Security

Ransomware Detections Fell 68%, and Extortion Claims Just Hit a Record Anyway

WatchGuard's 1H 2026 Threat Report found endpoint ransomware detections down 68% year over year while public extortion claims neared 5,000, the most on record. The gap between the two numbers is AI-assisted precision that most defenses were never built to see.

September 22, 2026 · Security
A tight angle on server rack cabling and patch panels in a data centre, lit blue with a lens flare

Key Takeaways

  • WatchGuard's 1H 2026 Internet Security Report found endpoint ransomware detections down 68% year over year, even as 41 new ransomware groups emerged and the top eight groups alone accounted for more than half of nearly 5,000 public extortion claims, a record pace.
  • Ninety-five percent of malware in the report arrived over encrypted TLS connections, yet only 20% of devices actually inspect that traffic, and evasive malware cleared 36% of detections even on devices running advanced defenses.
  • Darktrace's State of AI Cybersecurity 2026 survey of more than 1,500 professionals found 87% observing more AI-driven threats and 46% still feeling inadequately prepared, barely improved from 60% unprepared in 2024.
  • Check Point's 2026 Cloud Security Report found 77% of organizations updated their cloud security strategy for AI, but only 26% can actually enforce the updated policy, a 51-point gap between intent and capability.

A 68% drop in ransomware detections sounds like the best news the industry has had in years. According to WatchGuard's newly published 1H 2026 Threat Report, that is exactly the number, and it is exactly the wrong conclusion to draw from it. Public extortion claims are simultaneously on pace for a record year, 41 new ransomware groups surfaced in six months, and the top eight of them alone accounted for more than half of nearly 5,000 claims. Fewer alarms went off. The damage did not shrink to match.

The Alerts Went Quiet Because the Attacks Got Precise

WatchGuard's Chief Information Security Officer, Corey Nachreiner, put the disconnect plainly: "Attackers are not less dangerous because alert totals declined. They are using every tool at their disposal to become more selective and precise." The report backs that up with numbers that only make sense together. Network attack volume fell 79%, but novel malware on endpoints rose more than 2,000% year over year, and 96% of endpoint threats appeared on exactly one machine. That is not an industry under less pressure, it is an industry being hit by campaigns engineered to look like nothing rather than campaigns loud enough to count.

The delivery mechanism explains why signature-based tools keep missing it. Ninety-five percent of malware in the report travelled over encrypted TLS connections, and only 20% of devices actually inspect that traffic before it lands. Evasive malware, built specifically to slip past detection, still cleared 36% of devices running advanced defenses, and a third of the median vulnerabilities being actively exploited trace back to 2014, a decade-old weakness nobody expected to still matter. Attackers are not choosing between old tricks and new ones. They are running both.

The Confidence Gap Has Barely Moved in Two Years

Darktrace's State of AI Cybersecurity 2026 survey of more than 1,500 security professionals shows the human side of the same problem. Eighty-seven percent are seeing more AI-driven threats, 73% say those threats already have a significant organizational impact, and 87% say AI is directly increasing both malware sophistication and its success rate against them. None of that is contested internally: 92% agree AI-driven threats are forcing a defense upgrade now.

What has not moved is confidence. Forty-six percent of respondents still feel inadequately prepared for the current threat landscape, only a modest improvement on the 60% who said the same in 2024. Two years of vendor investment, board attention, and new tooling closed roughly a third of the preparedness gap and left the rest standing. Sixty-two percent of organizations reported a deepfake-based social engineering attempt, and a third of malicious emails observed in 2025 ran over 1,000 characters, a pattern consistent with large language model generation rather than a human writing on a deadline. The threats are not hypothetical anymore. The readiness still is.

Intent Outran Enforcement by 51 Points

Check Point's 2026 Cloud Security Report measures exactly where that gap sits inside an organization. Seventy-seven percent of respondents updated their cloud security strategy specifically for AI. Only 26% can actually enforce that updated policy consistently, a 51-point gap between what leadership decided and what the environment will actually let them do. Seventy-eight percent reported a confirmed or suspected AI-related security incident, 54% confirmed one outright, and 24% could not even say either way because they lack the visibility to tell.

The report ties the enforcement gap to architecture as much as intent. Only 24% of organizations can fully inspect AI traffic without a performance hit, 71% report a rise in web application firewall false positives as AI traffic volume grows, and 67% describe their policies as fragmented across environments, exactly the condition that lets a precisely targeted, TLS-encrypted, single-machine threat move without tripping anything at all.

Sixty-eight percent, 79%, 2,000%. Each of WatchGuard's numbers moves in the direction that should reassure a security team, and together they describe an industry under more pressure than it has faced in years. The organizations that will do well in the next twelve months are not the ones celebrating quieter dashboards. They are the ones asking why the dashboards went quiet.

Share

More in Security

All Resources →