Two records, one crime wave
Every ransomware breach can enter the public record twice. The criminals keep the first record: “leak sites,” where gangs post the names of victims who refused to pay, as leverage and as advertising. Regulators keep the second: breach notifications filed with state attorneys general, federal health authorities, and the SEC. DisclosureLens ingests both, continuously, from 22 sources. This report counts what each record showed in the first half of 2026.
One definition before the numbers. A leak-site posting is a criminal allegation: it means a gang claimed an organization as a victim, not that a breach has been independently confirmed. We count postings after deduplication at ingest — every claim is content-hashed, so re-captures of the same post never count twice — and our daily completeness sweep backfills anything the real-time feed missed, symmetrically for this year and last, so the comparison below is apples to apples.
The record half
Gangs posted 4,993 organizations in H1 2026, against 4,273 in H1 2025 (+17%) and 4,021 in H2 2025. Independent trackers agree on the direction: Comparitech logged 4,217 attacks in the same window and likewise called it a new high; DBDigest counted 4,725 victims. Our count runs higher because we aggregate more leak-site sources and recover late captures via the completeness sweep.
Data table
| Month | Postings |
|---|---|
| 2026-01 | 752 |
| 2026-02 | 828 |
| 2026-03 | 879 |
| 2026-04 | 861 |
| 2026-05 | 897 |
| 2026-06 | 776 |
| H1 2026 total | 4,993 |
| H1 2025 total | 4,273 |
| H2 2025 total | 4,021 |
The record half had no spike month: H1 2026 ran a steady 752–897 postings per month. February 2025's 1,086 — the Cl0p/Cleo mass dump — remains the only month above 900. Counts: DisclosureLens, snapshot 2026-07-31.
What makes the half remarkable is its shape. The previous record quarter — Q1 2025, 2,537 postings — was a spike: a single mass-publication event pushed February 2025 to 1,086 postings, a monthly figure nothing since has approached. H1 2026 had no such month, yet still produced 2,459 postings in Q1 and 2,534 in Q2 — the latter within three postings of the all-time quarterly record. (We decline to call Q2 a record; at this margin, late captures could put either quarter on top.) Spike-driven records tell you one gang had a good month. Breadth-driven records tell you the system got bigger.
The geography surprise: America's share is collapsing
Split the record half by victim geography and the headline inverts. Postings naming US organizations: roughly 1,995 in H1 2025, 1,944 in H1 2026 — flat. Postings naming victims everywhere else: up from about 2,278 to about 3,049, a 34% jump. The US share of geo-identified victims, which had held between 49% and 51% for two years, fell to 42% — the lowest we have measured. At the organization level the picture is the same: distinct US victims declined about 5%.
Data table
| Half | US-tagged | Everywhere else (incl. untagged) |
|---|---|---|
| 2024 H1 | 1,415 | 1,441 |
| 2024 H2 | 1,691 | 1,828 |
| 2025 H1 | 1,995 | 2,278 |
| 2025 H2 | 1,955 | 2,066 |
| 2026 H1 | 1,944 | 3,049 |
US-tagged postings (teal) vs all other postings (amber). Geography is machine-extracted from claim content, and the amber band deliberately includes the untagged remainder (354 postings, 7% of H1 2026) rather than hiding it. Imputing those untagged postings at each half's own US rate leaves US volume flat (+0.4%); see the method note for the full sensitivity.
We tried to break this finding before believing it. The geographic tags are machine-extracted, so we checked every way we know for the measurement to lie. Tag formats: our filter accepts every US tag variant in the corpus — an exhaustive scan found zero variants it misses, in any half. Extractor drift: if our tagger had simply become stingier about “US,” every gang's US share would fall together. The opposite happened — Akira's US share rose from 54% to 72% and INC Ransom's from 60% to 66%, while the half's volume leaders simply operate elsewhere: Qilin's postings were 38% US, TheGentlemen's 19%, the relaunched LockBit's 10%. And the untagged remainder, which grew from 182 postings to 354, cannot rescue the US number under any plausible assumption: impute it at each half's own US rate and US volume is flat (+0.4%). Only if virtually every untagged 2026 posting were American — while almost none of 2025's were — would the US have grown, and that requires the untagged rows to be far more American than the tagged ones they sit beside.
The drop, in other words, is composition: the gangs that grew are the gangs that don't primarily hit America. External trackers see the same direction — ReliaQuest put the US share of global victims at 49.3% in Q2 2026, down from 51.9%; Check Point noted LockBit's US share had fallen to 21.2% with “Italy, Brazil, and Turkey picking up the slack”; European victim growth ran far ahead of the US. No tracker we found has led with the US-flat finding — but none of their published numbers contradicts it.
Why it's happening is harder than whether. International expansion of affiliate recruiting, US law-enforcement pressure displacing targeting, new brands born outside the traditional US-focused playbook — all are consistent with the data, but our data measures where victims are, not why. We flag the question rather than answer it. One honest caution: geography tagging has thinned in the most recent months — about 96% of postings carried a tag through 2025, 91% in May 2026 and 85% in June — so this section reports halves and quarters, never single recent months.
The gang economy churned at startup speed
The supply side of the criminal record was rebuilt in eighteen months, and H1 2026 is what the rebuilt version produces at full speed.
Ranked by H1 2026 volume (gangs with ≥50 postings shown in the table below the chart). RansomHub and the original LockBit 3.0 label — the top brands of 2024 — are absent from the H1 2026 set entirely.
| Gang | H1 2025 | H1 2026 | US share of H1 2026 postings |
|---|---|---|---|
| Qilin | 345 | 685 | 38% |
| TheGentlemen | 35 | 457 | 19% |
| LockBit (relaunched) | 62 | 359 | 10% |
| Akira | 392 | 338 | 72% |
| INC Ransom | 168 | 260 | 66% |
| DragonForce | 91 | 256 | 41% |
| NightSpire | 69 | 200 | 49% |
| Play | 220 | 173 | — |
| Cl0p | 404 | 129 | — |
| SafePay | 224 | 93 | 12% |
US shares shown where the gang's Q2 2026 volume supports a stable estimate.
The new #1 doubled. Qilin posted 685 victims in the half, twice its H1 2025 pace — a run ZeroFox likewise scores as an unbroken twelve months at the top of the global table. Qilin was the primary beneficiary of the ecosystem's biggest vacancy: RansomHub, the most prolific operation of 2024, went dark on April 1, 2025, and its affiliates publicly scattered to Qilin and DragonForce. Both appear in this table's growth column; RansomHub does not appear at all.
The fastest riser barely existed a year ago. TheGentlemen posted 35 victims in H1 2025 and 457 in H1 2026 — growth Halcyon calls the fastest scaling of any group on record. (Some trackers score TheGentlemen ahead of Qilin for Q2 specifically; we have Qilin 304 to 281. On the half, it isn't close.) Cl0p, the gang whose Cleo spike set the old quarterly record, posted 129 — down 68% from its spike-year pace, the comedown that mass-exploitation campaigns always produce between exploits.
A third of the market is new this half. 36 brands published their first victim in H1 2026 (DBDigest independently counts 42 new operators). Two of them — Krybit (65 postings) and Payload (63) — reached top-25 volume within months of appearing. The active-brand count hit 111, a record, up from 91 two years earlier. Barriers to entry in the extortion economy are effectively zero, and brand loyalty is nonexistent — which is exactly what the enforcement playbook of the last three years (takedowns of LockBit, ALPHV, RansomHub) selects for: fewer giants, more startups.
We checked both ways this could be an illusion. The debuts are real brands, not renamed old ones: the only first-timer with a plausible prior-brand match in our corpus was Payload, and independent malware analysis dates its emergence to February 17, 2026 — the same day as its first posting here — as a new operation built on leaked Babuk source code, unrelated to the dormant 2021 brand of a similar name. And the record half is not gangs re-posting each other's old victims, the recycling behavior documented around brand collapses: only 2.4% of H1 2026 postings name a victim previously claimed by a different gang.
The US regulatory mirror
While the criminal record set records abroad, the American regulatory record ticked along. Measuring filing growth honestly requires an admission most trackers never make: coverage drift. Our raw state-AG total moved from 3,454 filings in H1 2025 to 3,477 in H1 2026 — “flat” — but that number is uninterpretable, because we gained two states (Texas and Massachusetts onboarding added roughly 640 filings) and lost volume in four others to our own collection outages and portal changes (Montana 274→18, Maryland 243→63, Oregon 157→83, Idaho 73→8). None of that is victim behavior. The honest subset is the four states our collectors covered continuously and healthily in both halves:
Indiana, New Hampshire, Vermont, and California — the four states with verified healthy collection in both halves (no zero-months). Total: 1,946 → 2,032, +4.4%. California's dip is within its normal month-to-month volatility.
Four-point-four percent. Against a 17% rise in global criminal publication — and, more tellingly, against flat US criminal publication — the US compliance channel looks stable to slowly growing. At the federal securities level, the numbers are smaller still: 13 SEC Item 1.05 cyber 8-Ks in six months (24 counting filings that disclosed cyber incidents under the catch-all Item 8.01) — against thousands of state filings. The SEC's materiality hurdle keeps the national-exchange disclosure channel a boutique record.
Where the two records meet
The natural question — how often does a leak-site victim later appear in the regulatory record? — is the subject of its own study we're publishing separately. The short version, from our 2024 US cohort: only about 1 in 5 identifiable US organizations posted on leak sites can be matched to any regulatory filing, and where a filing exists it landed a median 107 days after the criminals had already published the victim. Those numbers describe the 2024 cohort, not this half; the full method, matching audit, and limitations ship with that piece.
Method & limitations
Corpus. DisclosureLens continuously ingests 22 disclosure sources: 17 US state attorney-general breach registries, HHS OCR, SEC EDGAR, EU DPA enforcement decisions, press coverage, and ransomware leak-site claims. Snapshot date for every number in this report: July 31, 2026.
Counting. A “posting” is one deduplicated leak-site claim naming one victim organization. Deduplication happens at ingest: claims are content-hashed, and re-captures of the same post do not create new records. A daily completeness sweep re-fetches the full current and previous year from the upstream aggregator, so both halves of the year-over-year comparison are backfilled by the same mechanism (H1 2025's total includes 904 sweep-recovered postings; H1 2026's includes 1,403). Late captures continue to trickle in — H1 2026 gained 257 postings during July — so published counts are floors, and the +17% margin is more likely to widen than shrink.
Allegations, not adjudications. Leak-site postings are criminal claims. Gangs exaggerate and occasionally fabricate; postings are not independently confirmed breaches, and we name no victims from claims in this report.
Geography. Victim-geography tags are LLM-extracted from claim content. 92.9% of H1 2026 postings carry one, against 95.7% a year earlier; the shortfall is not a processing backlog (those postings are fully extracted and simply carry no geography), and the rate is lowest in the newest months — 85% in June — which is why no single-month figure appears here. That leaves 354 untagged H1 2026 postings against 182 in H1 2025, and how they are treated is the one assumption this finding rests on. Measured on tagged postings, US volume fell 2.6% (1,995 → 1,944). Imputing the untagged remainder at each half's own US rate gives +0.4% — flat either way. The arithmetic worst case, in which nearly every untagged 2026 posting is American and almost none of 2025's were, would put US growth near +15%; we consider that implausible, because it requires untagged postings to be roughly twice as American as the tagged ones alongside them, but we state it rather than bury it. The finding was additionally stress-tested by tag-format audit and per-gang decomposition, and holds under both. We therefore report US volume as “roughly flat” rather than as a point estimate.
Gang attribution uses each posting's canonical actor label; brand counts treat labels as brands, and splinter groups sharing infrastructure count separately. Fixed-coverage subset: states qualify by healthy, continuous collection in both compared halves, verified month by month; excluded states' drift is disclosed above rather than blended in. What we deliberately do not claim: a record quarter (the top two quarters are three postings apart — inside backfill noise); any affected-individual counts; any per-victim assertion from a claim alone.
Every figure in this report is reproducible from our database; the SQL behind each number is available on request.
What to watch
If the geography shift holds through H2, the implication is uncomfortable for a US-centric security industry: the ransomware economy is growing around American defenses, American law-enforcement pressure, and American disclosure law — not through them. Threat models, cyber-insurance books, and regulatory debates calibrated on “the US is half the problem” will need recalibrating. DisclosureLens tracks both records — criminal and regulatory — continuously, and flags when a leak-site claim gains (or conspicuously never gains) a regulatory echo. The dataset behind this report is queryable via our API.