Conceptual image of ransomware gangs exploiting VPN vulnerabilities and AI attacks in healthcare, retail, and government sectors, highlighting cybersecurity risks and data protection.

Ransomware attacks rose year over year in June for the fourth consecutive month, according to NCC Group, with Q2 2026 volume up just 3% over the previous quarter. Growth has flattened, but the floor is now much higher than it was a year ago. (Source: Csoonline)

Ransomware attacks were up year over year in June for the fourth consecutive month, though attacks increased just 3% in Q2 2026 versus the previous quarter. — NCC Group

The access method matters more than the volume. NCC Group reports that network edge vulnerabilities and stolen edge credentials — VPNs in particular — are increasingly the primary vector, with Akira, Qilin, and The Gentlemen named as heavy users. Targeted devices include appliances from Fortinet, Citrix, and Check Point.

That list covers equipment sitting at the perimeter of most mid-sized firms. If your remote workforce reaches internal systems through a Fortinet, Citrix, or Check Point gateway, that appliance is the same class of device these groups are working through to get in.

Recent activity backs this up:

  • A CitrixBleed-like NetScaler flaw is seeing exploit attempts in the wild.
  • The FortiBleed campaign exposed 75,000 Fortinet firewalls worldwide.
  • Check Point has warned of ransomware-linked attacks exploiting an outdated VPN protocol.
  • Arctic Wolf disclosed an ongoing Qilin campaign against a vulnerability in Palo Alto Networks' GlobalProtect VPN.

Edge access is attractive because it lands attackers inside the network with working credentials and no phishing email for staff to report. From your side, the initial intrusion looks like a legitimate remote session, which is why these breaches are often discovered at the encryption stage rather than the entry stage.

Two additional developments shape the current picture. Qilin and The Gentlemen have both been seen deploying "EDR killer" tooling that attempts to disable endpoint security agents on PCs and servers. And Sysdig documented JadePuffer, an autonomous AI agent that ran a full intrusion chain through to a Bitcoin ransom demand — what researchers called the first documented case of agentic ransomware.

Attack Chain & TTPs

The intrusion chain for the groups dominating Q2 2026 starts at the appliance, not the inbox. Exploitation of internet-facing edge devices maps to T1190 (Exploit Public-Facing Application), and where valid credentials are used instead of an exploit, to T1133 (External Remote Services) chained with T1078 (Valid Accounts). Because that access arrives through a device that legitimately terminates remote sessions, the first authentication event often looks like an ordinary employee logging in from home.

The specific targets named in recent reporting span most of the major edge vendors:

  • A Qilin campaign against a vulnerability in Palo Alto Networks GlobalProtect VPN, disclosed by Arctic Wolf as ongoing.
  • A CitrixBleed-like NetScaler flaw already seeing exploit attempts in the wild.
  • A FortiBleed campaign that exposed 75,000 Fortinet firewalls worldwide.
  • Check Point warnings of ransomware-linked attacks abusing an outdated VPN protocol.

A CitrixBleed-class flaw matters because of what it yields: session material that lets an attacker resume an authenticated session rather than crack a password. That sidesteps the login step entirely, which is why an appliance can be the source of a breach while your directory logs show nothing unusual.

Once inside, both Qilin and The Gentlemen have been observed deploying "EDR killer" toolsT1562.001 (Impair Defenses: Disable or Modify Tools) — per Cisco Talos and ESET respectively. The technique itself is old. What Talos and ESET flag as new is that affiliates now build or source their own killers, a real engineering effort given how many endpoint platforms defenders run, and a marker of rising affiliate capability.

For an IT manager, the practical consequence is that endpoint telemetry may stop arriving before encryption starts. An agent that goes silent is itself the signal.

Encryption scope has widened too. KryBit, first observed in March 2026 and operating as ransomware-as-a-service, builds for Windows, Linux, VMware ESXi, and NAS devices. Hitting a hypervisor takes down every guest VM on it in one action, and hitting NAS reaches the storage many firms treat as their backup tier.

Two backdoors round out the tooling picture. Mistic is a new backdoor tied to a ransomware broker — the access-broker model, where one crew establishes the foothold and hands or sells it to the crew that encrypts. GigaWiper, uncovered by Microsoft, is a backdoor built for destruction on demand, meaning the payload's purpose is wiping rather than extortion leverage.

The JadePuffer agent documented by Sysdig ran the full chain without an operator at the keyboard, using an LLM to adapt as it went and executing more than 600 coordinated payloads. Its observable steps line up cleanly with existing techniques:

  • Credential harvesting to expand access beyond the initial foothold (Credential Access).
  • Persistence establishment to survive restarts and session termination.
  • Internal service mapping — T1046 (Network Service Discovery).
  • Encryption of configuration records — T1486 (Data Encrypted for Impact).
  • Deletion of the original database tables — T1485 (Data Destruction).

It closed with a Bitcoin ransom demand, which Sysdig called the first documented case of agentic ransomware. The technique inventory is familiar; the change is execution speed and the fact that no human had to be available to make each decision.

Taken together, these chains share one shape: an edge device gives access, endpoint defenses get disabled, discovery precedes encryption, and virtualization and storage layers are in scope alongside endpoints. Recovery difficulty tracks how many of those layers an attacker reaches before anyone notices.

Business Impact

The clearest picture of what a ransomware outage costs comes from the April attack on Signature Healthcare in Massachusetts: ambulance services were disrupted, cancer treatments were cancelled, and Brockton Hospital ran downtime procedures for several weeks. That is the operational shape of these incidents — not a single day of encrypted files, but weeks of manual workarounds while systems are rebuilt.

Where you sit by sector determines how likely you are to be in that position. NCC Group's Q2 2026 breakdown puts industrials at 30% of victims, consumer discretionary at 24%, information technology at 11%, and healthcare at 10%. If you run manufacturing, distribution, retail, or a professional services firm serving them, you are in the top two verticals by attack share.

Comparitech's six-month figures show which sectors are absorbing the most new pressure: transportation up 52%, healthcare up 35%, retail up 28%, and technology up 23%. Public sector organizations recorded 89 confirmed and 98 unconfirmed attacks in the first half of 2026, with US government agencies accounting for 31% of them — though at a rate 23% below the second half of 2025. If your firm holds municipal or agency contracts, an incident at a client can freeze your own billing and project schedules alongside theirs.

Your recovery bill is shaped less by the ransom demand than by what the attackers reach before encryption. KryBit, the ransomware-as-a-service group first observed in March 2026, builds for Windows, Linux, VMware ESXi, and NAS devices. That combination matters to you directly:

  • Encrypting an ESXi host takes down every virtual machine on it at once, so a single compromised hypervisor can stop your ERP, file services, and line-of-business applications simultaneously.
  • NAS support means the appliance holding your local backups is a target in the same intrusion, which turns a restore job into a rebuild-from-scratch project.
  • Cross-platform coverage removes the assumption that Linux workloads or storage tiers sit outside the blast radius.

The JadePuffer case raises a different cost. Sysdig documented an autonomous agent that encrypted configuration records and then deleted the original tables before leaving a Bitcoin demand. When data is destroyed rather than locked, paying does not return it — your only path back is whatever offsite copy exists, and the gap between your last good backup and the intrusion becomes permanent data loss you have to explain to customers.

Investigation costs rise too. The EDR killer tooling now used by the most active groups disables endpoint agents, which means the telemetry your forensics team and your insurer need may be incomplete for the most important hours of the intrusion. Thin evidence lengthens claims handling and makes it harder to state, with confidence, exactly which records were touched.

That uncertainty runs straight into your disclosure obligations. Groups like The Gentlemen and Qilin publish victim names on data leak sites, so your customers, regulators, and competitors may learn about the incident before your scoping work is finished. For healthcare organizations that triggers HIPAA and state breach notification duties on facts you are still assembling; for industrials and IT providers it triggers contractual notification clauses with every downstream client.

Plan on parallel workstreams: operational restoration, forensic scoping, and notification, all running at once and all drawing on the same small group of people.

Detection & Response (NIST Cybersecurity Framework)

The first alert to wire up is endpoint agent tampering. Because Qilin and The Gentlemen affiliates now build or buy their own EDR killer tooling, an agent that stops reporting, has its service stopped, or logs a failed uninstall attempt should page someone rather than sit in a dashboard. In environments Capstone manages, SentinelOne flags and blocks that tampering across managed environments before the encryptor stages, and treats agent silence as an event in its own right.

Organize the rest of the work in the order of the NIST Cybersecurity Framework.

Identify

Inventory the layer KryBit was built for. The group, first observed in March 2026, operates as ransomware-as-a-service targeting Windows, Linux, VMware ESXi, and NAS devices, so your asset list needs to include hypervisors and storage appliances — not just laptops and servers.

  • Every ESXi host, its management interface exposure, and whether SSH is enabled
  • Every NAS unit reachable from outside the LAN, including vendor remote-access features
  • Which accounts can authenticate to hypervisor management, and which of those are shared
  • Which Linux systems run an endpoint agent at all, versus none

Protect

Turn on ESXi lockdown mode and disable the SSH service on hosts that do not need it, then require a separate out-of-band password to uninstall or upgrade endpoint agents. That second control is what turns an EDR killer from a quiet success into a failed, logged attempt. Encrypting a hypervisor datastore takes out dozens of workloads in one action, which is why the ESXi layer deserves stricter administrative controls than your general server fleet.

Detect

Write detections for the mechanics of agent removal rather than for named tools. Watch for kernel driver loads from unusual paths, service-stop events against security processes, and privileged process creation immediately followed by an agent heartbeat gap.

Add rate-based detection for automated intrusion. Sysdig's analysis of JadePuffer describes an autonomous agent that executed more than 600 coordinated payloads while using an LLM to adapt as it went — activity at a volume and cadence no human operator produces. Alert on bursts of authentication or command activity from a single identity within a short window, and enable database audit logging so mass table drops and bulk record modification surface as alerts instead of as a post-incident finding.

Respond

Preserve the edge appliance before you rebuild it. Export the running configuration, local user list, and session logs from the affected VPN or firewall first, because reimaging destroys the only record of which account was used and what was changed. Rotate every credential and certificate that appliance held, including service accounts and any local admin defined on the device itself.

Then hunt for a second foothold. Ransomware brokers have used the Mistic backdoor to hand off access, and Microsoft's disclosure of GigaWiper — a backdoor built for destruction on demand — shows why closing the original entry point is not the same as eviction. Assume data left the environment and start your notification assessment in parallel with containment rather than after it.

Recover

Keep at least one backup copy outside the identity system that authenticates production. N-able Cove holds restore points off the domain, so an operator with domain admin cannot delete the copies you need, and it lets you rehearse a hypervisor-level VM restore rather than assuming one will work. Test that restore against your largest ESXi workload, since recovery time on a single datastore usually sets the length of the whole outage.

Conclusion

Two figures from the current reporting are worth carrying into your own planning. Comparitech counted 89 confirmed and 98 unconfirmed ransomware attacks against government entities in the first half of 2026, with US agencies accounting for 31% of them — at a rate 23% lower than the second half of 2025. Over the same six months, the sectors with the sharpest increases were transportation (52%), healthcare (35%), retail (28%), and technology (23%).

If you run logistics, fleet, retail point-of-sale, or clinical systems, your sector's share of this activity is growing rather than holding steady. That matters for how you argue budget: the trend line is specific to your vertical, not a general claim about crime rates.

The second development is JadePuffer, the autonomous AI agent documented by Sysdig. It completed an entire intrusion chain on its own — harvesting credentials, establishing persistence, mapping internal services, encrypting configuration records, deleting the original tables, and leaving a Bitcoin ransom demand — using an LLM to adapt its actions and executing more than 600 coordinated payloads. Sysdig described it as the first documented case of agentic ransomware.

The relevant change for you is pace and volume of activity per intrusion. Hundreds of coordinated payloads inside a single incident compresses the window in which a human analyst would normally notice something odd and start asking questions.

The one thing to get right, given everything the reporting shows about where these groups enter, is knowing exactly which of your remote access appliances are reachable from the internet and what software version each one is running. Everything else in your defensive plan depends on that list being accurate.

In This Article

Top hits