Black Kite, a cyber-risk firm, counted 7,551 organizations in its ransomware leak-site dataset between April 2025 and March 2026, up 24.9% from 6,046 in the previous reporting period.
The company’s latest available scans found critical vulnerabilities and stolen-credential exposure remained visible across many affected organizations, according to cyber-risk firm Black Kite.
Black Kite found vulnerabilities rated CVSS 9.0 or higher at 43.5% of victims in the latest available scans. Separately, 30.8% had at least one flaw in CISA’s Known Exploited Vulnerabilities Catalog, while stealer-log findings remained visible at 29.6% of victims.
The company identified organizations named on ransomware leak sites and said it cross-validated the entries with open-source intelligence and its own telemetry. Its 2026 ransomware report covers disclosures between April 1, 2025 and March 31, 2026 and includes known or reliably estimated annual revenue for more than 6,000 victims.
Ransomware disclosures surge in the second half
Disclosure volume accelerated after September. Disclosures rose from 2,904 in the first six months to 4,647 in the second, increasing the monthly pace by 60%. March closed with 861 victims, the highest monthly total in Black Kite’s series.
The report also includes an update covering April through June 2026, after the annual reporting period. Black Kite counted another 2,230 victims: 737 in April, 716 in May and 777 in June.
The figures are excluded from the report’s annual comparison but show that monthly disclosures remained above 700 after the March cutoff. The trailing-12-month active-group count reached 146 by the end of June.
Mid-market organizations see the strongest share increase
Among victims with known or reliably estimated revenue, organizations in the $10 million-to-$50 million band remained the largest group at 37.4%. The $50 million-to-$100 million band recorded the strongest share increase, rising from 25.1% to 29.3%, while the $1 million-to-$5 million band’s share rose from 3% to 5.1%. The share of victims with revenue above $100 million declined from 13.9% to 9.5%.
Exposure signals persist after leak-site disclosures
Black Kite found that ransomware-related exposure signals were often visible before victims appeared on leak sites. More than 60% had at least one of three finding types: software vulnerability, credential stuffing or stealer logs. Nearly one in 10 had all three.
In the same scans, 62.5% of victims had at least one vulnerability rated medium severity or higher, while 57.7% had one rated CVSS 8.0 or higher. Stealer-log findings remained visible at nearly three in 10 victims.
Some of Black Kite’s proprietary indicators improved. Its average cyber rating rose by 0.69 points, while its botnet-activity measure fell from 9.7 to 3.1. Its ransomware-specific indicators moved differently: the company reported a 175% increase in its stealer-log measure and a 2.5% rise in its software-vulnerability measure. The latter worsened for roughly two-thirds of victims. Black Kite summarized the split this way: “Recovery is not the same as exposure reduction.”
Multiple threat actors claim the same victims
The report also identified 130 domains that appeared under more than one ransomware actor during the reporting period. Black Kite grouped those overlaps into 251 shared-victim clusters covering 376 related events.
Black Kite cautioned that the pattern does not prove that access was transferred between groups or that the organizations were compromised more than once. Affiliate movement, shared access, repeat targeting and false claims could produce similar records.
Post-incident guidance and dataset limitations
NIST’s current incident-response guidance says recovery from cybersecurity incidents can take weeks or months and recommends sharing lessons as they are identified rather than waiting for recovery to conclude.
CISA’s StopRansomware Guide tells organizations to identify the systems and accounts involved in the initial breach and, after cleaning and rebuilding the environment, reset passwords for affected systems and address associated vulnerabilities and visibility gaps.
Black Kite recommends external exposure reviews at 30, 60 and 90 days after an incident, covering stealer logs, KEV exposure, critical patch vulnerabilities, remote access, SaaS integrations and vendor-managed access. Neither NIST nor CISA prescribes that timetable.
The report also identifies SaaS integrations, OAuth tokens and enterprise applications as attack surfaces. Salesloft disclosed reconnaissance activity in its Salesloft and Drift application environments. Oracle separately said CVE-2025-61882 was remotely exploitable without authentication in E-Business Suite. Neither disclosure shows how frequently those routes appeared among the 7,551 organizations in Black Kite’s dataset.