
In February of 2024, a consortium of law enforcement agencies took down LockBit ransomware group. The discovery that LockBit retained victims’ stolen data despite promises to delete it demonstrates a critical flaw in the advice often given to ransomware victims. At the time, many legal and incident response professionals recommended payment on the assumption that LockBit had a strong financial incentive to honor its commitments and that the likelihood of data being publicly released after payment was relatively low. While that assessment may have appeared reasonable based on short-term observed outcomes, it relied heavily on assumptions about the behavior of a criminal enterprise that could never be independently verified. Operation Cronos revealed that the underlying premise was false: victims were paying for a result that was never actually delivered. More broadly, the episode highlights an important lesson in cyber risk management: rare or low-probability outcomes occur far more often than decision-makers tend to expect, particularly when dealing with volatile cyber criminals. Cyber incidents routinely produce outcomes that fall outside historical norms. Decisions based solely on what appears statistically likely, over a broad sample, can leave organizations exposed to significant and unforeseen consequences. In this example, the generic advice of “if you pay a ransom, your stolen data will be deleted” turned out to be incorrect advice. It just took a long measurement period to make that determination.
A more recent example that highlights the potential for volatile outcomes involves a ransomware group called Icarus and their supply chain compromise of Klue in June 2026. Klue fell victim to a highly coordinated SaaS supply chain attack orchestrated by the relatively new group. The attackers exfiltrated millions of highly sensitive CRM records, including business contacts, sales communications, and pricing details from a long list of Klue customers.
After a ransom payment was purportedly made to guarantee the deletion of the data, it subsequently came to light that a separate criminal group had retained the names of the victims as well as samples of the data. This left the impacted victim population exposed to ongoing extortion threats despite a ransom being paid to prevent this very outcome. A situation like this may seem like a lightning strike situation, but in reality, these sorts of volatile outcomes are becoming increasingly common.
To further this point, enterprises have grown fatigued by mass SaaS supply chain attacks. The same underlying piece of enterprise customer data is often being impacted more than once in a calendar year. An enterprise only needs to see the extortion circus once to wise up to the limited utility of engaging with one of these threat actors.
What is the point of highlighting these examples? When advising victims of cyber extortion incidents, vendors often paint an outcome picture colored by common past experience and “regression to the mean” outcomes. These are digested easily by executives unaccustomed to how incident response works. In reality, incident outcome forecasts are far more volatile than anyone wants to explain. Circumstances that sound remote are often well within the scope of possibility. First-time victims are strongly predisposed towards loss-aversion psychology and behavior. They are unlikely to grasp that an unfavorable outcome they perceive to be in the skinny tail portion of the curve is dangerously likely. Even if they can grasp it, they are unlikely to want to, as that outcome is scary even if it’s the truth.
One more story to demonstrate our point.
In January of 2020, we were working on a small extortion case. A few factors in the case were strange and we had attribution to suggest that the group was Chinese, but was using Dharma ransomware. A week or two into the case, the threat actors completely disappeared from our conversations. They were gone for several weeks, and we told the client it was unlikely that they would ever reengage. At the time, the variant of ransomware that this group was using was known to be fairly reliable in terms of the outcomes that could be forecasted and achieved. When the threat actors finally did resurface a few weeks later and began corresponding again, they attributed their absence to a virus that had sickened their entire team. Due to some members of their team no longer being available because they were so sick, they could not continue to negotiate or provide any deliverables. At the time, we thought that was just a bad excuse for them being lazy and sloppy. A few months later, as the COVID-19 pandemic enveloped the world, we re-examined the case and came to a different conclusion. Based on our attribution, it was actually quite likely that the threat actors were working out of a location that was ground zero for COVID-19 and could very well have contracted an early version of the virus (which you will recall was extremely virulent). Going into the matter, our intelligence on Dharma ransomware indicated that outcomes like this were low probability. Much like the pandemic itself, sometimes the truth sounds implausibly unlikely, but it nevertheless becomes reality.
While historical outcome data is still relevant and important for developing a recovery strategy, it is not the only data that matters. It is critical that qualitative conditions (global health crises, natural disasters, law enforcement actions) also be taken into consideration when forecasting the likelihood of certain results.

Ransomware payment metrics diverged sharply in Q2 2026: while the average ransom payment surged 176% from Q1 to $1,880,612, the median payment fell by 50% to $150,000. This widening gap stems primarily from a handful of unusually high, “lumpy” payments for extortions involving data exfiltration rather than traditional data encryption. A key driver behind this spike was the ongoing campaign by Silent Ransom (also known as Luna Moth) against high-profile law firms. By threatening public exposure of sensitive legal records exfiltrated through targeted social engineering, the group secured large payments that skewed the quarterly average dramatically upward.
Rather than relying on automated technical exploits, Silent Ransom relies heavily on high-touch social engineering to gain initial network access. The group frequently uses voice phishing (“vishing”) calls, posing as internal IT support or third-party help desks to manipulate employees into handing over login credentials or granting remote access. In even more aggressive recent operations, the group incorporated physical infiltration into its campaigns. Threat actors impersonating IT personnel walked directly into target law offices, convincing staff to grant them hands-on workstation access under the guise of routine maintenance. This allowed them to seamlessly bypass standard boundary defenses and steal files directly from law firm machines.
Ransomware Payment Rates in Q2 2026

While a few large payments skewed the average ransom payment amount in Q2, the percentage of clients that ultimately choose to pay sank to a new record low during the quarter. Victims of cyber extortion are becoming increasingly sensitive to the potential volatility of outcomes that may occur post-payment, especially in circumstances that involve the most recent cohort of cybercriminals that are focused on data exfiltration. The trend shows up most noticeably in the data-exfiltration-only payment rate, which also dropped to a historically low level of 15%.

Most Common Ransomware Threat Actors in Q2 2026
|
Rank |
Ransomware Type |
Market Share % |
Change in Ranking from Q1 2026 |
|
1 |
Lone Wolf |
17% |
+1 |
|
2 |
ShinyHunters |
12% |
+1 |
|
3 |
Akira |
9% |
-1 |
|
4 |
The Gentlemen |
8% |
New in Top Variants |
|
5 |
DragonForce |
4% |
New in Top Variants |
Significant market share in Q2 was held by data-theft-focused groups that remain engaged in high-volume vishing attacks geared towards cloud exfiltration. The targeted, identity-based nature of these attacks makes them difficult to defend against, and we see no sign of this intrusion pattern slowing down. Remaining market share was held by more conventional cyber extortion groups, including Akira, The Gentlemen, and DragonForce, who rely on more traditional, scalable entry vectors and less on social engineering.
Most Common Ransomware Attack Vectors in Q2 2026

In Q2 2026, initial access remained heavily identity-driven. The quarter was less about attackers breaking in loudly and more about finding ways to log in quietly through access paths that appeared legitimate. Phishing and social engineering moved back into the lead, but the broader pattern is the continued abuse of trusted identity workflows: MFA and password resets, help desk manipulation, account recovery processes, OAuth grants, delegated applications, remote access portals, vendor sessions, and previously stolen credentials. The initial intrusion increasingly looks like normal authentication or authorized administration, which makes early detection and scoping more difficult.
Remote access compromise declined from its late-2025 peak but remained a material pathway. This category should now be understood more broadly than VPN or RDP alone; it also includes SaaS administration portals, SSO platforms, cloud consoles, RMM tools, APIs, and delegated access into customer environments. Compromised credentials also continued to rise as a standalone vector, reflecting the ongoing availability of credentials through infostealers, botnets, reuse, and access brokers. Third-party and supply chain access remained lower volume, but higher complexity, because the relevant access, logs, and containment actions may sit partially or entirely outside the victim’s direct control.
The defensive priority is to harden trusted access paths. Organizations should treat help desk, password reset, MFA reset, device enrollment, and account recovery workflows as security controls; prioritize phishing-resistant MFA for privileged, remote access, SaaS, cloud, and backup admin accounts; monitor remote access broadly; audit OAuth grants, API tokens, service principals, connected apps, and delegated permissions; and tighten vendor/MSP access through named accounts, least privilege, logging, time limits, and disciplined offboarding. Vulnerability exploitation declined in Q2, but internet-facing appliances and management planes still require focused patching and monitoring.
Most Common Ransomware Tactics in Q2 2026

In Q2 2026, the top observed tactics continued to reflect hands-on-keyboard intrusions built around movement, access, and leverage. Lateral Movement and Exfiltration were tied as the most observed tactics, each appearing in 76% of cases. Lateral Movement remained the operational backbone of many intrusions, with attackers continuing to rely on legitimate administrative pathways such as RDP, SMB, WinRM, WMI, SSH, PsExec-style tooling, and RMM. Exfiltration remained a primary extortion lever in its own right, with attackers favoring legitimate web services, cloud storage, and file-transfer tools that can blend into normal HTTPS and SaaS traffic.
Command and Control increased materially in Q2, appearing in 69% of cases, up 11% from the prior quarter. The dominant pattern remained the use of legitimate or dual-use remote access tools, including RMM platforms, remote desktop utilities, mesh VPNs, file-transfer tools, and tunneling services. Discovery also moved higher, observed in 52% of cases, up 10%, reinforcing its importance as an early-warning phase before data theft, encryption, or disruption. Network mapping, share enumeration, user and service discovery, file searches, and visibility into virtual infrastructure should be treated as escalation signals, particularly when activity occurs near domain controllers, file servers, hypervisors, or backup systems.
Despite its low ranking, Impact remained the tactic most directly felt by leadership when it occurred. Fewer observed cases reached encryption, service disruption, or recovery impairment, but those that did continued to create pressure around operational continuity and recovery decision-making. The practical takeaway is that detection alone is not enough: organizations need the ability to contain lateral movement, disrupt active remote control, assess exfiltration quickly, and execute recovery decisions with clear authority over backups, isolation, rebuilds, and business restoration.

In Q2, the most represented industries in Coveware by Veeam cases were Software Services at 17.2%, Healthcare at 14.1%, Professional Services at 13.1%, Financial Services at 9.1%, and Materials at 9.1%. Compared with Q1, Healthcare and Professional Services remained highly represented, while Software Services became the top impacted sector and Consumer Services declined to 6.1%.
Software Services leading the quarter is notable because these environments can provide leverage through customer data, integration access, credentials, and downstream business disruption. Professional Services also remained highly represented, including law firms and other advisory businesses that can be targeted because they hold sensitive client information, privileged communications, transaction records, and other data that creates immediate legal, reputational, and client pressure if exposed.
Data sensitivity continues to shape threat actor selectiveness, particularly in sectors where stolen information creates immediate legal, regulatory, client, or operational pressure. High-impact sectors such as Healthcare and Public Sector can experience outsized disruption because downtime tolerance is low and response capacity is often constrained, even when the intrusion itself is not especially sophisticated. Conversely, lower representation in a given quarter should not be read as immunity; opportunistic actors will take any viable path of least resistance.

In Q2 2026, the mid-market remained the center of gravity for observed extortion activity, with organizations between 11 and 10,000 employees accounting for 75.8% of cases. The largest single band was 101-1,000 employees at 35.4%, followed by 1,001-10,000 at 22.2% and 11-100 at 18.2%. Larger organizations were more represented than in Q1, with companies above 10,000 employees making up 19.2% of cases, reflecting both opportunistic access patterns and the selectiveness of certain threat groups that pursue larger victims when the data sensitivity, access quality, or potential leverage justifies the effort. Overall, the distribution still points more toward scale, repeatability, and leverage than pure “big game hunting.”

Even though Median Company Size of ransomware victims grew to 750 (+50% from Q1 2026), employee count remains a weak predictor of extortion risk; exposure is more closely tied to identity compromise, remote access, data sensitivity, third-party dependencies, and the ability to recover safely under pressure. It is perhaps fair to say that company size can be a predictor of the type of compromise you’re likely to face; large enterprises tend to be at higher risk for the targeted, identity-based attacks, whereas SMEs are more likely to be impacted by intrusions stemming from unpatched vulnerabilities and compromised remote access.
The takeaway from Q2
The Q2 data tells a consistent story. Attackers spent the quarter logging in quietly through the same identity workflows that keep a business running. Meanwhile, the economics of paying continued to deteriorate. The average payment nearly tripled on the strength of a few outsized exfiltration cases, while the proportion of victims who chose to pay fell to a record low. Two numbers moving in opposite directions that points to a market shift in how victims are valuing the promises of their attackers.
We opened this report with outcomes that seemed implausible right up until they happened, and that is the lens we would encourage decision-makers to keep. In an extortion incident, the question “what usually happens?” can be a bit of a false flag. Organizations that prepare for the “rare” incident are the ones who can survive it. The same confidence cannot be granted to those who only consider the average.
Coveware by Veeam puts real case data behind every decision you will face in a cyber extortion incident, and we will keep publishing what we see, quarter by quarter.