INTEL_REPORT
Check Point Research · published 5/11/2026, 9:58:28 AM · TLP amber
Summary
Ingested excerpt (first ~500 chars of normalized text).
The State of Ransomware – Q1 2026 Key Findings Ransomware in Q1 2026: Consolidation at Scale During the first quarter of 2026, we monitored more than 70 active data leak sites (DLS) that collectively listed 2,122 new victims. This figure represents a 12.2% decline from the Q4 2025 all-time record of 2,416 victims but remains the second-highest Q1 on record at 117% […] The post The State of Ransomware – Q1 2026 appeared first on Check Point Research . Key Finding…
https://research.checkpoint.com/2026/the-state-of-ransomware-q1-2026
sha256:65572c6fd5d0072315743e47e07298a02a8dc9f25de01c13582164986fd15dac
What we pulled out
Deterministic extractor (IOC + allowlisted tokens + ATT&CK IDs present in DB).
Indicators
Linked with report → mentions → indicator. Values open the indicator workspace.
Malware families
Allowlist token matches only.
Threat actors mentioned
Allowlist mentions — not a formal attribution verdict.
ATT&CK techniques
MITRE IDs referenced in text and present in local technique table.
CONTINUE INVESTIGATION
High-signal pivots without leaving the thread you started in search.
Browse the report corpus.
Neighborhood from the first linked indicator.