Visualização de leitura
Ransomware Threats in the Americas H1 2026: Dissecting the Regional Attack Patterns and Dominant Actors

The Americas carried the heaviest ransomware burden of any region on the planet in the first half of 2026. According to Cyble Research and Intelligence Labs (CRIL), North and South America combined experienced 2,188 documented ransomware attacks between January and June 2026.
That single figure — 2,188 attacks — represents more than 57% of the 3,836 ransomware incidents CRIL tracked worldwide, making the Americas the undisputed center of gravity for global ransomware operations.
But the Americas is not a single threat theatre — it is two. North America alone absorbed 1,981 attacks, driven by a mature, multi-group Ransomware-as-a-Service (RaaS) economy competing for market share. South America, by contrast, recorded 207 attacks concentrated around a much smaller set of operators, with one group — The Gentlemen — claiming nearly a quarter of all regional incidents outright. Understanding the Americas means understanding both halves of that story: a saturated northern market and a consolidating southern one.
North America vs. South America: Two Distinct Ransomware Landscapes
Security leaders operating across the hemisphere cannot apply a single threat model to both sub-regions. The data shows meaningfully different attacker behavior, concentration, and monetization strategy north and south of the equator.
| Metric | North America | South America |
| Ransomware Attacks | 1,981 | 207 |
| Dominant Ransomware Actor | Qilin (370 attacks) | The Gentlemen (46 attacks) |
| Top Targeted Sector | Construction | IT & ITES |
| Top Targeted Nation | United States (1,721) | Brazil (71) |
| Distinct Ransomware Groups Active | 50+ | 30+ |
| % of Attacks from Top 3 Groups | ~40% (Qilin, Akira, INC Ransom) | ~57.5% (The Gentlemen, Qilin, LockBit) |
Why the split matters: North America's threat landscape is a genuine marketplace — dozens of RaaS operators compete for affiliate loyalty, and no single group commands more than a fifth of total volume. South America's landscape is more consolidated, with three groups controlling well over half of all attacks.
For defenders, that means North American organizations need broad-spectrum threat intelligence covering a long tail of active groups, while South American organizations can build highly specific defenses against a short list of named adversaries.
The Five Dominant Ransomware Groups Targeting Americas
Across both sub-regions combined, five ransomware operators account for the overwhelming share of documented activity: Qilin, Akira, INC Ransom, Dragonforce, and The Gentlemen. Together, these five groups are linked to roughly 1,148 of the Americas' 2,188 attacks — approximately 52.5% of all regional ransomware activity.

1. Qilin: The Biggest Ransomware Threat in the Americas
Attack Volume: 410 documented incidents across the Americas (370 in North America, 40 in South America) — 18.7% of the regional total.
Qilin is the single most prolific ransomware actor operating in the hemisphere, and its dominance is not evenly spread — it is concentrated hardest in the United States.
Geographic Concentration:
- United States: 323 attacks (the single largest country-level concentration of any group, anywhere)
- Canada: 33 attacks
- Argentina: 13 attacks
- Broader South America: 40 attacks
Worldwide Sectoral Targeting: Qilin's targeting logic is deliberate rather than opportunistic:
- Construction: 108 incidents (primary focus)
- Professional Services: 90 incidents (legal, accounting, consulting firms)
- Manufacturing: 67 incidents
- Healthcare: 53 incidents
- IT & ITES: 43 incidents
Operational Characteristics:
Qilin's affiliate model is built for scale. Initial access brokers handle reconnaissance and compromise, mid-tier operators manage lateral movement, and dedicated crews execute encryption and exfiltration. This compartmentalization lets Qilin run dozens of concurrent operations across the United States without any single point of failure. The group's near-total dominance of the American ransomware market (323 of 1,721 US attacks) suggests either an unusually large affiliate roster or a payout structure attractive enough to pull operators away from competing platforms.
Why Qilin Dominates:
- Affiliate Loyalty: Competitive payout splits keep operators recruiting and retaining talent
- Rapid Exploit Weaponization: Fast turnaround from vulnerability disclosure to active exploitation
- Sector Fluency: Deep understanding of which industries face the highest downtime cost
- Established Data Brokerage Ties: Exfiltrated data reliably reaches monetization channels
Americas Security Implications: Any organization in construction, professional services, manufacturing, or healthcare operating in the US or Canada should treat Qilin as a primary named threat, not a generic ransomware risk.
2. Akira: North America's Persistent Operator
Attack Volume: 268 documented incidents, almost entirely concentrated in North America — 12.2% of the regional total
Akira is the second most active group in the Americas, and unlike Qilin, its footprint is almost exclusively North American. CRIL's data shows Akira's South American presence is negligible to date.
Geographic Concentration:
- United States: 247 attacks (92% of Akira's total Americas volume)
- Canada: Remaining North American activity
- South America: Minimal to no confirmed activity
Worldwide Sectoral Targeting:
- Construction: 57 incidents
- Manufacturing: 54 incidents
- Professional Services: 47 incidents
- Consumer Goods: 19 incidents
- IT & ITES: 16 incidents
Operational Characteristics:
Akira has built a reliable playbook around compromising small-to-medium-sized businesses through unpatched public-facing network devices, then pivoting into construction and manufacturing environments where downtime tolerance is lowest. The group's consistency — rather than explosive growth — is its defining trait; it has neither the explosive scale of Qilin nor the geographic diversification of The Gentlemen, but it reliably executes against the same target profile month after month.
Americas Security Implications: North American SMBs in construction, manufacturing, and professional services should assume Akira is actively scanning for exposed remote access infrastructure. Its South American absence should not be mistaken for permanence — RaaS groups expand geographically once North American markets saturate.
3. INC Ransom: The Law-Firm Specialist
Attack Volume: 171 documented incidents (164 in North America, 7 in South America) — 7.8% of the regional total
INC Ransom distinguishes itself through sector specialization rather than volume. The group shows a clear, repeated preference for Professional Services organizations — particularly law firms — leveraging the sensitive, high-stakes nature of legal client data.
Geographic Concentration:
- United States: 154 attacks
- Canada: 6 attacks
- Brazil: 4 attacks
Worldwide Sectoral Targeting:
- Professional Services: 58 incidents (primary focus, with a documented preference for law firms)
- Construction: 27 incidents
- Manufacturing: 26 incidents
- Healthcare: 21 incidents
- Organisation/Non-profit: 12 incidents
Operational Characteristics:
INC Ransom's rapid operational pace and consistent targeting of law firms, healthcare providers, and transportation/energy operators reflects a strategy built entirely around double-extortion leverage. The sensitivity of the data matters more than the size of the victim. A regional law firm holding privileged client communications is, to INC Ransom, a more valuable target than a much larger manufacturer with less sensitive data.
Americas Security Implications: Law firms, accounting practices, and consulting shops across the US, Canada, and Brazil should assume INC Ransom is actively targeting client confidentiality as leverage — not just encrypting file servers for disruption.
4. Dragonforce: The Cross-Border Supply-Chain Operator
Attack Volume: 153 documented incidents (148 in North America, 5 in South America) — 7.0% of the regional total
Dragonforce maintains an aggressive operational tempo focused heavily on the United States, with a strategy that suggests supply-chain-aware targeting rather than random opportunism.
Geographic Concentration:
- United States: 135 attacks
- Canada: 11 attacks
- South America: 5 attacks
Worldwide Sectoral Targeting:
- Construction: 48 incidents
- Manufacturing: 31 incidents
- Professional Services: 28 incidents
- IT & ITES: 18 incidents
- BFSI: 17 incidents
Operational Characteristics:
Dragonforce's manufacturing and construction focus mirrors Qilin's and Akira's playbooks, but its concentration in the US combined with limited-but-present South American activity hints at interest in transnational manufacturing supply chains. North American organizations with manufacturing partners or subsidiaries in Latin America should treat this as a lateral-access risk, not just a direct-targeting one.
Americas Security Implications: Manufacturers and construction firms with cross-border operations — a common structure across USMCA supply chains — should extend Dragonforce-specific monitoring to subsidiaries and vendors, not just headquarters networks.
5. The Gentlemen: South America's Dominant Threat
Attack Volume: 146 documented incidents (100 in North America, 46 in South America) — 6.7% of the regional total, but the single most active ransomware group in South America specifically.
While The Gentlemen rank fifth across the combined Americas, they are the #1 threat actor in South America on their own — responsible for roughly 22% of every ransomware attack recorded in that sub-region.
Geographic Concentration:
- United States: 77 attacks
- North America: 100 attacks
- Brazil: 15 attacks
- South America: 46 attacks (largest single-group share in the sub-region)
Worldwide Sectoral Targeting:
- Manufacturing: 56 incidents
- Construction: 45 incidents
- Healthcare: 37 incidents
- IT & ITES: 36 incidents
- Consumer Goods: 34 incidents
Operational Characteristics:
The Gentlemen are a relatively new operator that has achieved outsized scale in a short window, and their South American concentration is the most important regional signal in this dataset. Unlike Qilin or Akira — which built North American dominance first and are only beginning to diversify — The Gentlemen appear to have prioritized South America as a primary theatre from early in their operational life, an unusual strategic choice that may reflect lower defensive maturity, less aggressive law enforcement cooperation, or simply less competitive pressure from other RaaS operators in the sub-region.
Americas Security Implications: South American organizations — especially in healthcare, manufacturing, and IT services — should treat The Gentlemen as their single highest-priority named adversary. North American organizations should not discount them either; 100 US-focused attacks is a substantial footprint for a group still building its brand.

Other Notable Threats: Play, LockBit, and CL0P
Three additional groups warrant inclusion in any Americas threat model:
- Play (144 attacks, North America only): Continues its "Big Game Hunting" approach layered with high-volume SMB attacks via unpatched public-facing network devices, concentrated almost entirely on US and Canadian construction, professional services, and manufacturing targets.
- LockBit (80 attacks combined — 47 in North America, 33 in South America): Despite sustained international law enforcement pressure and repeated takedown attempts, LockBit remains operationally resilient across both sub-regions, notably compromising Chile's Clínica Dávila in South America.
- CL0P (93 attacks combined — 91 in North America, 2 in South America): Operated differently from its peers, executing a large-scale campaign concentrated in January and February 2026 that exploited a single zero-day vulnerability across hundreds of organizations at once — reminiscent of the group's historical MOVEit campaign.
Also read: The Most Active Threat Actors of H1 2026
The Five Most Targeted Nations in the Americas

United States: The Global Ransomware Epicenter
Attack Volume: 1,721 ransomware attacks — 78.7% of all Americas ransomware activity, and roughly 45% of every ransomware attack recorded worldwide.
No other country on Earth comes close to the volume of ransomware activity absorbed by the United States in H1 2026. The country functions as the default target for nearly every major RaaS operator active today.
Threat Actor Concentration:
- Qilin: 323 attacks
- Akira: 247 attacks
- INC Ransom: 154 attacks
- Dragonforce: 135 attacks
- Play: 134 attacks
Sectoral Breakdown: Manufacturing, Professional Services, Construction, and Healthcare bear the brunt, consistent with the broader North American pattern of operationally sensitive, low-downtime-tolerance industries.
Why the United States Faces Maximum Pressure
The scale of the US economy, its dense concentration of mid-market manufacturers, law firms, and healthcare providers, and its comparatively high ransom-payment history combine to make it the most economically rational target for every major ransomware operator. US organizations also frequently anchor cross-border supply chains stretching into Canada, Mexico, and South America — meaning a US compromise can cascade into lateral access against hemispheric partners.
Defensive Priority: US organizations across construction, manufacturing, professional services, and healthcare should assume Qilin, Akira, INC Ransom, Dragonforce, Play, and The Gentlemen are all actively scanning for exploitable entry points into their networks simultaneously — not sequentially.
Canada: The Cross-Border Extension
Attack Volume: 179 ransomware attacks — 8.2% of the regional total.
Canada's threat profile closely tracks the United States, reflecting deep economic integration and shared supply chains rather than a distinct targeting logic of its own.
Sectoral Breakdown: Manufacturing, professional services, and construction dominate, mirroring the US pattern almost directly.
Why Canada Faces Sustained Pressure
Canadian organizations are frequently subsidiaries, suppliers, or joint-venture partners of US enterprises, which means the same RaaS groups saturating the US market extend naturally northward. Cross-border manufacturing in particular creates lateral access opportunities that Dragonforce and Akira appear well-positioned to exploit.
Defensive Priority: Canadian organizations should not assume distance from US headquarters provides insulation — the same threat actors, exploiting the same vulnerability classes, are already active on both sides of the border.
Brazil: The Financial Malware and Ransomware Convergence Point
Attack Volume: 71 ransomware attacks — 3.2% of the regional total, but the largest single concentration in South America.
Brazil represents South America's most complex threat environment, combining traditional ransomware pressure with a maturing, sophisticated financial malware ecosystem.
Threat Actor Concentration: The Gentlemen (15 attacks), LockBit, and a fragmented tail of smaller operators.
Sectoral Breakdown: Government & Law Enforcement, BFSI, and Healthcare are the most consistently targeted sectors.
Why Brazil Faces a Dual Threat
Beyond ransomware, Brazil emerged in H1 2026 as a focal point for new Android banking trojan families — TCLBANKER and BTMOB RAT — which use self-propagation, evasion techniques, and Malware-as-a-Service (MaaS) distribution models to target banking and cryptocurrency users directly. Brazil also suffered an alleged 250-million-record breach of Serasa, one of the country's largest credit bureaus, alongside an access sale allegedly targeting the Central Bank of Brazil — a listing that, if genuine, represents one of the most significant initial-access offerings tracked anywhere in the report.
Defensive Priority: Brazilian financial institutions should treat mobile banking malware and ransomware as converging risks rather than separate problems — the same underground economy is monetizing both. Government and BFSI entities should assume access-broker listings referencing critical national infrastructure require immediate incident-response-level validation, not routine monitoring.
Mexico: The Emerging Nearshoring Risk
Attack Volume: 39 ransomware attacks — 1.8% of the regional total.
Mexico's attack volume is meaningfully lower than the US, Canada, or Brazil, but its position within North American manufacturing supply chains — accelerated by ongoing nearshoring trends — makes it a nation to watch closely rather than dismiss.
Why Mexico Warrants Increased Attention
As global manufacturers continue relocating production closer to the US market, Mexican facilities increasingly sit inside the same supply chains that Dragonforce, Akira, and Qilin already target aggressively north of the border. Lower current attack volume may reflect earlier-stage targeting rather than lower risk — a pattern security teams should not mistake for durable safety.
Defensive Priority: Manufacturers with Mexican operations should extend the same OT/IT segmentation and vulnerability management discipline applied to US and Canadian facilities to their Mexican sites, rather than treating them as lower priority.
Colombia: Where Hacktivism Meets Cybercrime
Attack Volume: 33 ransomware attacks — 1.5% of the regional total.
Colombia's ransomware volume is modest, but the country stands out for the density of ideologically motivated activity layered on top of financially driven attacks.
Why Colombia Faces a Blended Threat
Groups such as Anonymous Colombia (#OpColombia) ran active campaigns throughout H1 2026 blending website defacement, DDoS attacks, and data leak activity — consistent with the broader South American pattern in which hacktivist-branded channels frequently overlap with financially motivated cybercrime infrastructure.
Defensive Priority: Colombian government and law enforcement entities — the most frequently targeted sector across South America overall — should treat hacktivist claims as credible threat intelligence signals rather than dismissing them as purely ideological noise.
Where Americas Organizations Face Maximum Risk: A Sectoral Analysis
Professional Services: One of the Top Targets
Attack Volume: The second most heavily impacted sector in North America.
Professional services firms — law, accounting, and consulting practices — are one of the top jobs on North America's ransomware target list, driven overwhelmingly by INC Ransom and AiLock's aggressive targeting of client-confidential data.
Why Professional Services Are Targeted
- Privileged Data Concentration: Legal privilege and client confidentiality create existential regulatory and reputational exposure that threat actors exploit for maximum ransom leverage.
- Regulatory Pressure: Breach notification requirements incentivize rapid ransom payment to avoid compounding disclosure penalties.
- Trust-Based Business Model: A single confirmed breach can permanently damage client relationships built entirely on confidentiality.
- Documented Actor Preference: INC Ransom has shown a specific, repeated preference for law firms — this is not incidental targeting.
Notable Incident Pattern: AiLock's activity stood out for a coordinated wave of victim disclosures on a single day — March 3, 2026 — a pattern consistent with mass-exploitation of a shared vulnerability rather than individually researched targeting.
Defensive Recommendations:
- Segregate client data on separate network segments with distinct, audited access controls
- Deploy data loss prevention (DLP) with aggressive egress monitoring for client-data exfiltration
- Maintain comprehensive access logs for all sensitive client-data touchpoints
- Evaluate ransomware-specific cyber insurance addressing confidentiality exposure
Construction and Manufacturing: The Downtime Economy
Attack Volume: Construction and Manufacturing rank first and third in North America; combined, they represent the largest share of Qilin, Akira, Dragonforce, and The Gentlemen's worldwide targeting.
Constructions and manufacturing share a common vulnerability across the Americas: both operate on tight, contractually enforced timelines where downtime translates directly into cascading financial penalties.
Why Construction and Manufacturing Are Targeted
- Time-Sensitive Financial Exposure: Missed construction deadlines trigger contractual penalties; halted production lines trigger lost revenue and breached delivery commitments.
- OT/IT Convergence: Modern factories and job sites increasingly integrate operational technology with corporate IT, creating exploitation bridges unavailable in pure-IT industries.
- Supply-Chain Complexity: Both industries depend on dense webs of subcontractors and suppliers — compromising one upstream partner can provide lateral access into prime contractors.
- Cross-Border Exposure: US-Canada-Mexico manufacturing integration (and increasingly, US-Brazil trade relationships) means a single compromise can propagate across national borders.
Defensive Recommendations:
- Implement airgapped network segmentation between OT and corporate IT environments
- Prioritize vulnerability patching for network appliances and identity systems over blanket patch cycles
- Maintain fully offline, immutable backups of critical project and production data
- Extend third-party risk assessments to subcontractors, suppliers, and cross-border subsidiaries
Healthcare: South America's Critical Infrastructure Threat
Attack Volume: One of the top four most heavily impacted sectors in South America.
Healthcare organizations across the Americas — but particularly in South America — face a threat dynamic distinct from financial pressure alone: ransomware attacks against hospitals directly endanger patient safety.
Why Healthcare Is Targeted
- Patient Safety Leverage: Downtime in diagnostic systems, pharmaceutical dispensing, and patient records directly threatens continuity of care, creating existential pressure to pay quickly.
- Documented Regional Incidents: The Gentlemen's claimed attack on Primero Medicina Privada and LockBit's compromise of Chile's Clínica Dávila both illustrate ransomware groups' willingness to target hospital networks directly.
- Data Value: Patient medical records and clinical data command premium prices on dark web marketplaces.
- System Complexity: Healthcare IT environments blend legacy diagnostic equipment, electronic health records, and connected medical devices — each with distinct security postures.
Defensive Recommendations:
- Implement complete network isolation between clinical systems and corporate IT
- Deploy redundant diagnostic and pharmaceutical systems capable of manual fallback operation
- Encrypt all patient medical records end-to-end
- Build healthcare-specific incident response plans addressing patient notification and continuity of care
Agriculture & Livestock: The Americas' Emerging Supply-Chain Target
Attack Volume: 33% of all North American initial access listings — the second-most targeted sector in the region's access brokerage market.
A distinctive Americas finding: initial access brokers targeting the region show unusually strong interest in Agriculture & Livestock, second only to Technology.
Why Agriculture & Livestock Is an Emerging Target
North America's food supply chain increasingly depends on connected logistics, cold-chain monitoring, and precision agriculture technology — creating an attack surface that did not meaningfully exist a decade ago. Access brokers appear to be positioning themselves ahead of ransomware operators, selling footholds into agricultural operations before ransomware crews weaponize them. This mirrors a pattern seen elsewhere globally but is particularly pronounced in North America's access brokerage data.
Defensive Recommendations:
- Treat agricultural technology platforms (precision ag, cold-chain IoT) with the same security rigor as manufacturing OT
- Monitor initial access broker markets specifically for agriculture and food-sector listings
- Build incident response plans accounting for food-supply-chain continuity, not just data confidentiality
Geopolitical and Ideological Dimensions: Hacktivism Across the Hemisphere
SOLDADOS DIGITALES – UNIÓN AMERICANA: A Hemispheric Hacktivist Collective
Unlike most hacktivist channels tracked in this report, SOLDADOS DIGITALES – UNIÓN AMERICANA operates across both North and South America, making it one of the few genuinely hemispheric threat actors identified in H1 2026 — a significant finding given how regionally siloed most hacktivist activity tends to be.
Combined Hacktivism Metrics (North + South America):
- ~140 confirmed data leak and dump posts across both sub-regions
- At least 932 unique domains impacted (360 in North America, 572 in South America)
- Primary targets: Government & LEA, Technology, BFSI, Telecommunication, Education
Notable Collectives by Sub-Region:
- North America: SOLDADOS DIGITALES – UNIÓN AMERICANA, Anonymous #FreeTurtleIsland, KERALA HACKERS, LYSTIC TEAM #ID
- South America: SOLDADOS DIGITALES – UNIÓN AMERICANA, Anonymous Colombia (#OpColombia) Y.A.N, BLAZER TEAM ATTACK
The Convergence Problem: As with hacktivist activity documented elsewhere in CRIL's global dataset, several Americas-based channels marketed as ideological collectives function as hybrid operations — logging DDoS attacks and defacement claims alongside stolen-data brokerage and DDoS-for-hire services. Security teams should treat these channels as credible threat intelligence sources rather than dismissing their claims as purely political theater.
Regional Threat Actor Summary: Who Targets Your Americas Organization
If You're in Professional Services:
- Primary Threat: INC Ransom, Qilin
- Secondary Threat: AiLock, The Gentlemen
- Vulnerability: Client data exfiltration, regulatory breach-notification pressure
- Defensive Focus: DLP, client data segregation, ransomware-specific cyber insurance, cyber threat intelligence
If You're in Manufacturing or Construction:
- Primary Threat: Qilin, Akira, Dragonforce
- Secondary Threat: The Gentlemen, Play
- Vulnerability: OT/IT convergence, cross-border supply-chain exposure, contractual downtime penalties
- Defensive Focus: OT segmentation, immutable backups, cross-border third-party risk management
If You're in Healthcare:
- Primary Threat: The Gentlemen (South America), Qilin (North America)
- Secondary Threat: LockBit
- Vulnerability: Patient-safety leverage, legacy medical device integration
- Defensive Focus: Clinical system isolation, redundant critical systems, patient-notification-ready incident response
If You're in BFSI:
- Primary Threat: Data exfiltration actors, mobile banking malware (Brazil)
- Secondary Threat: Qilin, The Gentlemen
- Vulnerability: Financial data value, mobile malware convergence, regulatory exposure
- Defensive Focus: DLP with aggressive egress controls, mobile threat monitoring, data encryption
If You're in Agriculture & Livestock:
- Primary Threat: Initial access brokers
- Secondary Threat: Downstream ransomware operators exploiting sold access
- Vulnerability: Precision agriculture and cold-chain IoT exposure
- Defensive Focus: OT-equivalent segmentation for agricultural technology, access-broker monitoring
If You're in Government & Law Enforcement (South America specifically):
- Primary Threat: RALord/Nova, CoinbaseCartel, hacktivist-branded channels
- Secondary Threat: LockBit, The Gentlemen
- Vulnerability: Public-sector data value, hybrid ideological/financial targeting
- Defensive Focus: Treat hacktivist claims as credible intelligence, harden citizen-data repositories
Strategic Defense Recommendations for Americas Organizations
Based on CRIL's H1 2026 regional data, Americas security leaders should prioritize defensive investment in the following sequence.
Phase 1: Critical Infrastructure Protection (30 days)
- Inventory Network Appliances: Document every internet-facing firewall, VPN, and security gateway
- Patch Critical CVEs: Prioritize Ivanti, Fortinet, Cisco, SolarWinds, and Palo Alto Networks appliances — the vendors repeatedly appearing in both the CISA KEV catalog and active exploitation campaigns
- Harden Remote Access: Enforce phishing-resistant MFA on all administrative and remote access paths
- Deploy Behavioral Monitoring: Watch for anomalous activity on network appliances specifically
Phase 2: Data Protection (60 days)
- Data Inventory: Catalog sensitive holdings — client data, financial records, patient records, intellectual property
- DLP Implementation: Deploy data loss prevention with aggressive egress monitoring
- Encryption Standards: Enforce encryption in transit and at rest across all sensitive data stores
- Access Auditing: Maintain comprehensive logs for every access event touching sensitive data
Phase 3: Operational Resilience (90 days)
- Immutable Backups: Establish offline, immutable backup infrastructure isolated from production networks
- Sector-Specific Incident Response: Build playbooks addressing construction project continuity, manufacturing downtime, and healthcare patient-safety scenarios specifically
- Cross-Border Continuity Planning: For organizations with US-Canada-Mexico or US-Brazil operations, extend continuity plans across all connected facilities
- Recovery Testing: Conduct quarterly backup restoration drills to verify actual recovery capability
Phase 4: Threat Hunting and Detection (Ongoing)
- Named-Actor Threat Intelligence: Subscribe to intelligence feeds tracking Qilin, Akira, INC Ransom, Dragonforce, and The Gentlemen specifically
- Access-Broker Monitoring: Track listings for organizational exposure
- Supply-Chain Monitoring: Continuously assess vendor and subsidiary security posture across borders
- Mobile Malware Awareness (Brazil-specific): Financial institutions should monitor for TCLBANKER- and BTMOB RAT-style Android banking trojan activity targeting customers
Conclusion: The Americas Ransomware Reality
The Americas is not just the largest ransomware theatre in the world by volume — it is two distinct threat environments operating under a single regional label. North America hosts a saturated, competitive RaaS marketplace where no single group dominates outright. South America is consolidating around a smaller set of operators, led decisively by The Gentlemen.
Key Takeaways:
- The Americas carries the global center of gravity: 2,188 of the world's 3,836 documented ransomware attacks (57%) struck North or South America in H1 2026.
- Five groups anchor the threat: Qilin (410), Akira (268), INC Ransom (171), Dragonforce (153), and The Gentlemen (146) collectively account for over half of all Americas ransomware activity — but their dominance splits sharply by sub-region.
- North America and South America require different playbooks: North America's threat model demands broad coverage against a long tail of competing operators; South America's demands deep, specific defense against The Gentlemen, Qilin, and LockBit.
- The United States remains the world's single largest target: 1,721 attacks — nearly 45% of global ransomware volume — makes the US the default target for virtually every major RaaS operator active today.
- Brazil's threat is compounding, not singular: ransomware, mass data breach, and mobile banking malware are converging in the same underground economy targeting the same financial institutions.
- Sector risk follows economic logic, not chance: Professional Services, Manufacturing, Construction, Healthcare, and — distinctively for the Americas — Agriculture & Livestock face targeting because threat actors have identified specific, exploitable economic pressure points in each.
- Access brokers are a leading indicator: a small number of sellers control the region's initial access market and routinely precede ransomware deployment by weeks.
For security leaders across North and South America, the strategic imperative is the same even where the tactical details diverge: know which named actors are active in your specific country and sector, prioritize risk-based patching over blanket cycles, treat data exfiltration as inevitable rather than optional, and build recovery infrastructure that assumes an attack will happen — not one that hopes it won't. The data confirms the Americas will remain the world's most heavily targeted ransomware region through the remainder of 2026. The only open question is how prepared each organization chooses to be.
Frequently Asked Questions (FAQs)
How many ransomware attacks hit the Americas in H1 2026?
2,188 documented ransomware attacks were observed across North and South America in H1 2026, according to Cyble Research and Intelligence Labs (CRIL) findings.
Which ransomware group is most active in the Americas in H1 2026?
Qilin is the most active group across the combined Americas, with 410 documented attacks (370 in North America, 40 in South America). Within South America specifically, however, The Gentlemen — not Qilin — is the dominant actor.
How many ransomware attacks hit North America in H1 2026?
CRIL recorded 1,981 ransomware attacks in North America during H1 2026, representing roughly 52% of all ransomware activity tracked worldwide.
How many ransomware attacks targeted the US in H1 2026? Is it the highest?
Yes. CRIL observed 1,721 ransomware attacks targeted at the US — which is 78.7% of the American continent (North and South, both), and nearly 45% of every ransomware attack recorded worldwide.
Which sector was the most targeted in South America?
IT & ITES remained the most targeted sector in South America for H1 2026.
Ransomware actors targeted which country the most in South America?
Brazil. With 71 attacks, it was the prime target of ransomware actors in H1 2026.
Is Brazil a significant ransomware target?
Yes. Brazil recorded 71 ransomware attacks — the highest total in South America — and additionally faced an alleged 250 million record breach at credit bureau Serasa, an access sale allegedly targeting the Central Bank of Brazil, and new Android banking trojan families (TCLBANKER, BTMOB RAT) targeting financial and cryptocurrency users.
What is the most targeted industry in the Americas?
Construction tops North America's target list, while IT & ITES, Healthcare, and Professional Services top South America's. Across the whole Americas, Construction and Manufacturing remain consistently high-risk due to their low tolerance for operational downtime.
The post Ransomware Threats in the Americas H1 2026: Dissecting the Regional Attack Patterns and Dominant Actors appeared first on Cyble.
How the World’s Most Active Ransomware Operation Expanded in H1 2026

Download the Cyble H1 2026 Cyber Threat Landscape Report for the full analysis.
Breaking Down the Qilin Ransomware Operation
Qilin’s activity was particularly significant in North America, where the group accounted for 370 ransomware attacks during H1 2026. This represented nearly one-fifth of all ransomware incidents recorded in the region.
The group also maintained a strong presence in Europe and the UK, claiming 158 attacks, while Asia-Pacific recorded 64 incidents linked to Qilin. In South America, the group was responsible for 40 attacks, further demonstrating its ability to operate across diverse geographic environments.
Rather than concentrating on a single market, Qilin followed a broad targeting strategy designed to maximize opportunities across industries.
Targeting Sectors Where Downtime Hurts Most
Qilin’s victim profile reflected a common ransomware strategy: focusing on organizations where operational disruption creates immediate pressure. Manufacturing organizations remain especially attractive because ransomware incidents can interrupt production lines and affect supply chains. Healthcare organizations face additional pressure due to the critical nature. Construction, Healthcare, and Professional Services were among the sectors most frequently targeted. These industries often depend on continuous availability, hold sensitive information, and face significant financial or regulatory consequences when systems are disrupted. Manufacturing organizations remain especially attractive because ransomware incidents can interrupt production lines and affect supply chains. Healthcare organizations face additional pressure due to the critical nature of their services and the sensitivity of patient information. Professional Services firms, including legal and consulting organizations, also represent valuable targets because they manage confidential client data that can increase the impact of double-extortion campaigns.The RaaS Model Behind Qilin’s Growth
Qilin’s success reflects the maturity of the ransomware-as-a-service model. Instead of relying on a single internal team to handle every stage of an attack, RaaS groups operate through specialized ecosystems that include affiliates, initial access brokers, and other underground service providers. This structure allows ransomware brands to expand quickly, launch simultaneous campaigns, and maintain activity even as individual operators face disruption. The continued success of groups like Qilin shows why ransomware remains difficult to contain. Law enforcement actions and infrastructure takedowns can affect individual operations, but decentralized affiliate models allow new campaigns to continue.Defending Against the Qilin Threat
The group’s activity reinforces several priorities for organizations: reducing exposed attack surfaces, strengthening identity controls, monitoring suspicious access activity, and preparing for data theft alongside encryption. Since ransomware operators increasingly rely on stolen credentials and compromised infrastructure, security programs must focus on preventing initial access as much as responding to active attacks.To explore Qilin’s attack patterns, global ransomware trends, targeted industries, and the broader threat landscape observed in H1 2026, download the complete Cyble H1 2026 Cyber Threat Landscape Report.
June 2026 Dark Web Breach Incident Trend Report
6.9 million driver’s license numbers stolen from AssuranceAmerica
Insurance provider AssuranceAmerica has confirmed a data breach affecting the personal information and driver’s license numbers of up to 6.9 million people.
AssuranceAmerica provides car and rental insurance to customers across 14 US states through a network of over 9,500 independent agents.
TechCrunch reports:
“AssuranceAmerica said it discovered hackers in its computer systems on March 17. The company concluded its investigation on June 15, finding that the hackers had stolen customers’ names, contact information, and driver’s license numbers.“
The breach notice letter also mentions information about customers’ auto insurance policies and accounts, their drivers and vehicles, and details about customer claims.
AssuranceAmerica has not yet released a public statement about the data breach. However, public breach notices and independent reporting indicate that the incident began with a targeted phishing attack against a single employee. An unauthorized third party accessed parts of the insurer’s IT systems and copied files containing customer policy information and driver’s license numbers. So far, no law‑enforcement or vendor report has publicly linked this activity to a specific threat group, ransomware operation, or nation‑state actor.
No public source has reported a ransom demand, negotiations, or payment, and AssuranceAmerica’s public filings are quiet about any contact with the attackers.
Protecting yourself after a data breach
There are some actions you can take if you are, or suspect you may have been, the victim of a data breach.
- Check the vendor’s advice. Every breach is different, so check with the vendor to find out what’s happened and follow any specific advice they offer.
- Change your password. You can make a stolen password useless to thieves by changing it. Choose a strong password that you don’t use for anything else. Better yet, let a password manager choose and store one for you.
- Enable two-factor authentication (2FA). If you can, use a FIDO2-compliant hardware key, laptop, or phone as your second factor. Some forms of 2FA can be phished just as easily as a password. 2FA that relies on a FIDO2 device can’t be phished.
- Watch out for impersonation scams. Criminals may contact you pretending to be the company. Check the company’s website to see how it is contacting affected customers, and verify anyone who contacts you using a different communication channel.
- Take your time. Phishing attacks often impersonate people or brands you know, and create a false sense of urgency with messages about missed deliveries, suspended accounts, or security alerts.
- Consider not storing your card details. It’s definitely more convenient to get sites to remember your card details for you, but we highly recommend not storing that information on websites.
- Set up identity monitoring. Identity monitoring alerts you if your personal information is found being traded illegally online and helps you recover if your identity is stolen.
Check your personal data exposure
You can check whether any of your personal information has been exposed using our Digital Footprint portal. Enter the email address you use most often and we’ll generate a free Digital Footprint report.
AssuranceAmerica Data Breach: 6.9M Driver’s License Numbers Exposed
AssuranceAmerica says hackers accessed the driver's license data of 6.9 million customers, exposing personal information and raising concerns about identity theft.
The post AssuranceAmerica Data Breach: 6.9M Driver’s License Numbers Exposed appeared first on TechRepublic.
AssuranceAmerica Breach Exposes 7 Million Driver’s Licenses After Employee Account Hack
AssuranceAmerica confirmed a breach exposing nearly 7 million driver’s licenses after hackers compromised an employee account and stole customer data.
U.S. auto insurer AssuranceAmerica has confirmed a data breach affecting nearly 7 million people, making it the largest known theft of Americans’ driver’s license information in 2026.
“In a data breach notice sent to customers and seen by TechCrunch, AssuranceAmerica said it discovered hackers in its computer systems on March 17.” TechCrunch reported. “The company concluded its investigation on June 15, finding that the hackers had stolen customers’ names, contact information, and driver’s license numbers.”
The company operates across more than a dozen states through a network of over 9,500 independent agents, handling large volumes of customer identity and vehicle data. Notification letters go out July 10.
The attack vector was a compromised employee credential; how that credential was stolen, whether through phishing, infostealer malware, or a third-party compromise, hasn’t been disclosed.
“On March 17, 2026, the Company detected suspicious activity involving certain Company systems that appears to have resulted from malicious activity on March 16, 2026 that targeted one of theCompany’s employees. The Company promptly began an investigation and engaged external computer forensic specialists to help determine what occurred and what data may have been impacted.” reads the data breach notification.
AssuranceAmerica detected the breach on March 17 but didn’t finish reviewing the affected files until June 15, three months later. The company disabled the compromised credentials, cut off unauthorized sessions, isolated affected systems, and notified law enforcement.
The data stolen covers a wide range of customer information, including names, contact details, and driver’s license numbers. The company hasn’t specified what other personal data types were taken, which is a gap that tends to frustrate regulators and affected customers alike.
“During the investigation, the Company determined that an unauthorized third party accessed certain portions of the Company’s informational technology (IT) environment and copied certain data files.” continues the notification.”The Company subsequently conducted a review of the affected files to identify individuals whose personal information may have been contained within those files. Because of the nature of the files involved and the scope of the required review, this file evaluation process was only recentlycompleted (on June 15, 2026), and we are now providing this notice.”
In response to the incident, the company disabled compromised credentials, removed unauthorized sessions, isolated affected systems, notified law enforcement, and strengthened security controls with password resets, monitoring, and employee training.
“The Company has taken, and continues to take, steps to prevent a similar incident from happening in the future. After detecting the activity, the Company disabled compromised credentials, terminated unauthorized sessions, isolated affected systems as appropriate, and notified law enforcement,” continues the notification. “The Company also implemented additional measures designed to enhance the security of its IT systems and data, including resetting passwords, deploying enhanced monitoring and threat detection tools, and providing additional instruction to personnel regarding cybersecurity threats.”
In June, the Texas Parks and Wildlife Department (TPWD) disclosed a data breach affecting around 3 million individuals after a third-party vendor used for hunting and fishing license sales was compromised.
The Texas Parks and Wildlife Department (TPWD) is the state agency responsible for managing and protecting Texas’s natural and recreational resources.
Hackers may have accessed email addresses, physical addresses, phone numbers, driver’s license details, and passport numbers.
The incident was identified through Texas Cyber Command and highlights risks tied to third-party service providers.
Driver’s license numbers are useful for fraud and impersonation in ways that, say, a leaked email address isn’t, they tie directly to identity verification systems used by financial institutions, government services, and increasingly by websites and apps demanding age verification. The more those systems expand, the more valuable license data becomes to attackers, and the bigger the incentive to go after the insurers, governments, and services that hold it.
Follow me on Twitter: @securityaffairs and Facebook and Mastodon
(SecurityAffairs – hacking, data breach)

Ransom & Dark Web Issues Week 2, June 2026
Ransom & Dark Web Issues Week 5, April 2026
Why U.S. Critical Infrastructure Is the Highest-Value Target in the Global Cyber War

The idea that cyber conflict operates quietly in the background no longer holds. What used to be a shadow contest of espionage and occasional disruption has evolved into something far more direct and consequential. Today, the cyber war on US infrastructure is not a supporting element of geopolitical tension—it is one of its primary arenas.
Recent global conflicts have shown that digital operations are now tightly woven into military and political strategy. Critical systems that sustain everyday life, energy, water, communications, and transportation have become high-value targets. The logic is simple: disrupting infrastructure creates immediate, visible consequences without crossing traditional thresholds of war.
From Silent Intrusions to Persistent Attacks
Cyber operations were once defined by stealth. Attackers sought long-term access, often avoiding detection for as long as possible. That model has shifted toward persistence and scale.
By early 2026, threat activity across the Americas reflected this change. In the first quarter alone, 1,305 cyber incidents were recorded, with 1,138 ransomware attacks publicly claimed, according to the Cyble Americas Threat Landscape Report. This volume alone signals how normalized large-scale cyber operations have become. Even more telling, 58% of these incidents were driven by just five ransomware groups, highlighting how concentrated and industrialized the threat ecosystem is.
This surge is directly tied to rising cybersecurity threats to the US critical infrastructure. Attackers are no longer experimenting; they are executing repeatable, scalable campaigns designed to disrupt essential services.
Why Critical Infrastructure Is a Strategic Target
To understand why critical infrastructure is targeted by hackers, it helps to look at the impact rather than the intent. Infrastructure is not just a technical system; it is a force multiplier.
Disrupting it can:
- Undermine public confidence
- Interrupt economic activity
- Create pressure on governments without physical confrontation
Sectors such as healthcare, manufacturing, and government services have been among the most frequently targeted. These industries are particularly vulnerable because downtime is not an option. For example, ransomware campaigns in healthcare environments can force immediate decision-making under pressure, often leading to rapid payouts or operational shutdowns.
This is why cyberattacks on power grids and water systems are especially concerned. Unlike data breaches, these attacks have physical consequences. Even a temporary outage can cascade across multiple sectors, amplifying the overall impact.
The Rise of Identity-Driven Attacks
One of the most important shifts in the current threat landscape is the move away from traditional malware-centric attacks. Attackers are exploiting identity and trust.
Instead of breaking in, they log in.
Techniques such as:
- Credential theft
- Multi-factor authentication (MFA) bypass
- Session hijacking
- Abuse of third-party access
These techniques have become central to modern attack strategies. This reflects a deeper structural issue: the traditional network perimeter has dissolved. Cloud adoption, remote work, and third-party integrations have created an environment where identity is the new attack surface.
For critical infrastructure operators, this dramatically increases exposure. A compromised vendor or service provider can provide indirect access to sensitive systems, making critical infrastructure cyberattack scenarios more difficult to detect and contain.
Nation-State Strategy and Pre-Positioned Access
The growing frequency of nation-state cyberattacks on US systems adds another layer of complexity. These operations are not opportunistic; they are strategic and often long-term.
State-sponsored actors focus on:
- Mapping infrastructure dependencies
- Identifying systemic weaknesses
- Establishing persistent access for future use
In many cases, access is established well before any visible disruption occurs. This creates a latent risk, where attackers can activate capabilities at a time of their choosing, often aligned with geopolitical escalation.
This approach transforms infrastructure into a strategic asset in conflict scenarios. It is not just about immediate disruption, but about maintaining the ability to disrupt when it matters most.
Hacktivists, Cybercrime, and the Blurred Battlefield
The modern threat environment is no longer defined by clear boundaries. State actors, cybercriminals, and hacktivist groups often operate in parallel, sometimes targeting the same systems for different reasons.
In North America alone, nearly 300 domains were targeted by hacktivist activity in early 2026. These campaigns are often disruptive rather than destructive, but they contribute to a broader atmosphere of instability.
At the same time, cybercriminal groups are leveraging access markets, buying and selling entry points into networks. This accelerates the speed of attacks and lowers the barrier to entry, enabling less sophisticated actors to participate in high-impact operations.
The result is a crowded and unpredictable battlefield, where a single critical infrastructure cyberattack may involve overlapping motives, political, financial, and ideological.
Infrastructure Under Pressure: Real-World Implications
Certain sectors have emerged as consistent targets due to their strategic importance. Technology and financial services accounted for 44% of breach activity in North America, reflecting their central role in both economic and operational systems.
However, the risk extends beyond these industries. Critical infrastructure depends on a web of interconnected services:
- Energy systems rely on telecommunications and cloud platforms
- Water utilities depend on industrial control systems and remote monitoring
- Transportation networks integrate with logistics and supply chain platforms
This interconnectedness means that disruption in one area can quickly spread. The increasing frequency of cyberattacks on power grid and water systems highlights how attackers are beginning to exploit these dependencies more deliberately.
Rethinking Defense in a Persistent Threat Environment
Defending against modern US critical infrastructure cybersecurity threats requires a shift in mindset. Traditional defenses focused on perimeter security and reactive response are no longer sufficient.
Organizations must prioritize:
- Continuous monitoring for early indicators of compromise
- Strong identity and access management
- Visibility into third-party and supply chain risks
- Resilience against high-volume disruption tactics like DDoS
Equally important is the ability to anticipate attacker behavior. With adversaries operating at scale and speed, waiting for alerts is no longer viable. Proactive threat hunting and intelligence-driven defense are becoming essential capabilities.
Infrastructure as the Center of Modern Conflict
Critical infrastructure has become the centerpiece of modern cyber conflict. The convergence of geopolitical tension, advanced attack techniques, and systemic vulnerabilities has created an environment where disruption is both achievable and strategically valuable.
The data reinforces this reality: high volumes of ransomware, concentrated threat actor activity, and increasing reliance on identity-based attacks all point to a more aggressive and coordinated threat landscape.
The cyber war on US infrastructure is not defined by isolated incidents—it is shaped by persistent pressure, evolving tactics, and long-term strategic intent. As nation state cyber attacks on US systems continue to expand in scope and sophistication, the challenge is no longer just preventing breaches.
It is ensuring that the systems society depends on can withstand them. In a threat landscape defined by speed and precision, waiting for alerts is no longer enough.
Request a demo to see how Cyble helps detect and anticipate critical infrastructure cyberattacks—before they turn into real-world disruption.
The post Why U.S. Critical Infrastructure Is the Highest-Value Target in the Global Cyber War appeared first on Cyble.