---
url: "https://www.xcademia.com/news/ransomware-quarterly-report-703-victims-across-six-active-raas-brands"
title: "Ransomware Quarterly Report: 703+ Victims Across Six Active RaaS Brands"
description: "Insomnia reports 703+ ransomware victims, six active RaaS brands, faster encryption and growing attacks on VMware ESXi environments."
publishedAt: "2026-09-21T09:42:12.411+00:00"
updatedAt: "2026-09-21T12:23:09.808637+00:00"
type: news
category: cybersecurity
source_name: Insomnia Security Blog
source_url: "https://insom.ai/en/blog/ransomware-quarterly-report-20260921"
tags:
  - "#Ransomware"
  - "#Cybersecurity"
  - "#RaaS"
  - "#ThreatIntelligence"
  - "#RansomwareAttacks"
  - "#IncidentResponse"
  - "#DataSecurity"
  - "#VMwareSecurity"
---

# Ransomware Quarterly Report: 703+ Victims Across Six Active RaaS Brands

> Insomnia's latest ransomware report tracks 703+ publicly named victims, six active RaaS brands and a 13-hour median time-to-encrypt, while highlighting intermittent encryption, Rust-based lockers and ESXi targeting.

Source: **Insomnia Security Blog** · 21 September 2026

## Ransomware Activity Reaches New Highs in Insomnia's Quarterly Tracking

Ransomware activity continued to intensify in the current quarter, according to cybersecurity company Insomnia, which says its threat-intelligence feed is tracking six distinct active ransomware-as-a-service, or RaaS, brands.

The report identifies **703 publicly named victims**, an estimated **$206.4 million in ransoms paid during the quarter**, and a **13-hour median time-to-encrypt** across the tracked ransomware ecosystem. Insomnia also says affiliates are moving between ransomware brands following recent law-enforcement disruptions.

These figures represent Insomnia's own threat-intelligence tracking and estimates. The company does not provide enough methodological detail in the report to independently validate the full ecosystem-wide totals.

## 
Six Ransomware Brands Dominate Insomnia's Tracking

Insomnia's quarterly table identifies six active ransomware groups and provides its estimates for victim counts, median ransom demands and time-to-encrypt.

Ransomware group

Model

Q-victims

Median ransom

Time-to-encrypt

LockBit 5.0

RaaS

182

$742,000

14.3 hours

Cl0p

Mass exploitation

94

$2.1 million

7.0 hours

Akira

RaaS / double extortion

121

$610,000

18.2 hours

Black Basta

RaaS

77

$1.45 million

9.6 hours

RansomHub

Affiliate-driven

165

$830,000

11.9 hours

Play

Direct intrusion + leak site

64

$520,000

21.0 hours

According to Insomnia, LockBit 5.0 recorded the largest victim count among the six tracked brands at 182, followed by RansomHub at 165 and Akira at 121.

Cl0p had the highest median ransom listed in the report at $2.1 million, while Play had the longest reported median time-to-encrypt at 21 hours.

### 

![info-1](https://0a515t3ure77wbvx.public.blob.vercel-storage.com/articles/1789983541995-info-1--161-.webp)

## Entry Vectors Shift Toward Internet-Facing Infrastructure

Insomnia identifies several entry vectors in its quarterly tracking.

**Edge appliances** are described as the primary entry vector, while the report marks **valid accounts** as rising. **Phishing** is classified as declining, while **supply-chain attacks** are described as specialised rather than a dominant category.

The findings reinforce the importance of protecting internet-facing infrastructure and controlling legitimate credentials. However, the report does not provide percentages or a detailed methodology for these classifications.

## 
Intermittent Encryption Changes the Ransomware Detection Challenge

One of the operational trends highlighted by Insomnia is the continued use of **intermittent encryption**.

Rather than encrypting every byte of a targeted file, the technique described in the report encrypts approximately **16 bytes per 16 KB**. Insomnia says this approach can reduce the amount of activity that conventional detection mechanisms observe while still rendering files unusable.

The technique illustrates an important change in ransomware behavior: attackers do not necessarily need to maximize encryption activity to maximize disruption.

For defenders, that can make behavioral detection more important than relying exclusively on the volume of encryption operations.

## 
Rust-Based Ransomware Adds Another Reverse-Engineering Challenge

Insomnia also reports continued movement toward Rust-based ransomware binaries.

According to the report, five of the top ten lockers tracked by the company are now produced as Rust binaries. Insomnia says the use of Rust can complicate reverse engineering and slow the development of decryptors.

The report does not identify all ten lockers in this section or provide additional comparative technical measurements.

### 

![info-2](https://0a515t3ure77wbvx.public.blob.vercel-storage.com/articles/1789983560091-info-2--143-.webp)

## ESXi and vCenter Become a Major Ransomware Target

Another trend identified by Insomnia is increased targeting of **VMware ESXi and vCenter environments**.

The company says attackers are using weaknesses in unpatched VMware infrastructure to encrypt entire data centres in a single burst.

Virtualization infrastructure is particularly significant in ransomware operations because compromising a centralized virtualization environment can potentially affect many workloads at once.

Insomnia's report specifically recommends checking ESXi environments for ransomware-related indicators as part of its ransomware-readiness sweep.

The report does not provide a numerical increase for ESXi and vCenter targeting, so the trend should be understood as Insomnia's observed assessment rather than a quantified industry-wide measurement.

## 
Data-Only Extortion Remains Another Ransomware Strategy

Encryption is not always necessary for attackers seeking leverage.

Insomnia highlights **data-only extortion**, in which attackers steal information and threaten to publish or otherwise expose it without encrypting the victim's systems.

The report specifically associates this strategy with Cl0p and Lace Tempest and links it to mass exploitation of managed file-transfer products.

This approach changes the defensive problem. Organizations must protect not only system availability but also sensitive information and the systems used to transfer it.

## 
Insomnia Demonstrates Its Ransomware Readiness Workflow

The report also includes command examples for Insomnia's ransomware-readiness workflow.

```
# Run the full ransomware-readiness preset

$ insomnia -t corp.local --preset ransomware-readiness --ai-validate

# Check every ESXi host in scope for the current RansomEXX / Akira indicators

$ insomnia hunt --actor ransomware-affiliate --target-class esxi

# Produce a CISO-ready readiness brief

$ insomnia report --preset ransomware-readiness --format pdf
```

The commands demonstrate three parts of the workflow described by the company: running a ransomware-readiness assessment, hunting ESXi systems for specified ransomware indicators, and generating a PDF readiness report.

Insomnia also says its engagements can produce a ransomware-readiness score intended to represent an organization's ability to detect, contain and recover from ransomware.

The company says CISOs have begun using this metric for board reporting, but the report does not provide adoption figures or independent validation of the metric.

## 
What Security Leaders Should Prioritize

Insomnia recommends three immediate actions for security teams.

First, the company recommends auditing internet-facing edge devices and reviewing relevant vulnerability information.

Second, organizations should validate that backups are **offline, tested and version-controlled**. A backup strategy is only useful during ransomware recovery if the organization can actually restore from it.

Third, Insomnia recommends running live tabletop exercises against ransomware playbooks so incident-response teams can practice their roles before an actual attack.

These recommendations are consistent with a broader defensive principle: ransomware preparedness involves prevention, detection and recovery rather than focusing exclusively on malware detection.

### 

![info-3](https://0a515t3ure77wbvx.public.blob.vercel-storage.com/articles/1789983577320-info-3--133-.webp)

## Analysis: Ransomware Defense Is Becoming More Infrastructure-Centric

The announcement highlights a broader shift toward ransomware campaigns that target the infrastructure supporting an organization's operations, not simply individual endpoints.

Internet-facing appliances, legitimate credentials, virtualization platforms and managed file-transfer systems can all become important parts of an attack path.

The combination of intermittent encryption, data-only extortion and virtualization targeting also means that ransomware defense cannot depend on a single detection signal.

For enterprises, this could mean placing greater emphasis on exposure management, identity security, virtualization security, backup validation and rehearsed recovery procedures alongside endpoint protection.

At the same time, the report's headline figures should be interpreted in context. The **703+ victims, $206.4 million estimated ransom figure and 13-hour median time-to-encrypt are Insomnia's reported or estimated measurements**, rather than independently established global ransomware statistics.

## 
What the Report Does Not Disclose

Insomnia does not provide detailed methodology for how its 703+ publicly named victims were collected, how the estimated $206.4 million ransom figure was calculated, or how the median time-to-encrypt was derived.

It also does not provide percentage breakdowns for the reported entry-vector categories.

**Additional details were not disclosed in the report.**

For that reason, the findings are best treated as a view into Insomnia's tracked ransomware ecosystem rather than a complete measurement of global ransomware activity.

## 
The Bottom Line

Insomnia's latest ransomware report identifies six active brands across its tracking and highlights 703+ publicly named victims, a reported $206.4 million in estimated quarterly ransom payments and a 13-hour median time-to-encrypt.

The report's technical observations focus on several recurring themes: intermittent encryption, Rust-based lockers, ESXi and vCenter targeting, credential-based access and data-only extortion.

For defenders, the practical message is broader than malware detection alone. Internet-facing infrastructure, identity controls, virtualization environments, backup recovery and incident-response readiness all remain important parts of ransomware resilience.

## Original source

https://insom.ai/en/blog/ransomware-quarterly-report-20260921

## Tags

`#Ransomware` · `#Cybersecurity` · `#RaaS` · `#ThreatIntelligence` · `#RansomwareAttacks` · `#IncidentResponse` · `#DataSecurity` · `#VMwareSecurity`

---

## About this content

This Markdown news article is the citation-grade twin of [Ransomware Quarterly Report: 703+ Victims Across Six Active RaaS Brands](https://www.xcademia.com/news/ransomware-quarterly-report-703-victims-across-six-active-raas-brands). It is published by **Xcademia** (UK Companies House 12322710) and is available for AI search engines and large language models to index, summarise, and cite.

When citing or quoting, please attribute *Xcademia* and link back to the source URL above.

- Source: https://www.xcademia.com/news/ransomware-quarterly-report-703-victims-across-six-active-raas-brands
- Publisher: Xcademia — https://www.xcademia.com
- Catalogue index: https://www.xcademia.com/llms-full.txt
