Sixty-three new ransomware programs built using artificial intelligence were discovered in 2025 alone. Let that number settle for a second. Not variants. Not upgrades. Sixty-three entirely new AI-powered tools, purpose-built for extortion, deployed against hospitals, power grids, and financial institutions. And according to NCC Group’s latest analysis, the groups behind these attacks aren’t slowing down — they’re scaling up, with software supply chains now squarely in their crosshairs.
The facts:
- The FBI received 1,008,597 cybercrime complaints in 2025 — a 36.2% increase over 2024.
- Cyber fraud and ransomware cost the United States over $28.7 billion in 2025, according to FBI data cited by former Puerto Rico House Speaker José Aponte.
- 467 ransomware complaints in 2025 involved critical infrastructure — a 26.4% jump from the prior year.
- In Italy alone, 148 confirmed ransomware claims were recorded in just six months, with attackers claiming to have stolen roughly 13.4 TB of data across 64 disclosed cases.
- According to Infosecurity Magazine, disabling endpoint detection and response tools before launching encryption has become standard operating procedure across the ransomware ecosystem in 2026.
Why Are Software Supply Chains Suddenly the Favorite Target?
Because one compromised vendor can unlock hundreds of victims simultaneously. That’s not a theory — it’s the operating logic that ransomware groups have been quietly perfecting for the last three years. NCC Group’s findings confirm what security researchers have been muttering at conferences: targeting the supply chain isn’t a clever side strategy anymore. It is the strategy.

The economics are brutal and obvious. Breaking into a single well-positioned software provider gives attackers downstream access to every company running that vendor’s code. The return on investment per intrusion skyrockets. The blast radius expands far beyond what any direct attack could achieve. And the defenders on the receiving end — smaller manufacturers, regional healthcare systems, municipal utilities — often have no idea they’re exposed until the ransom note appears.
This supply chain focus intersects uncomfortably with broader industrial concerns. As manufacturers push deeper into digital infrastructure — including the software systems that support carbon emissions compliance and green transformation — the attack surface grows with every integration. Digitizing operations is not optional anymore. But every new connection is also a new door.
Halcyon’s Q2 2026 Ransomware Evolution Report documents the operational evolution in granular terms. Shutting down endpoint detection and response tools before encryption begins — what researchers call EDR-kill — was once a niche capability. Now it’s table stakes. Groups like The Gentlemen, one of the most prolific threats tracked in 2026, have built EDR and antivirus shutdown directly into their standard attack chain. Defenders are losing detection windows that were already uncomfortably short.
Is the Security Industry Actually Keeping Pace — Or Just Saying It Is?
Here’s the uncomfortable truth most enterprise security vendors won’t say plainly: the industry has been losing this fight for years, and the gap is widening. Not because defenders lack talent or tools. But because the incentive structure is broken. Security is still sold as a cost center. Boards still treat it as a compliance checkbox. And ransomware groups have figured out that the soft underbelly isn’t the firewall — it’s the procurement decision three vendors up the supply chain that nobody audited.

The Italian data is a useful case study in how this plays out geographically. Northwest Italy absorbed 42.6% of all confirmed ransomware claims in the first half of the tracked period — 63 victims — largely because that’s where the industrial density is. LockBit5 and Qilin led the attack volume. The numbers, as Security Affairs noted, are almost certainly undercount; leak-site disclosures from criminal groups are marketing copy, not audited records. The real figure is higher. It always is.
The AI angle here deserves direct treatment without the usual breathless framing. Ransomware groups using AI to build new malware isn’t science fiction in 2026 — it’s documented, confirmed, and accelerating. The same technology fueling Alzheimer’s research breakthroughs and AI data center cost projections is being used to automate extortion at industrial scale. That’s not a paradox. It’s just what powerful general-purpose tools do — they go everywhere, including places we’d rather they didn’t.
The pattern that emerges from NCC Group’s findings, Halcyon’s Q2 report, and the FBI’s complaint data is consistent: ransomware is not a niche crime problem or an IT department headache. It is a systemic infrastructure risk operating with increasingly sophisticated tooling, and any organization still treating it as someone else’s problem is making a very expensive assumption.
If you run, work at, or depend on any organization connected to a software vendor — which is to say, essentially everyone — 2026 is the year the supply chain threat became your personal problem whether you opted in or not.
Watch the Breakdown
Sources
- Ransomware Groups Increasingly Deploy EDR Kill Techniques — www.infosecurity-magazine.com
- LockBit5 and Qilin Lead Ransomware Attacks Against Italian Organizations — securityaffairs.com
- Aponte warns of record increase in cyber fraud and ransomware attacks — www.sanjuandailystar.com
