Ransomware-as-a-Service Is Splitting Up: What Smaller, Faster Gangs Mean for SMBs 

Ransomware-as-a-Service

For the past few years, the ransomware conversation has centered on a handful of household names: LockBit, ALPHV/BlackCat, RansomHub, Conti’s descendants. Security teams built their threat models around a short list of dominant, professionalized crews. That model, however, is changing. 

2026 has been the year the ransomware-as-a-service (RaaS) economy fractured. Law enforcement takedowns, affiliate defections, and internal power struggles have splintered the old syndicates into a sprawling, fast-moving ecosystem of smaller gangs, many of which are just as capable as their predecessors, and considerably harder to track. For small and midsize businesses, this shift changes the shape of the risk in ways that matter well beyond the security team’s dashboard. 

The Big Gangs Didn't Disappear, They Multiplied

The numbers tell the story. Check Point Research counted a record 93 active ransomware groups in Q2 2026, up from 71 the previous quarter, with the top ten operators’ share of total victims falling from 71% to under 58% in a single three-month span. Black Kite’s annual analysis puts the total even higher: roughly 146 active groups by mid-2026, with new ransomware groups surfacing at an unprecedented rate during the busiest stretch of the year. RansomLook, an open-source leak-site tracker, has logged weeks where dozens of “new” group names appear with functioning extortion infrastructure and confirmed victims already attached. 

This isn’t a story of amateurs flooding the market. When major operations like LockBit and RansomHub were disrupted or went quiet, their affiliates didn’t retire, they took their access, their tooling, and their playbooks and regrouped under new banners. Group-IB has described the shift bluntly: the old RaaS “franchise” model, where a handful of brands controlled distribution, has given way to something more fragmented, more privatized, and harder to disrupt through brand-level takedowns alone. 

Some of these splinter operations have grown explosively. The Gentlemen, founded by a former Qilin affiliate in late 2025, claimed several hundred victims across dozens of countries within months, a growth curve that dwarfs what most legacy groups managed in their first year. Because these newer crews are formed by experienced operators rather than newcomers learning on the job, they typically arrive already equipped with mature tooling, working leak sites, and functional encryption, so no ramp-up period required. 

Why Fragmentation Is a Speed Problem, Not Just a Volume Problem

More groups sounds like it should mean less coordinated, less dangerous cybercrime. In practice, fragmentation has sped everything up. 

RaaS affiliates, the operators who actually breach networks, deploy the malware, and negotiate with victims, are no longer locked into a single platform. When one group is disrupted or a payout dispute sours a relationship, affiliates simply move their access to a competing operation. That mobility means the underground economy self-heals almost instantly after enforcement action, and it means the people carrying out attacks against your network today may have worked under three different group names in the past year. 

The attacks themselves have also compressed dramatically. Recent incident-response data shows the fastest quarter of intrusions now reach data exfiltration in roughly 72 minutes from initial access, down from nearly five hours the year before. AI-assisted tooling is a major driver: newer groups are using it to build ransomware panels, tailor extortion messaging in real time, and automatically triage stolen data for the documents most likely to force a payout, including cyber insurance policies used to calibrate ransom demands. 

For an SMB, the practical effect is this: the old assumption that you’d have hours or days to detect and contain an intrusion before real damage occurs no longer holds reliably. Newer, smaller groups aren’t necessarily more sophisticated engineers than the legacy gangs but they’re operating with less overhead, less internal bureaucracy, and more urgency to prove themselves, which often translates into faster, more aggressive attacks. 

Ransomware-as-a-Service

Why Smaller Businesses Are Squarely in the Blast Radius

It’s tempting to assume this is an enterprise problem that a fragmenting criminal market mostly reshuffles which Fortune 500 company makes headlines next. That assumption doesn’t match how these newer groups choose their targets. 

Splinter groups need victims to establish credibility, and SMBs are frequently the fastest path to that credibility. Smaller organizations tend to have thinner security staffing, fewer layered defenses, and less mature incident response planning while often carrying the same valuable data (customer records, financial information, healthcare data, vendor access) as larger firms. Newer groups, eager to build a track record on their leak site, have every incentive to prioritize targets where the time from access to payout is shortest. That describes a lot of small businesses. 

There’s also a supply-chain dimension. As initial-access brokers and affiliates move fluidly between groups, SMBs that serve as vendors or contractors to larger organizations become attractive not just for their own data, but as a foothold into bigger networks downstream. A breach at a 40-person accounting firm or a regional logistics provider can be the opening move in a much larger attack chain that is planned months ahead. 

Meanwhile, the economics still favor the attacker even as payment rates decline overall. Fewer victims are paying out ransom demands, but the volume of attacks has more than made up the difference; a total disclosed victims rose from roughly 6,000 to over 7,500 in the most recent 12-month period tracked by Black Kite. Fragmentation hasn’t shrunk the threat; it’s distributed it across more actors, more targets, and more entry points. 

What This Means for How SMBs Should Think About Risk

The strategic implication is straightforward, even if it’s uncomfortable: a defense posture built around blocking a short list of known ransomware entities is no longer sufficient. When the threat landscape includes dozens of active groups rotating names, tooling, and affiliates on a quarterly basis, static, signature-based protection increasingly misses the point. What matters now is whether your organization can detect anomalous behavior and unusual access patterns, credential misuse, and lateral movement, regardless of which brand is behind the keyboard that day. 

It also means the “we’re too small to be a target” mindset needs to be retired for good. Smaller, faster-moving affiliate groups aren’t scanning for household names, they’re scanning for exposed remote access tools, unpatched systems, weak or reused credentials, and gaps in multi-factor authentication. Those are exactly the gaps that go unnoticed in businesses that haven’t had a structured look at their own environment recently. 

The Fix: Know Where You're Exposed Before Someone Else Finds Out

Given how quickly this threat landscape shifts, the most valuable thing a small or midsize business can do isn’t chasing headlines about the newest named group, it’s getting a clear, current picture of its own vulnerabilities. Fragmentation means the specific attacker is unpredictable, but the entry points they exploit are consistently the same: unpatched systems, exposed remote access, weak identity controls, and gaps in backup and recovery readiness. 

A structured cyber risk assessment identifies exactly those gaps before an attacker does, mapping your attack surface, testing your defenses against the tactics these groups actually use, and giving you a prioritized, actionable plan rather than a vague sense of unease. In a threat environment defined by speed and unpredictability, that clarity is the difference between catching an intrusion in minutes or finding out about it on a leak site. 

Book a Cybersecurity Assessment

Ready to see where your organization actually stands?

Learn more about our Cyber Risk Assessments and get a clear, prioritized view of your exposure before the next new group finds it for you.

Sources referenced:  

  1. Check Point Research Q2 2026 State of Ransomware – The State of Ransomware Q2 2026 – Check Point Research 
  2. Black Kite 2026 Ransomware Report – 2026 Ransomware Report: 7,551 Victims, Up 24.9%
  3. ReliaQuest Q1/Q2 2026 Threat Spotlight 
  4. Unit 42 2026 Global Incident Response Report  
  5. Group-IB “Ransomware in 2026” analysis.

Under Attack? Guaranteed 15 minute response time.

Please call our emergency hotline below or fill out the form with your name, email, and phone number.

US/CAD

1 800 762 3290

UK

0800 368 8731

AUS

61 1800 413 128

Email

response@cyberclan.com

The information you provide in this form is only used exclusively to assist you. We do not share your data.

Sugandha Sood

Executive Vice President, Finance

As a professional accountant Sugandha, CPA, CGA has over 15 years of progressive finance and accounting experience across multiple industries including healthcare, medical, nuclear waste, and transportation.

Prior to joining CyberClan she worked at Energy Solutions Canada and was responsible for various aspects of accounting, financial reporting, internal controls, process improvements and taxation. Sugandha is eager to leverage her professional skills and play a vital role in the growth of the company by providing information to make informed decisions.