# The Ransomware Surge Has Nothing to Do With AI — That's What Should Scare You
Nearly 28 organizations fell to ransomware every single day in March 2026. Not because attackers got smarter. Not because AI unlocked some new capability. Because the barrier to running a ransomware operation has collapsed, the ecosystem splintered into dozens of hungry new entrants, and defenders are still guarding last year's perimeter.
That's the uncomfortable finding at the center of Black Kite's latest ransomware report, which tracked 7,551 known victims over the twelve months ending March 2026. A 25% increase over the prior year sounds bad enough. But the acceleration embedded inside that number is worse: 2,904 victims in the first half of the tracking period, 4,647 in the second half. That's a 60% jump, compressed into six months.
This is not a plateau. It's a climb.
## Sixty New Groups and a Lowered Floor
The ransomware space used to be dominated by a handful of sophisticated actors — REvil, Conti, LockBit — with serious infrastructure, negotiation teams, and affiliate networks. Law enforcement pressure fractured those operations, but it didn't kill the market. It democratized it.
Black Kite counted more than 60 new ransomware groups entering the ecosystem in the past year. Most of them aren't sophisticated. They don't need to be. Leaked builder tools, commoditized initial access from brokers, and ready-made Ransomware-as-a-Service platforms mean you can stand up an operation without writing a line of malware. The intellectual and financial barriers that once culled bad actors from the market are nearly gone.
Ferhat Dikbiyik, Black Kite's chief research and intelligence officer, put it plainly: "It's still a lucrative business, and the barrier to running one keeps getting lower."
That's the actual threat model now — not a nation-state actor deploying AI-enhanced exploits, but 60-plus opportunistic crews scraping for targets below the enterprise tier, where defenses are thinner and incident response is slower.
## The Supply Chain Multiplier
Volume is only part of the story. The efficiency per attack is also climbing, and that's where third-party compromise changes the math entirely.
When Qilin hit a single managed service provider last year, that one breach cascaded to 32 South Korean financial institutions. One vendor. Dozens of victims. The math for attackers becomes extraordinary: instead of compromising 32 separate organizations — each with its own defenses, authentication stack, and detection tooling — you compromise their common infrastructure supplier and collect.
Black Kite specifically cited incidents involving Oracle and Salesforce as examples of how a single supply chain breach enables multivictim campaigns at scale. The pattern isn't new, but its frequency is. MSPs and SaaS platforms have become ransomware's force multiplier, and the industry still treats vendor security as an audit checkbox rather than a live threat surface.
This is a structural problem. When defenders talk about "third-party risk management," they usually mean questionnaires and annual reviews. What Qilin demonstrated is that attackers are doing continuous reconnaissance of vendor attack surfaces, looking for the one pivot that yields 32 for the price of one.
## Visibility Failures That Weren't Hidden
Perhaps the most damning finding in the Black Kite data: many victims showed elevated ransomware susceptibility scores before they were hit. Their external attack surface was readable to anyone looking — open ports, unpatched internet-facing systems, leaked credentials — and attackers were looking.
This matters because it dismantles a common defensive excuse. Organizations often explain breaches as sophisticated, zero-day attacks that couldn't have been anticipated. The data says otherwise. The weakness was visible. The attack was predictable. The question is whether anyone on the defense side was watching the same signals attackers were.
External attack surface management has been a category for years. Most organizations still treat it as optional.
## What "Fragmentation" Actually Means for Defenders
Fragmentation sounds like a problem for law enforcement. It's also a problem for security teams.
When the ecosystem was dominated by a few major groups, threat intelligence was tractable. You tracked LockBit's TTPs, you knew their preferred initial access vectors, you had YARA rules for their payloads. Now you're chasing 60-plus groups with different tooling, different targets, and different negotiation behaviors. The threat intelligence burden has multiplied alongside the attack volume.
Smaller organizations — the ones now squarely in the crosshairs as attackers seek softer targets — rarely have the resources to maintain that kind of tracking. They're relying on shared threat feeds that lag by weeks, or they're not tracking at all.
The implication isn't that enterprises are safe. It's that the attacks on mid-market and small organizations are happening faster than those organizations can adapt, and the incidents often don't generate the public reporting that would help others prepare.
---
## HackWire Analysis
The "ransomware is accelerating but AI isn't the cause" framing is worth sitting with, because the AI narrative has absorbed enormous attention from boards, vendors, and media — and this data suggests it may have displaced focus from the more mundane factors actually driving the surge.
The real drivers here are economic and structural: a commoditized criminal market, supply chain leverage that multiplies ROI per attack, and a deliberate pivot toward organizations that aren't equipped to respond. None of these require AI. All of them are harder to solve than deploying a new detection tool.
The October-to-March acceleration is particularly telling. That period overlaps with several major supply chain incidents and the continued expansion of RaaS platforms after LockBit's disruption. When you take out a dominant player and don't eliminate the underlying market demand, you don't reduce attacks — you disperse them across more actors with less predictable behavior.
The most underreported angle in this data is the RSI finding: victims had visible external weaknesses before they were hit. That means a meaningful percentage of these 7,551 incidents were preventable with basic attack surface hygiene — not AI-powered defense, not zero-trust architecture overhauls, just knowing what you're exposing to the internet and patching it.
For defenders right now: the priority isn't keeping up with 60 new threat actors. It's ensuring your organization doesn't look like the easiest target on the block. Attackers at this level of the market are selecting on opportunity, not sophistication. Make your external surface boring.
For organizations that rely on MSPs or major SaaS platforms: the Qilin/MSP incident should be a forcing function for vendor segmentation reviews. What does an attacker gain if your primary MSP is compromised? If the answer is "everything," that's the gap.
The acceleration doesn't stop when AI becomes more capable. It stops when the economics of running a ransomware operation get harder — and nothing in this data suggests that's happening.
— HackWire Editorial
---
## Related Coverage