Check Point India threat intelligence report reveals ransomware shift

Ransomware is holding its ground, but the way attackers operate is changing. The latest Check Point India threat intelligence report shows that Q2 2026 brought 2,139 ransomware victims, broadly flat from the previous quarter but 33% higher year over year. The bigger signal is the growing number of active groups and their changing methods.
For India, the pressure is already higher than the global picture. Organisations in the country faced an average of 3,359 cyber attacks each week over the past six months, compared with 2,161 globally. Ransomware affected 9.5% of Indian organisations, against 5.1% worldwide.
More groups, less concentration
The ransomware market is becoming more fragmented. Active groups rose from 71 in Q1 to 93 in Q2, while the top 10 groups' share of victims fell from 71% to 57.6%.
Qilin remained the leading group with 279 victims. The Gentlemen followed closely, growing 62% and moving ahead of Qilin in June. For Indian organisations, the concern is not one dominant group but a wider pool of attackers operating across the same digital environment.
AI is lowering the entry barrier
One of the clearest findings came from leaked chats linked to The Gentlemen. A core team of roughly nine people used AI coding tools while building a top-tier ransomware operation within months.
The finding does not suggest that AI was independently running attacks or selecting targets. Instead, it shows how AI-assisted development can help skilled operators build ransomware tooling faster.
That matters because the barrier to entering the ransomware economy is getting lower.
Data theft is becoming the bigger pressure point
Ransomware payment rates have fallen to roughly 23%, down sharply from 85% in 2019. Better backups have made encryption less effective as a pressure tactic.
But stolen data creates a different problem. Restoring systems does not prevent leaked information from being published. As a result, attackers are putting greater weight on data theft and extortion.
For defenders, this changes the priority. Backups remain important, but detecting initial access and stopping data exfiltration now deserve equal attention.
What Indian organisations should watch
The report points to a straightforward defensive approach. Organisations need to focus on exposed access points, stolen credentials, phishing, vulnerability remediation and exfiltration detection.
India's threat picture makes this harder to ignore. Ransomware sits alongside botnets affecting 18.7% of organisations and infostealers affecting 8.3%.
The takeaway is simple. Ransomware is no longer just a file-encryption problem. It is part of a wider attack chain, and organisations that can detect and contain that chain earlier will be better placed to limit the damage.
Read More:
Genesys International CTO appointment brings Dhiman Basu Ray onboard
Huawei and HP Agreement Puts Wi-Fi Patents in Focus
AWS and NVIDIA partnership pushes AI beyond GPUs
Salesforce Partners: Why AI is changing the channel opportunity






