The ransomware landscape in 2026 is getting tougher – not because defenses are lacking, but because attacks are moving more “silently” and organizations often realize what’s happening when it’s already too late.

ExtraHop has released its “ 2026 Global Threat Landscape Report ,” presenting findings from a survey of 1,800+ security and IT leaders. The figures that stand out are of immediate interest to CISOs, CIOs , and executives – and are ideal for starting a conversation about investing in detection/response.
Ransomware 2026: The shocking numbers
According to the announcement:
– Attackers had access to corporate networks for nearly 2.5 weeks on average before being detected by victims’ security teams
– 49% of organizations did not identify the threat actor before data was stolen (up from 31% last year).
– 14% only learned of the attack when they received a ransom message (up from 6% previously).
At the same time, ExtraHop notes an interesting “trade-off” from attackers:
– The average ransom payment fell to $2.8 million from $3.6 million in 2025.
– However, the percentage of victims paying rose to 83% from 70%.
Simply put: less money per victim, but more payments overall.
See also: INTERPOL: Phishing, Ransomware and AI Scams Sweep Asia-Pacific
Which “players” dominate the ransomware landscape?
ExtraHop reports that LockBit and RansomHub were the two groups with the most detections for the second year in a row. It also reports that detections related to the group APT41 decreased by 50% compared to last year.
Regardless of whether an organization “sees” all these names in its own telemetry, the message is clear: ransomware ecosystems have matured and operate almost like an “industry.”.

AI: New surface attack, new noise
A key point of the report is that AI adoption opens up new entry points. ExtraHop states that:
– 55% of respondents consider AI agents/agentic infrastructure/GenAI apps to be the biggest attack risk.
– 85% report having experienced an incident or data exposure related to an AI system.
☁️ Keep safe copies with Proton Drive
Encrypted cloud storage from Proton — protect your files from ransomware, corruption, and data loss with end-to-end encryption.
- ✔ End-to-end encrypted files & backups
- ✔ Version history — recover files after ransomware
- ✔ Free space — sync across all devices
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
This doesn't mean that "AI is bad" — but that organizations are putting new systems into production without clear governance, data controls, and monitoring.
See also: INC Ransomware: Over 830 victims since 2023
Why attacks get away: The problem of detection
ExtraHop lists reasons that delay the detection of critical alerts, such as:
– encrypted channels that bypass detection,
– activity that resembles legitimate procedures,
– use of valid high-privilege accounts,
– alert fatigue.
The “key” here is that modern attacks don’t always look like malware outbreaks. They often look like “normal” usage — until ransomware or data theft unfolds.

What does it mean for Greece / businesses / decision makers
For Greek businesses (especially SMEs and organizations with limited SOC), the findings translate into 3 practical conclusions:
1) Ransomware is data theft , then encryption. If you expect to figure it out at encryption, you’re lost.
2) “Silent stay” for weeks is realistic. This requires logging, centralized visibility, and incident response processes.
3) AI adoption requires security by design. Shadow AI and vendor AI integrations can open up new avenues of leakage.
See also: Conti Ransomware member pleads guilty
Practical steps for today
– Invest in visibility (logs/EDR/NDR where it makes sense) and in use cases that capture lateral movement, credential abuse and exfiltration.
– Reduce risk from privileged accounts (MFA, least privilege, PAM where possible).
– IR exercise: tabletop for “data theft + ransomware” (not just “ransomware encryption”).
– Governance for GenAI: which applications are allowed, which data, with which controls.
