Dive Brief:
- Many ransomware victims remain vulnerable to follow-up cyberattacks, even after they complete their incident response processes, highlighting gaps in mitigation activities that increase their odds of becoming repeat targets, the security firm Black Kite said on Tuesday in its annual ransomware report.
- The report described how victims fail to patch critical vulnerabilities and properly configure email security tools, underscoring the importance of thorough digital cleanup operations as part of the ransomware recovery period.
- Black Kite also shared fresh data on the ransomware ecosystem and its top targets.
Dive Insight:
Because ransomware is a profit-motivated business, cybercriminals prioritize the easiest and most lucrative targets, and if an organization fails to fix the problems that opened the door for hackers in the first place, they are likely to return. That fact makes it imperative for hacked businesses to fix digital liabilities as soon as possible after an incident, lest hackers revictimize them seeking another payout.
But many organizations haven’t learned that lesson and continue to operate with serious cybersecurity weaknesses.
Forty-three percent of victimized organizations still have at least one unpatched critical vulnerability, and 31% still have at least one vulnerability that the Cybersecurity and Infrastructure Security Agency says hackers are currently exploiting.
In addition, 59% of victims still haven’t properly configured their Domain-based Message Authentication, Reporting & Conformance (DMARC) email authentication systems, which can protect organizations from phishing attacks and business email compromise scams, and 32% still have misconfigured DomainKeys Identified Mail (DKIM) records, leaving their email domains open to impersonation.
“These signals show what remains visible after the incident closes: conditions that attackers can observe, rank, and reuse,” Black Kite researchers wrote in their report. “These signals matter because ransomware operators do not need a single perfect entry point. They need enough evidence that access may be available, identities may be weak, or trust controls may be incomplete.”
Even as those weaknesses remain unaddressed, hackers are getting better at crafting the kinds of attacks that ensnare businesses every day — and AI is helping them do it.
AI isn’t unlocking devastating new intrusion capabilities, researchers said. Instead, it’s helping unsophisticated hackers generate workable tools that level up their capabilities. “The clearest early signal [of AI value] came from lower- and mid-tier actors,” Black Kite said, noting that the amateur FunkSec threat group “showed signs of AI-assisted development, including tool and encryptor work that appeared more polished than the operator’s apparent technical maturity would suggest.”
And with spear-phishing and impersonation attacks remaining a prime avenue for intrusions, AI is helping ransomware gangs generate increasingly convincing-sounding messages that are helping them fool help-desk employees and other corporate workers. “This is especially important because some of the year’s most disruptive intrusions were not defined by malware sophistication alone,” Black Kite said. “They were defined by attackers understanding how people, vendors, support desks, and identity workflows actually operate.”
Black Kite’s report — which is based on dark-web monitoring of nearly 300 ransomware groups, open-source analysis of victim infrastructure and intelligence from the company’s endpoint detection platform between April 2025 and March 2026 — also confirmed other recent industry findings about the ransomware ecosystem.
While 61 new groups entered the ecosystem during the reporting period, the threat landscape remains heavily concentrated — “the five largest actors still controlled 43.6% of all victims,” Black Kite noted.
In addition, manufacturing remains the most victimized sector, with its 1,660 victims accounting for 22% of all intrusions announced on dark-web leak sites. Black Kite has seen the manufacturing sector top its list for the past four years, and this year, the sector remained in first place in every month of the reporting period.