Cyber Threats Surge: Over 7,000 Ransomware Hits by 2026

More than 7,000 victims are expected to be publicly named in ransomware incidents by the close of 2026 – a 40% jump from 2024 levels – according to a new report commissioned by insurer QBE.
The forecast, compiled by Control Risks, represents a fivefold increase on 2020 figures, when just 1,412 victims were identified on leak platforms.
The report highlights how threat actors are becoming more adept at exploiting enterprise cloud systems and artificial intelligence to breach networks and extract valuable data.
Between August 2023 and August 2025, UK-based organisations accounted for 49 of the 447 known incidents worldwide, or 10% of the total.
AI and cloud accelerate attack velocity, targeting QBE clients
David Warr, Cyber Portfolio Manager at QBE, says rapid digital transformation is outpacing many firms' ability to manage exposure.
“As British businesses expand their use of cloud infrastructure and AI tools, they are also reshaping their risk landscape,” he says.
“The challenge is not just preparing for the future but catching up with exposures that have evolved at speed.”
The figures underscore this pace: ransomware volumes nearly tripled year-on-year, rising from 572 incidents in Q1 2024 to 1,537 in the same quarter of 2025.
Publicly confirmed extortion cases climbed by 54% in the first four months of 2025 compared with the same period a year earlier.
In 2024, deepfake technology featured in almost 10% of ransomware cases, with financial impacts ranging between US$250,000 and US$20m per breach.
Third-party risks stretch cyber cover
David draws attention to how supplier networks are amplifying risk.
“The supply chain threat causes concern for companies,” David explains.
“While outsourcing certain parts of your business can create efficiencies and cost savings, there are security considerations to bear in mind.”
He continues: “Each outsourced provider that connects into your company creates an additional layer of risk – not only in terms of potential malware transmission but also in terms of critical dependencies.
“Each third-party connection creates new risk, and a single point of failure can halt business operations altogether.”
- Ransomware incidents rose from 572 in Q1 2024 to 1,537 in Q1 2025, marking a near-tripling of attacks in 12 months.
- High-severity cloud alerts increased by 235% in 2024 compared with 2023 as criminals exploit Microsoft 365 and other platforms.
- ChatGPT reached 755m users in early 2025 while 78% of organisations now deploy AI in at least one business function.
New era of zettabytes for storage as Microsoft 365 tightens security
By 2025, global data storage is expected to reach 200 zettabytes, with 50% of that data hosted in cloud environments. Just a decade ago, this figure stood at 10%.
The shift to cloud has driven a 235% year-on-year spike in high-risk security alerts in 2024, according to the report.
Ransomware operators have increasingly turned their attention to services like Microsoft 365, taking advantage of their integration across enterprise systems.
These business email compromise attacks are harder to detect and often bypass conventional security layers. With nearly half of all cloud-stored corporate data classified as sensitive, the stakes are high.
Major breaches show domino effect
High-profile third-party breaches have illustrated the systemic risk. In 2023, the compromise of identity management provider Okta impacted 134 client organisations and led to a US$ 2bn drop in the company’s market capitalisation.
Similarly, a 2024 failure linked to cybersecurity firm CrowdStrike affected 8.5 million Windows machines and cost Fortune 500 firms an estimated US$5.4bn.
Cloud and AI tools are giving attackers more entry points and opportunities
For insurers, such incidents offer critical insight into aggregation risk and the operational dependency many clients have on external providers.
Generative AI boosts both business and threat actors
Generative AI adoption is soaring across Europe and North America. By early 2025, ChatGPT had reached 755 million users following a 33% user growth between December and February, while Microsoft Copilot counted 88 million active users.
Among enterprises, 78% now use AI in at least one business area – up from 55% in 2024 – with usage highest in technical functions like software development.
While many organisations leverage AI to drive efficiency, cybercriminals are using the same tools to scale fraud. Automated phishing, identity theft and deepfake scams are increasingly AI-powered.
More experienced hackers are accelerating attacks with AI, while less skilled actors are using these tools to write scripts and code malware, expanding the threat landscape.
QBE urges embedding cyber resilience from the ground up
QBE is urging organisations – particularly those in data-rich and digitally dependent sectors – to incorporate cyber defence into their entire technology lifecycle. This includes mapping critical assets, identifying threat vectors, and defining risk thresholds to guide resource allocation.
David emphasises the importance of contingency planning and external support. “Cloud and AI tools are giving attackers more entry points and opportunities.
“Businesses need a robust strategy to anticipate and withstand cyber incidents, particularly those arising from third-party services and cloud environments,” he says.

