GRIT Q3 2026 Ransomware and Cyber Threat Insights Report: Top Takeaways
Key findings from the GRIT Q3 2026 Ransomware and Cyber Threat Insights Report:
GuidePoint’s Research and Intelligence Team (GRIT) just unveiled the Q3 GRIT Ransomware and Cyber Threat Insights Report. This quarter, they look at the so-called “vulnpocalypse,” shine a spotlight on the Education industry and ShinyHunters group, analyze the Clop syndicate’s latest activity and assess payment trends in the ransomware space.
Let’s explore the top takeaways from the report.
In Q3 2026, the GuidePoint Research and Intelligence Team (GRIT) tracked 2,760 victims claimed by 112 distinct threat actors across 29 industries and 115 countries.
Relative to Q3 2025, victim counts surged 75.3% YoY (up from 1,574), the number of active threat actors grew by 47.4% (up from 76) and targeting expanded to 25 additional countries (a 27.8% increase), while industry breadth held steady.
TheGentlemen accounted for 12.9% of observed victims in Q3 2026, narrowly overtaking Qilin at 12.6%. Together the two groups claimed roughly one in four victims.
AI is no longer just advising attackers. It is operating alongside them inside the intrusion. For example, one AI agent actor went from an empty workspace to its first Remote Code Execution (RCE) achieved against a real victim in under four hours. It reached its first domain admin account two hours later and once the full campaign launched, compromised at least 11 organizations in 26 seconds.
AI IS orchestrating the intrusion phase for a growing number of affiliate-tier and access-broker actors. It IS NOT (yet) orchestrating the underlying business.
ShinyHunters is a “pure” data extortion actor, meaning it skips ransomware encryption entirely, steals data in bulk and demands payment to keep it private. Tracked payments attributable to ShinyHunters have averaged approximately $600,000 per victim in 2026, with more than $8 million USD observed across attributed Bitcoin wallets since the beginning of Q3 2026.
Clop has been unable to recreate previously seen success with subsequent mass exploitation campaigns. GRIT has not identified any ransom payments made to Clop from the PTC Windchill campaign and the volume of victims shared to their data leak site is dwarfed by the number of victims from previous campaigns.
The compounding effect is the real problem. A low-yield campaign hurts Clop financially. But the ShinyHunters dispute threatens Clop’s credibility, which is arguably more valuable than any single campaign’s proceeds. Absent a rebrand or major shift in tactics, Clop’s operations under their current brand may be close to end of life.
In May 2026, ShinyHunters claimed a ransomware and extortion attack against Instructure, the US-based parent company of the widely used Canvas learning management system. Over the following months, GRIT tracked a further six education-technology and learning-management platforms targeted in the same manner, spanning multiple countries and claimed by six distinct threat actors working independently of one another.
Now more than ever, schools must focus on identity and access management security in addition to the traditional network perimeter.
With 978 Common Vulnerabilities and Exposures (CVEs) recorded in Microsoft’s Patch Tuesday in September alone, the trend warrants closer examination. That changed in July 2026, when 663 disclosures were recorded compared to just 144 and 137 in the same month in 2024 and 2025, respectively.
Aggregating the less likely and unlikely categories, 86% of disclosed vulnerabilities fell into these lower-risk classifications in 2024, 83% in 2025 and 83% through 2026 to date. The signal-to-noise ratio remains manageable for now. The challenge will be in ensuring that triage processes and patch management programs scale accordingly.
The rate of ransomware payment dropped sharply in Q3, from 50% to just under 21%. But among those who did pay, the average payment rose 34%, from $240,000 to $321,000. The big game hunt hasn’t ended, but the hunting party has gotten much larger and many of its members are content with smaller kills.
Do not mistake a declining payment rate for a declining threat.
The shifts noted in the report present a new core threat: time. As threat actors increasingly employ AI and LLM tools that can process, infer and act faster than humans, the window for error in detection and response narrows.
The good news is that nothing in this reporting requires new categories of control. AI turns known weaknesses into faster losses, but it does not create new weaknesses on its own. The controls that mattered in every case from this report – patch velocity, identity hygiene, response automation – are the same ones that mattered last year. Yes, the attackers got faster, but the fundamentals on which they depend didn’t move.
Download the GRIT Q3 2026 Ransomware and Cyber Threat Insights Report for the complete analysis, including the full ShinyHunters and Clop breakdowns, an Education industry spotlight and short-, mid- and long-term recommendations for how defenders can respond.
Yes. GRIT tracked 2,760 victims in Q3 2026 alone, a 75.3% increase over the same quarter last year. Active threat groups grew by 47.4% and targeting expanded to 115 countries.
AI is now orchestrating parts of the intrusion phase. In one observed case, an AI agent achieved remote code execution against a real target in under four hours. Once the campaign launched, it compromised 11 organizations in 26 seconds.
Manufacturing remains the most impacted industry globally. Education saw a notable spike in Q3 2026 after ShinyHunters targeted Instructure, the parent company of Canvas. Six additional education-technology platforms were claimed by independent threat actors.
Patch velocity, identity hygiene and response automation. AI is turning known weaknesses into faster losses, but the underlying controls that matter have not changed. Speed of detection and response is now the primary differentiator.
How it works
Once you click Generate, Ollama reads this article and crafts 5 comprehension questions. Your answers are graded against the article content — general knowledge won't be enough. Score 70+ to count toward your certificate.
Questions are cached — you'll always get the same 5 for this article.