Check Point reveals India’s evolving ransomware threat landscape

DQChannels Bureau
DQChannels Bureau
Check Point reveals India’s evolving ransomware threat landscape

The ransomware threat landscape remained elevated through Q2 2026, with 2,139 victims recorded on data leak sites. While the headline figure was broadly flat from the previous quarter, the structure of the ecosystem changed significantly, with more active groups and a smaller share controlled by the largest operators.

For Indian enterprises, the pressure is even more visible. Organisations in India faced an average of 3,359 cyber attacks per week over the last six months, compared with 2,161 globally. Ransomware impacted 9.5% of organisations in India, against 5.1% worldwide, making the threat harder to treat as an isolated security concern.

Check Point India threat intelligence report shows wider pressure

The Check Point India threat intelligence report highlights that ransomware sits within a much wider attack environment. In India, botnets affected 18.7% of organisations and infostealers 8.3% during the same period.

India also accounted for 3.6% of ransomware activity by geography over the last 30 days. The broader picture suggests that enterprises are dealing with multiple forms of malicious activity that can feed into the same attack chain.

Ransomware market fragmentation changes the equation

The ransomware market fragmentation became clearer in Q2. The number of active groups increased from 71 to 93, while the top 10 groups' share of victims dropped from 71% in Q1 to 57.6%.

The Gentlemen emerged as a notable example of how quickly a smaller operation can scale. Its leaked chats showed a core team of around nine people, supported by affiliates. Its administrator reportedly used AI coding assistants to build the ransomware management panel in about three days.

This points to a lower barrier for building ransomware operations, even though human expertise remains important for guiding and correcting AI-generated code.

Data exfiltration-first extortion gains ground

The data exfiltration-first extortion tactics highlighted in the report are becoming more important as payment rates decline. Ransom payments have fallen for six consecutive years, from 85% in 2019 to roughly 23% today.

Better backups have reduced the impact of encryption, but they cannot prevent stolen information from being exposed. That is pushing attackers towards data theft, while on-chain ransomware payments still exceeded $820 million in 2025.

AI-Assisted cyber attacks raise the speed

The growth of AI-assisted cyber attacks adds another layer to the challenge. The Gentlemen example shows how AI-assisted cyber tooling can speed up software development for ransomware operations, reducing the time needed to build parts of an attack infrastructure.

For defenders, the report points towards faster detection and response, with initial access, credential protection, remote access and exfiltration detection becoming key priorities.

The ransomware threat landscape reinforces the need to look beyond recovery alone. The focus increasingly has to include preventing initial access, limiting exposure and detecting stolen data before an attack turns into a wider business problem.

Read More:

Data Lineage Matters in the Age of AI, and Graphs Make It Possible

Net Protector Antivirus eyes India’s next cybersecurity shift

Comnet Vision 30 years anniversary marks years of IT evolution

Operant AI Launches Semantic Firewall to Govern Autonomous Agent Intent

Latest Stories