Ransomware 2026 H1: 146 Groups, Qilin Leads — NC SMB Priorities

Help Net Security July 24 report: 146 active ransomware groups, Qilin leads, US = 49.3% of victims. NC SMB defense priorities today. Call (336) 886-3282.

Cover Image for Ransomware 2026 H1: 146 Groups, Qilin Leads — NC SMB Priorities

TL;DR: Help Net Security published its 2026 mid-year ransomware trends report on July 24, 2026, aggregating leak-site telemetry across the ransomware ecosystem. Headlines: 146 active ransomware groups by June 2026, up from 85 in mid-2025; 61 new groups formed between April 2025 and March 2026 (more than one per week); Qilin is the top-volume operator during October 2025-March 2026; the United States accounted for 49.3% of all observed victims, making NC SMBs the single most-targeted population by geography. Manufacturing remained the most-targeted sector, with construction, healthcare, wholesale trade, financial services, and technology forming the next tier. For NC SMBs — particularly Triad manufacturers, contractors, medical practices, and community nonprofits — the message is: the ransomware ecosystem is bigger, faster, and more affiliate-driven than at any point since 2020, and defensive priorities need to reset accordingly.

Key takeaway: The number of ransomware groups doubled year over year while attack volume rose 20% globally and 74% against billion-dollar targets. For an NC SMB, the operational meaning is: even if your revenue is small, you are inside the 49.3% US-victim majority, and 88% of SMB breaches involve ransomware. Defensive priorities should be immutable backup + tested restore + 24/7 MDR + KEV-cadence patching, in that order.

Need an honest 2026 ransomware readiness assessment for your NC business? Contact Preferred Data Corporation at (336) 886-3282 for a two-week assessment. BBB A+ rated, serving High Point, Greensboro, Winston-Salem, Charlotte, Raleigh, and the Piedmont Triad since 1987.

What Are the Headline Numbers in the H1 2026 Ransomware Report?

The Help Net Security 2026 mid-year report synthesizes leak-site tracking, dark-web observation, and incident-response casework from multiple vendors. Five numbers frame the year to date.

  • 146 active ransomware groups by June 2026, up from roughly 85 in mid-2025 — a 72% year-over-year growth in the operator population.
  • 61 new ransomware groups formed between April 2025 and March 2026, averaging more than one new group per week.
  • Qilin is the top-volume ransomware operator across the October 2025 to March 2026 tracking window, per the report.
  • US-based victims accounted for 49.3% of all leak-site postings, meaning American organizations bore roughly half of all observed ransomware attacks worldwide.
  • Total ransomware volume rose ~20% year over year, with a 74% quarter-over-quarter jump in attacks against billion-dollar organizations, per the BlackFog State of Ransomware 2026 report.

Two secondary numbers from adjacent reports round out the picture. BrightDefense's data breach tracker shows 88% of SMB breaches involve ransomware, versus 39% for large organizations, and only 17% of US small businesses carry cyber insurance, leaving 83% of SMBs to absorb ransomware losses directly.

Why Does the "Bigger Ecosystem, Same Playbook" Story Matter for NC SMBs?

Two structural changes drive the ecosystem growth, and both push risk down-market toward the NC SMB tier.

  • The Ransomware-as-a-Service (RaaS) model. New groups form by licensing existing malware from experienced operators, adding affiliates, and running their own extortion sites. Barriers to entry are trivially low, and the affiliate revenue split (typically 70-30 favoring the affiliate) means aggressive targeting of high-frequency, low-friction victims — exactly the SMB profile.
  • The "insurance ceiling" effect on enterprise targeting. Large-enterprise ransomware payouts have compressed as insurers tightened terms and clients hardened defenses. Ransomware crews responded by broadening the target pool downward. Sophos' 2026 State of Ransomware report documents falling ransom-demand medians alongside rising victim counts — a volume strategy.

For a High Point manufacturer, a Charlotte medical practice, or a Greensboro nonprofit, the practical translation is that being small no longer confers meaningful obscurity. The Anubis, Qilin, Interlock, Pear, and Gentlemen crews all posted July-2026 SMB victims in the US: YMCA of Western NC posted by Interlock July 22, P&A Construction posted by Qilin July 22, Bath Fitter posted by Anubis July 20, and Metropolitan Construction Systems posted by Pear July 24 collectively represent the exact size class of NC SMB that PDC serves.

Who Is Qilin and Why Are They the Volume Leader Right Now?

Qilin (also tracked as Agenda) is a Russian-linked RaaS operation that emerged in late 2022, rebranded and rewrote its locker in 2023, and rose to top-of-leaderboard status in 2025-2026. Three operational characteristics explain Qilin's H1 2026 leadership.

  • Multi-platform locker. Qilin's malware runs on Windows, Linux, ESXi, and Nutanix, letting affiliates hit hypervisor tiers and shut down entire virtualized fleets in a single event.
  • Affiliate quality. Qilin has publicly recruited experienced affiliates from other crews (BlackCat/ALPHV, LockBit, others) that shut down or fragmented over 2024-2025. The Hacker News' Qilin analysis documents PAN-OS vulnerability exploitation and Cobalt Strike deployment as recurrent TTPs.
  • Cross-sector reach. Qilin's H1 2026 victim list spans manufacturing (Stryker July 24), construction (P&A Construction July 22, S.J. Louis Construction July 7), healthcare, dental practices, and professional services, per DeXpose's ransomware tracking.

The takeaway for an NC SMB is not "watch out for Qilin specifically." It is that Qilin's playbook — patch-gap exploitation of edge appliances, RMM-tool abuse for lateral movement, ESXi/hypervisor targeting for maximum blast radius — is the template that every other 2026 crew is copying.

What Are the Top Sectors Hit and Where Does NC Sit?

Help Net Security's sector ranking for H1 2026 puts manufacturing first, followed by professional / scientific / technical services, then a middle tier of construction, healthcare, wholesale trade, finance, information, and retail. Every one of the top four sectors is a defining part of the North Carolina SMB economy.

  • Manufacturing. NC is the ninth-largest manufacturing state by GDP; the Piedmont Triad has 350+ defense manufacturers and thousands of small industrial firms across textiles, furniture, food, chemicals, plastics, and metalworking. Manufacturing was the most-hit sector in H1 2026.
  • Professional services. The Triangle (Raleigh-Durham-Chapel Hill) alone has thousands of law firms, CPA firms, engineering consultancies, and management-consulting shops. Professional / scientific / technical services was the second-most-hit sector.
  • Construction. NC construction added roughly 30,000 jobs in 2024-2025 per NC Department of Commerce data. Construction was the third-tier target, and July 2026 alone saw at least two named US construction ransomware victims.
  • Healthcare. NC has 100+ hospitals plus thousands of independent medical, dental, behavioral-health, and specialty practices. Healthcare ransomware activity rose 35% year over year per Cybersecurity Insiders' H1 2026 tracking.

The blunt implication for an NC SMB owner is that if you are a manufacturer, contractor, professional-services firm, or medical practice, you are inside the top-four most-targeted sectors and the US-49.3% majority simultaneously. The intersection is where the highest concentration of 2026 ransomware activity lands.

What Are the Top Five NC SMB Defensive Priorities in Response to This Report?

The 2026 mid-year report reinforces a defensive priority stack that has been evolving since 2023. The five priorities below are ordered by "will most reliably interrupt a real 2026 attack chain."

  • Priority 1: Immutable, air-gapped backups with a documented restore test in the last 90 days. Ransomware crews specifically target backup infrastructure. Immutable snapshots (Veeam Hardened Repository, Cohesity, Rubrik, or S3 Object Lock) that cannot be deleted by any admin credential are the only reliable path to full recovery without payment.
  • Priority 2: 24/7 Managed Detection and Response (MDR) on all endpoints and servers. Bank-hours SOC is inadequate against off-hours affiliate operations. MDR with human analysts on-call correlates events across endpoints and network to interrupt the kill chain between reconnaissance and encryption.
  • Priority 3: CISA KEV-cadence patching for internet-facing and management-plane systems. BOD 22-01 sets a federal reference; NC SMBs should adopt a policy of KEV-catalog patch within 72 hours for edge appliances (firewall, VPN, remote access, SharePoint, Exchange, RMM) and within 14 days for internal systems.
  • Priority 4: Phishing-resistant MFA + RMM tool allowlisting + outbound-tunnel detection. The Anubis / Citrix Bleed 2 / RMM-abuse pattern documented in our July 25 Anubis defense post is now common enough that generic MFA and default egress are insufficient.
  • Priority 5: Documented incident-response plan + evidence packet + cyber-insurance alignment. Written IR plan, tabletop within the last 12 months, evidence-packet template (technical timeline, notification drafts, insurance-broker script), and a policy renewal that reflects real controls.

Five is the practical maximum for a 25-250 seat NC SMB to execute concurrently. Any additional priority should sit on the roadmap, not on the this-quarter list.

What Does This Cost, and What Do NC SMBs Actually Spend?

The honest cost range for the five-priority stack, sized for a 50-seat NC SMB, is $60,000-$180,000 in the first year, dropping to $45,000-$150,000 in year two and beyond. That is meaningful money, and it is dramatically smaller than an unrecovered ransomware event.

PriorityYear-1 Cost (50 seats)Year-2+ RecurringNC SMB Typical Vendor Options
Immutable backup + restore$8-25K$6-18KVeeam + hardened repo, Datto, Rubrik, Cohesity
24/7 MDR$20-60K$18-55KHuntress, Arctic Wolf, SentinelOne + Vigilance
KEV-cadence patching (managed IT)$18-45K$15-40KInternal IT + policy, or fully managed IT partner
Phishing-resistant MFA + RMM allowlist$8-25K$4-15KMicrosoft Entra P2, Yubico, Duo, RMM audit tool
IR plan + tabletop + evidence packet$6-25K$2-12KFractional IR retainer or annual tabletop
Total (all five)$60-180K$45-150KDelivered by internal IT or managed IT partner

Sophos' 2026 State of Ransomware report puts median SMB total-cost-of-recovery above $1M when downtime, restoration, legal, notification, and lost sales are included. The five-priority stack's cost is 6-15% of that median event cost — the classic insurance math.

Ready to size and phase the five priorities for your NC business? Contact Preferred Data Corporation at (336) 886-3282 or visit 1208 Eastchester Drive, Suite 131, High Point, NC 27265.

How Does the July 24 Report Change Cyber-Insurance Renewal Conversations?

2026 cyber-insurance renewals were already tightening. The mid-year ransomware trends confirm the underwriting posture. Four consequences NC SMBs should expect at the next renewal.

  • MFA + EDR are floor requirements, not preferred controls, per the 96% MFA / 88% EDR mandate we documented on July 16.
  • Immutable backup with tested restore is being added to the base questionnaire by several carriers, with premium impact for "no immutable backup" responses.
  • CISA KEV compliance is trending toward affirmative attestation. Unpatched KEV entries at loss time have become a top denial category in 2026 disputes.
  • Rate increases are moderating but not reversing — 2026 renewals are trending 5-25% higher for SMBs with documented controls; 60-200% higher without.

The documented five-priority program is what turns a renewal from "priced out" to "priced comfortably."

Frequently Asked Questions

If ransomware groups are proliferating, is any single group actually a bigger threat than the others?

Not really, and that is the point. Qilin, Anubis, Interlock, Pear, and Gentlemen are all serious operators in H1 2026, but the defensive controls that stop one stop most. Ransomware defense in 2026 is not group-specific; it is TTP-specific (initial access, escalation, credential theft, lateral movement, backup destruction, exfiltration, encryption).

We are a 20-person business. Are we still inside the "US 49.3%" majority?

Yes. Leak-site postings do not filter by employee count. Small businesses are heavily represented in the US victim tally, and 88% of SMB breaches involve ransomware per DBIR-adjacent tracking. The 49.3% share is a national exposure, not a large-enterprise exposure.

Is paying the ransom actually cheaper than not paying?

Almost never. Sophos' 2026 report confirms that businesses that paid recovered slower and paid more (ransom + restoration + downtime) than businesses that refused to pay and restored from immutable backup. Payment also does not guarantee data return, decryption, or that the exfiltrated data is destroyed.

Do cyber-insurance carriers require the specific five priorities in this article?

Increasingly, yes. MFA and EDR are near-universal in 2026 questionnaires. Immutable backup, KEV-cadence patching, and documented IR plan are trending toward required. RMM allowlisting is still emerging but is on the leading-edge questionnaires. The five-priority stack is directionally aligned with 2026-2027 underwriting.

How long does it take a Qilin-style attack to go from initial access to encryption?

Median dwell time in H1 2026 dropped to under a week for affiliate operations, with some Qilin operations executing in 24-48 hours from initial access to full encryption. Our July 3 analysis of 72-minute AI-accelerated attacks covers the fastest-observed cases. The MDR-must-be-24/7 requirement follows directly.

What is the difference between the Anubis, Qilin, and Interlock crews?

Anubis is US SMB-focused with an RMM-abuse and Citrix Bleed 2 preference. Qilin is high-volume, multi-platform, hypervisor-capable, and cross-sector. Interlock is a smaller but active crew that has hit US nonprofits and mid-market entities including YMCA of Western NC on July 22. The defensive controls do not need to distinguish between them.

What happens if a KEV entry is not patched by its CISA deadline?

Federal civilian agencies face directive-level noncompliance under BOD 22-01. Private-sector organizations do not face direct penalty, but insurers, plaintiffs, and regulators increasingly treat KEV non-compliance as evidence of unreasonable security. In 2026, "unpatched KEV at time of loss" is a leading argument for claim denial.

Should NC SMBs join CISA's KEV notification list?

Yes, or subscribe indirectly through a managed IT / cybersecurity partner. CISA's KEV catalog publishes updates several times per week, and email or RSS notifications make it possible to align a 72-hour patch cadence to real-time KEV posting.

Support