Briefing

  • According to the annual ransomware report released by security firm Black Kite on Tuesday, many ransomware victims remain vulnerable to subsequent cyberattacks even after completing the incident response process, highlighting deficiencies in mitigation measures and increasing their likelihood of becoming repeat targets.
  • The report describes cases where victims failed to patch critical vulnerabilities and properly configure email security tools, emphasizing the importance of thorough digital cleanup during the ransomware recovery period.
  • Black Kite also shared new data on the ransomware ecosystem and its primary targets.

In-depth analysis

Since ransomware is a profit-motivated business, cybercriminals prioritize the easiest and most lucrative targets. If organizations fail to fix the issues that initially allowed hackers to breach them, they are likely to return. This fact makes it essential for victim businesses to address digital liabilities promptly after an incident to prevent hackers from re-attacking for another ransom.

But many organizations have not learned this lesson and continue to operate with serious cybersecurity weaknesses.

43% of victim organizations still have at least one unpatched critical vulnerability, and 31% still have at least one vulnerability flagged by the U.S. Cybersecurity and Infrastructure Security Agency (CISA) as "being exploited by hackers."

Additionally, 59% of victims still have not properly configured Domain-based Message Authentication, Reporting, and Conformance (DMARC) email authentication systems—which protect organizations from phishing attacks and business email compromise scams—and 32% of victims still have misconfigured DomainKeys Identified Mail (DKIM) records, leaving their email domains at risk of impersonation.

"These signals show residual risk that remains visible after the incident ends: conditions that attackers can observe, prioritize, and exploit," Black Kite researchers wrote in the report. "These signals matter because ransomware operators do not need a perfect entry point. They only need enough evidence that access may be available, identities may be weak, or trust controls may be incomplete."

While these weaknesses remain unresolved, hackers have become more adept at creating the types of attacks that plague businesses daily—and artificial intelligence (AI) is fueling this trend.

Researchers say AI has not unlocked destructive new intrusion capabilities. Instead, it helps less technically skilled hackers generate usable tools, thereby enhancing their capabilities. "The clearest early signals of AI's value come from lower- and mid-tier actors," Black Kite said, noting that the amateur FunkSec threat group "shows signs of AI-assisted development, including tools and encryption programs that appear more sophisticated than the operators' apparent technical maturity would suggest."

As spear phishing and impersonation attacks remain the primary intrusion vectors, AI is helping ransomware gangs generate increasingly convincing messages that aid them in deceiving help desk staff and other corporate employees. "This is especially important because some of this year's most destructive intrusions were not defined solely by malware sophistication," Black Kite said. "They were defined by attackers' understanding of how people, vendors, support desks, and identity workflows actually operate."

Black Kite's report—based on dark web monitoring of nearly 300 ransomware groups, open-source analysis of victim infrastructure, and intelligence from its endpoint detection platform between April 2025 and March 2026—also confirms recent findings from other industry sources.

Although 61 new groups entered the ecosystem during the reporting period, the threat landscape remains highly concentrated—"the top five actors still controlled 43.6% of all victims," Black Kite noted.

Furthermore, manufacturing remains the most attacked industry, with its 1,660 victims accounting for 22% of all intrusions announced on dark web leak sites. Black Kite has seen manufacturing top its list for four consecutive years, and this year, the industry held the number one spot in every month of the reporting period.