The Q1 State of Ransomware Report from BlackFog has exposed the limited visibility into ransomware activity.
Only one in nine attacks was publicly disclosed during the period, indicating that the majority of incidents go unreported. This gap means the overall scale of the threat is far greater than official records suggest.
In the first quarter of 2026, the research identified 2,160 undisclosed ransomware attacks. That figure represents a two per cent rise compared with the same quarter the previous year.
The data was compiled through detailed monitoring and analysis of incidents not captured in public announcements or media coverage.
Record High Ransom Demands
Financial pressure on victims continued to grow. The average ransom demand exceeded one million dollars, reaching $1,028,214. This amount reflects demands made across the identified cases and highlights the increasing sophistication and ambition of ransomware operators. Organisations faced substantial costs even before considering potential recovery expenses or operational downtime.
Attacks Span 39 Countries
The report confirms that ransomware operators targeted organisations in 39 countries during the quarter. The geographic spread demonstrates the global nature of the threat, affecting businesses and public bodies regardless of location. No single region was immune, with incidents reported on every continent.
Sector Vulnerabilities Exposed
Certain industries bore a heavier burden than others. The logistics sector recorded a 200 per cent year-on-year increase in attacks, signalling heightened interest from cybercriminals in supply-chain operations.
Healthcare emerged as the most targeted sector, suffering 72 attacks. This accounted for 27 per cent of the total incidents examined. The figure underscores the critical risk to patient care and sensitive medical data.
Government entities experienced 32 attacks, representing 12 per cent of cases. Technology organisations followed closely with 28 attacks, or 11 per cent. Together these three sectors accounted for half of the identified activity, while the remaining incidents affected a range of other industries.
The concentration in healthcare, government and technology points to strategic targeting of organisations that hold valuable data or provide essential services. Logistics operators, meanwhile, appear to have become more attractive due to their role in global trade and distribution networks.
Implications
Public disclosures capture only a fraction of real-world ransomware events. With undisclosed attacks rising modestly but average demands climbing sharply, the financial and operational risks remain elevated.
Organisations are advised to strengthen defences, particularly in the most affected sectors. Regular backups, staff training and robust incident response plans can help mitigate the impact of an attack, whether or not it becomes public knowledge.
Source: Cyber Security Intelligence
BlackFog