A recent report by Halcyon reveals that ransomware groups are increasingly employing techniques to shut down endpoint detection and response (EDR) tools before initiating attacks, now a common practice among the most proactive ransomware groups. In Q2 2026, there were 1988 reported ransomware attacks from 89 active groups, marking a 5.7% decline in frequency, but with evolved tactics leading to more effective and automated operations.
The report highlighted the emergence of AI use in these attacks, including malware disguised as AI tools and AI-assisted negotiations, indicating a shift towards faster, more complex ransomware. Key vulnerabilities in enterprise edge devices were exploited, and the manufacturing sector was the most targeted.