Ransomware threats in 2026 are not merely “computer viruses”. Most are criminal ecosystems that combine stolen access, data theft, encryption and public extortion. This guide explains ten operations Australian businesses should recognise, who they have affected, the costs that can be verified and the warning signs worth checking.
The watchlist starts with the ten variants most frequently reported to the FBI in 2025, then checks their position against fresh Q1 and Q2 2026 research. It is a practical risk guide, not a breaking-news league table and not a claim that every leak-site post is true.
By Compuloop | Australian managed IT and cybersecurity guidance | Published 29 July 2026
Ransomware threats 2026: the short answer
The FBI’s 2025 Internet Crime Report names Akira, Qilin, INC/Lynx/Sinobi, BianLian, Play, RansomHub, LockBit, DragonForce, SafePay and Medusa as the ten most frequently reported ransomware variants. Together, they represented 56.8% of reported ransomware incidents and losses equivalent to more than approximately A$23.0 million reported to the bureau.
That loss number is a floor, not the full bill. The FBI states that complaints often exclude lost business, time, wages, files, equipment and third-party remediation. Meanwhile, Check Point recorded 2,122 organisations on ransomware data-leak sites in Q1 2026, and GuidePoint recorded 2,279 in Q2.
How this top ten was chosen
Base list: the FBI’s ten most frequently reported ransomware variants for 2025. 2026 check: Q1 and Q2 threat research was used to show whether activity continued, grew or declined. Cost rule: a number appears only when an authority, affected organisation or attributable filing published it.
Currency: every monetary amount is shown in Australian dollars. Source-currency figures were converted using RBA exchange rates published for 28 July 2026: approximately A$1.44 per US dollar and A$1.91 per UK pound. Converted figures are approximate and rounded to the nearest A$0.1 million.
Leak-site counts are attacker claims and can contain duplicates or false claims. They are labelled as claimed victims rather than confirmed breaches. Company costs are not automatically proof of actor attribution.
The top 10 ransomware threats and their documented impact
| Threat | Documented cost or impact | Evidence status |
|---|---|---|
| 1. Akira | Approximately A$350.4 million ransomware proceeds, converted to AUD | FBI estimate; RBA currency conversion |
| 2. Qilin | Approximately A$62.4 million estimated Synnovis loss, converted to AUD | Official UK estimate; RBA currency conversion |
| 3. INC, Lynx and Sinobi | Not publicly disclosed verified aggregate damage cost | Activity verified; aggregate loss unavailable |
| 4. BianLian | Not publicly disclosed verified aggregate damage cost | Official joint advisory |
| 5. Play | About 900 entities affected by May 2025 | Official joint advisory |
| 6. RansomHub | Approximately A$50.2 million Halliburton expense, converted to AUD | Cost confirmed; actor link unconfirmed |
| 7. LockBit | Approximately A$717.7 million+ ransom payments, converted to AUD | US DOJ estimate; RBA currency conversion |
| 8. DragonForce | Approximately A$250.4 million M&S incident costs, converted to AUD | Cost confirmed; actor attribution unconfirmed |
| 9. SafePay | 22 claimed victims in Q1 2026 | Threat-intelligence count |
| 10. Medusa | More than 300 victims reported by February 2025 | Official joint advisory |
1. Akira: Approximately A$350.4 million
The FBI’s updated Akira advisory said the operation had received ransomware proceeds equivalent to approximately A$350.4 million by late September 2025. The advisory identifies manufacturing, education, information technology, healthcare, financial services and food and agriculture among affected sectors.
Akira is not a simple email virus. Affiliates gain access, move through a network, steal data and encrypt systems. The business pressure comes from both downtime and threatened publication. In Q1 2026, Check Point found Akira especially concentrated in consumer goods and industrial manufacturing, where production delays can quickly become expensive.
Look out for: exposed or weakly protected remote access, reused credentials, unmanaged administrator accounts and backups reachable from the production domain. Australian firms should also verify that old VPN accounts are disabled and that recovery copies are isolated and tested.
2. Qilin: Approximately A$62.4 million
Qilin remained the most prominent operation in Q1 2026, with 338 victims posted to its data-leak site. Its most sobering documented impact is the 2024 attack on Synnovis, a pathology provider for London hospitals. A UK Government impact assessment estimated losses equivalent to approximately A$62.4 million and more than 11,000 postponed outpatient appointments and elective procedures.
The UK NCSC’s 2025 annual review said the incident directly contributed to at least one patient death. That is why Qilin belongs near the top of a business watchlist: the harm is operational and human, not just technical.
Look out for: unmanaged internet-facing devices, stolen credentials and accounts that can reach too many systems. Prioritise network segmentation, privileged-access controls and service continuity plans for processes that cannot wait for a full technical recovery.
3. INC, Lynx and Sinobi: Not publicly disclosed
The FBI’s 2025 IC3 report grouped INC, Lynx and Sinobi among the variants most frequently reported to the bureau. The names matter because the ransomware market constantly rebrands, splits and reuses code, infrastructure and affiliate relationships. A familiar intrusion pattern can reappear under a new leak-site name.
Check Point recorded 80 Sinobi claimed victims in Q1 2026, down 42% from the previous quarter. That decline is useful intelligence, but it does not make an exposed business safe. Data-leak-site counts measure public claims, not every intrusion, and some victims may never be listed.
Look out for: security decisions based only on a malware name or file hash. Defenders should monitor behaviours such as credential dumping, remote administration, unusual archive creation, bulk data transfer and mass file changes. No defensible aggregate loss figure is public, so this article does not manufacture one.
4. BianLian: Not publicly disclosed
A joint FBI, CISA and ASD ACSC advisory says BianLian has targeted organisations in multiple US critical-infrastructure sectors as well as Australian critical-infrastructure organisations and private enterprises. The group moved away from primarily encrypting systems and toward data theft followed by extortion.
That shift matters. A business can restore every server and still face privacy, legal and reputational harm if sensitive data has been copied. Backups remain essential, but they are not a complete control for a data-extortion event.
Look out for: remote access through compromised credentials, unusual use of legitimate administration tools, data staged into large archives and outbound transfers to unfamiliar destinations. Test whether monitoring can detect theft before encryption or an extortion email makes the incident obvious.
5. Play: About 900 entities
The FBI, CISA and ASD ACSC Play advisory reported approximately 900 affected entities by May 2025. Play has used a double-extortion model and recompiled its ransomware binary for individual attacks, creating unique hashes that weaken simplistic blocklists.
Play was still moving in 2026. Check Point recorded 121 claimed victims in Q1 2026, a 64% quarter-on-quarter increase. That does not tell us the total damage bill, and no verified aggregate cost is publicly available.
Look out for: unpatched edge devices, exposed remote services, valid-account abuse and lateral movement that blends into ordinary administrator traffic. Use multi-factor authentication, patch internet-facing systems promptly and collect logs centrally so an attacker cannot erase the only copy.
6. RansomHub: Approximately A$50.2 million
The FBI, CISA, MS-ISAC and HHS advisory describes RansomHub affiliates using phishing, stolen credentials and exploitation of public-facing applications, followed by data theft, encryption and pressure to pay.
Halliburton’s 2024 financial disclosure recorded cybersecurity-incident expense equivalent to approximately A$50.2 million. RansomHub publicly claimed responsibility, but Halliburton’s filings did not identify the actor. Therefore, the cost is confirmed for the incident while the RansomHub attribution remains a public claim, not a company-confirmed fact.
Look out for: a false sense of certainty created by a criminal leak-site post. During an incident, preserve evidence, separate verified findings from attacker claims and maintain one approved communications record for customers, insurers, regulators and staff.
7. LockBit: Approximately A$717.7 million+
The US Department of Justice says LockBit victims made ransom payments equivalent to at least approximately A$717.7 million and incurred substantial additional losses that were not precise enough to convert responsibly. The DOJ’s dedicated LockBit case page records more than 2,500 victims across at least 120 countries.
International law-enforcement action disrupted LockBit infrastructure, yet Check Point recorded 163 claimed victims in Q1 2026. A takedown can raise the operator’s cost and expose members, but it does not instantly remove affiliates, stolen access or copied tooling.
Look out for: assuming a well-publicised disruption has removed the threat. Keep controls aimed at common intrusion paths: phishing-resistant MFA for privileged users, rapid patching, application allow-listing, segmented backups and tested isolation procedures.
8. DragonForce: Approximately A$250.4 million
Marks & Spencer reported FY25/26 cyber-incident costs equivalent to approximately A$250.4 million. The retailer had earlier estimated an effect equivalent to approximately A$572.2 million on operating profit before mitigation. Those are company-published business figures, not ransom amounts.
Google Threat Intelligence said public reporting suggested tactics consistent with UNC3944 and deployment of DragonForce ransomware at a UK retailer, but Google did not independently confirm that attribution. M&S also did not name the actor. The article keeps that uncertainty beside the cost rather than hiding it in a footnote.
Separately, GuidePoint ranked DragonForce third by claimed victims in Q2 2026. Look out for: social engineering aimed at help desks, identity resets and remote-access enrolment. Strong technology can still be bypassed when an attacker persuades a person to change the attacker’s access.
9. SafePay: 22 claimed victims
Check Point recorded 22 SafePay claimed victims in Q1 2026, down 77% from 97 in the previous quarter. Its data-leak site was marked inactive from mid-March into early April. Lower public activity is a signal to monitor, not proof that operators or access have disappeared.
Check Point’s SafePay profile describes an operation that can move from initial compromise to ransomware deployment in less than 24 hours. It also cites the 2024 incident at UK telematics company Microlise as an early high-profile claim.
Look out for: slow escalation between identity, network and endpoint teams. A fast intrusion demands pre-agreed thresholds for disabling accounts, isolating devices and blocking remote access. No verified aggregate damage cost is public, so the activity count is shown instead.
10. Medusa: More than 300 victims
A joint FBI, CISA and MS-ISAC advisory said Medusa had affected more than 300 victims by February 2025. Targeted sectors included medical, education, legal, insurance, technology and manufacturing organisations.
Medusa affiliates use a ransomware-as-a-service model. The advisory describes common paths such as phishing and exploitation of unpatched vulnerabilities. It also documents double extortion: stealing data before encrypting systems, then threatening publication.
Look out for: patch backlogs, flat networks and security alerts that have no named owner. Maintain an asset inventory, prioritise internet-facing vulnerabilities, require MFA for remote access and rehearse a response that can preserve evidence while restoring essential services. A verified aggregate loss figure is not publicly disclosed.
What Australian businesses should check this month
The names will change. The controls below remain useful because they address the common paths that ransomware affiliates exploit. They also align with the ASD Essential Eight and official ransomware guidance.
- Identity: require MFA for remote access and administrators; remove dormant accounts; review emergency access.
- Internet-facing systems: inventory VPNs, firewalls, remote tools and web applications; patch by risk and exposure.
- Privileges: separate daily and administrative accounts; reduce standing access; alert on role changes.
- Endpoints: use application control and endpoint detection; investigate disabled protection or unusual remote tools.
- Data movement: detect large archives, unusual cloud uploads and outbound transfers before encryption begins.
- Backups: keep isolated, immutable or offline copies; protect backup administration separately; test real restores.
- Segmentation: stop one compromised account or device from reaching every server, cloud tenant and backup system.
- Response: assign decision owners, preserve logs, document insurer and legal contacts, and rehearse service isolation.
Compuloop can turn this list into a scoped Essential Eight review, cybersecurity assessment or backup recovery test for an Australian business. The goal is a prioritised improvement plan, not a fear-based product list.
If ransomware is already suspected
Do not rush to wipe systems or negotiate from an employee’s personal email. First, isolate affected devices and accounts where this can be done safely, preserve logs and volatile evidence, activate the incident plan and contact qualified legal, insurance and forensic advisers. Keep operational recovery separate from public attribution until evidence supports it.
Australian organisations can use ReportCyber and the Australian Cyber Security Centre’s ransomware guidance. If people may be at risk or sensitive data may have been accessed, involve the appropriate privacy, safety and regulatory functions promptly.
Ransomware readiness is a business-continuity exercise
Review managed IT support, Microsoft 365 security, cybersecurity services and data backup solutions. Each link leads to a real service, not a generic sales form.
Find the weak point before an extortion crew does
Book a practical ransomware-readiness review covering identity, endpoints, remote access, backups, monitoring and incident response.
Request a ransomware reviewCall 1300 007 613Email CompuloopQuestions businesses ask about ransomware in 2026
Are these really the top ten computer viruses of 2026?
They are the ten ransomware variants most frequently reported to the FBI in 2025, checked against current 2026 activity. Most are criminal service operations rather than self-spreading computer viruses.
Does a leak-site victim count prove every breach?
No. Leak-site listings are attacker claims. They help measure activity, but can include duplicates, misidentification or organisations that have not confirmed an incident.
Why do some threats have no damage-cost figure?
Because no defensible aggregate figure is public. Ransom demands, payments, recovery costs and total economic harm are different measures. “Not publicly disclosed” is more accurate than an estimate presented as fact.
Will backups stop ransomware?
Backups can restore systems, but they do not prevent stolen data being published. Effective preparation also needs identity controls, endpoint protection, segmentation, logging, data-loss monitoring and a rehearsed response.
What is the first practical step for a small business?
Confirm MFA coverage, internet-facing assets, administrator accounts and whether a recent backup can actually be restored. Those checks often expose the most urgent work quickly.
Sources and editorial standards
- FBI: 2025 Internet Crime Report
- Check Point Research: State of Ransomware, Q1 2026
- GuidePoint Research and Intelligence Team: Q2 2026 report
- Reserve Bank of Australia: exchange rates used for AUD conversions
- FBI: StopRansomware Akira advisory
- UK Government: Cyber Security and Resilience Bill impact assessment
- FBI, CISA and ASD ACSC: BianLian advisory
- FBI, CISA and ASD ACSC: Play advisory
- FBI, CISA, MS-ISAC and HHS: RansomHub advisory
- US Department of Justice: LockBit case update
- FBI, CISA and MS-ISAC: Medusa advisory
Editorial note: evidence was checked on 29 July 2026. Criminal leak-site claims are labelled as claims. Company incident costs are not described as ransom payments unless the source says so. Logos are used for editorial identification and do not imply endorsement. This article will be corrected if material evidence changes.





