organizations are emerging rapidly, while the influence of major groups with large-scale attack capabilities is also becoming stronger.
Generative AI is also affecting these changes, but the key point is not that AI created a new form of ransomware.
AI reduces the time and cost required for existing attack processes, including target research, phishing message creation, translation, vulnerability analysis, code modification, and the preparation of extortion messages.
As a result, attackers can carry out the same attacks against more targets in less time.
AI is not the fundamental cause of ransomware growth. It is closer to an accelerator that allows an already industrialized criminal ecosystem to operate more efficiently.
Post-incident response must also change.
In Black Kite’s reassessment, stealer log exposure among victim organizations was 175% higher than before. Serious vulnerabilities were still found in 43.5% of victim organizations, while 30.8% had not properly addressed vulnerabilities confirmed as used in actual attacks.
This means that restoring systems after a ransomware incident does not necessarily remove all the accounts, vulnerabilities, and external connections that attackers could exploit.
The direction companies need to focus on is ultimately clear.
Strengthening AI security technology alone is not enough to stop ransomware. Account management, multi-factor authentication, patch management, remote access control, SaaS and external service connection management, supply chain security, data exfiltration detection, and backup and recovery capabilities must all be strengthened together.
Only when these basic security capabilities are solid can organizations respond effectively to attacks that use AI to increase speed and scale.

