Business knowledge guide | Evidence checked 29 July 2026

Ransomware threats in 2026 are not merely “computer viruses”. Most are criminal ecosystems that combine stolen access, data theft, encryption and public extortion. This guide explains ten operations Australian businesses should recognise, who they have affected, the costs that can be verified and the warning signs worth checking.

The watchlist starts with the ten variants most frequently reported to the FBI in 2025, then checks their position against fresh Q1 and Q2 2026 research. It is a practical risk guide, not a breaking-news league table and not a claim that every leak-site post is true.

Evidence status: official reports, company disclosures and attributed threat research checked 29 July 2026
2026 ransomware watchlist card for AKIRA, showing A$350.4M approx. proceeds, converted to AUD and evidence from FBI / StopRansomware
Compuloop evidence card for AKIRA. Data source: FBI / StopRansomware. Logo source: FBI Cyber Division, used for editorial identification; no endorsement is implied. Monetary figures converted to AUD using RBA rates published 28 July 2026.

Ransomware threats 2026: the short answer

The FBI’s 2025 Internet Crime Report names Akira, Qilin, INC/Lynx/Sinobi, BianLian, Play, RansomHub, LockBit, DragonForce, SafePay and Medusa as the ten most frequently reported ransomware variants. Together, they represented 56.8% of reported ransomware incidents and losses equivalent to more than approximately A$23.0 million reported to the bureau.

That loss number is a floor, not the full bill. The FBI states that complaints often exclude lost business, time, wages, files, equipment and third-party remediation. Meanwhile, Check Point recorded 2,122 organisations on ransomware data-leak sites in Q1 2026, and GuidePoint recorded 2,279 in Q2.

2,122claimed data-leak-site victims in Q1 2026
2,279reported ransomware victims in Q2 2026
91active groups observed by GuidePoint in Q2 2026

How this top ten was chosen

Base list: the FBI’s ten most frequently reported ransomware variants for 2025. 2026 check: Q1 and Q2 threat research was used to show whether activity continued, grew or declined. Cost rule: a number appears only when an authority, affected organisation or attributable filing published it.

Currency: every monetary amount is shown in Australian dollars. Source-currency figures were converted using RBA exchange rates published for 28 July 2026: approximately A$1.44 per US dollar and A$1.91 per UK pound. Converted figures are approximate and rounded to the nearest A$0.1 million.

Leak-site counts are attacker claims and can contain duplicates or false claims. They are labelled as claimed victims rather than confirmed breaches. Company costs are not automatically proof of actor attribution.

Terminology: “virus” is familiar shorthand, but these are mainly ransomware-as-a-service groups, data-extortion operations and affiliate ecosystems. Correct terminology helps businesses defend against the full intrusion, not only the final encryption file.

The top 10 ransomware threats and their documented impact

Ten ransomware threats to watch in 2026 and their documented cost or impact signals
ThreatDocumented cost or impactEvidence status
1. AkiraApproximately A$350.4 million
ransomware proceeds, converted to AUD
FBI estimate; RBA currency conversion
2. QilinApproximately A$62.4 million
estimated Synnovis loss, converted to AUD
Official UK estimate; RBA currency conversion
3. INC, Lynx and SinobiNot publicly disclosed
verified aggregate damage cost
Activity verified; aggregate loss unavailable
4. BianLianNot publicly disclosed
verified aggregate damage cost
Official joint advisory
5. PlayAbout 900 entities
affected by May 2025
Official joint advisory
6. RansomHubApproximately A$50.2 million
Halliburton expense, converted to AUD
Cost confirmed; actor link unconfirmed
7. LockBitApproximately A$717.7 million+
ransom payments, converted to AUD
US DOJ estimate; RBA currency conversion
8. DragonForceApproximately A$250.4 million
M&S incident costs, converted to AUD
Cost confirmed; actor attribution unconfirmed
9. SafePay22 claimed victims
in Q1 2026
Threat-intelligence count
10. MedusaMore than 300 victims
reported by February 2025
Official joint advisory

1. Akira: Approximately A$350.4 million

DOCUMENTED SIGNALApproximately A$350.4 millionransomware proceeds, converted to AUDFBI estimate; RBA currency conversion

The FBI’s updated Akira advisory said the operation had received ransomware proceeds equivalent to approximately A$350.4 million by late September 2025. The advisory identifies manufacturing, education, information technology, healthcare, financial services and food and agriculture among affected sectors.

Akira is not a simple email virus. Affiliates gain access, move through a network, steal data and encrypt systems. The business pressure comes from both downtime and threatened publication. In Q1 2026, Check Point found Akira especially concentrated in consumer goods and industrial manufacturing, where production delays can quickly become expensive.

Look out for: exposed or weakly protected remote access, reused credentials, unmanaged administrator accounts and backups reachable from the production domain. Australian firms should also verify that old VPN accounts are disabled and that recovery copies are isolated and tested.

2. Qilin: Approximately A$62.4 million

DOCUMENTED SIGNALApproximately A$62.4 millionestimated Synnovis loss, converted to AUDOfficial UK estimate; RBA currency conversion

Qilin remained the most prominent operation in Q1 2026, with 338 victims posted to its data-leak site. Its most sobering documented impact is the 2024 attack on Synnovis, a pathology provider for London hospitals. A UK Government impact assessment estimated losses equivalent to approximately A$62.4 million and more than 11,000 postponed outpatient appointments and elective procedures.

The UK NCSC’s 2025 annual review said the incident directly contributed to at least one patient death. That is why Qilin belongs near the top of a business watchlist: the harm is operational and human, not just technical.

Look out for: unmanaged internet-facing devices, stolen credentials and accounts that can reach too many systems. Prioritise network segmentation, privileged-access controls and service continuity plans for processes that cannot wait for a full technical recovery.

2026 ransomware watchlist card for QILIN, showing A$62.4M estimated incident loss, converted to AUD and evidence from UK NCSC / NHS impact assessment
Compuloop evidence card for QILIN. Data source: UK NCSC / NHS impact assessment. Logo source: NHS England, used for editorial identification; no endorsement is implied. Monetary figures converted to AUD using RBA rates published 28 July 2026.

3. INC, Lynx and Sinobi: Not publicly disclosed

DOCUMENTED SIGNALNot publicly disclosedverified aggregate damage costActivity verified; aggregate loss unavailable

The FBI’s 2025 IC3 report grouped INC, Lynx and Sinobi among the variants most frequently reported to the bureau. The names matter because the ransomware market constantly rebrands, splits and reuses code, infrastructure and affiliate relationships. A familiar intrusion pattern can reappear under a new leak-site name.

Check Point recorded 80 Sinobi claimed victims in Q1 2026, down 42% from the previous quarter. That decline is useful intelligence, but it does not make an exposed business safe. Data-leak-site counts measure public claims, not every intrusion, and some victims may never be listed.

Look out for: security decisions based only on a malware name or file hash. Defenders should monitor behaviours such as credential dumping, remote administration, unusual archive creation, bulk data transfer and mass file changes. No defensible aggregate loss figure is public, so this article does not manufacture one.

2026 ransomware watchlist card for INC / LYNX / SINOBI, showing NOT PUBLIC verified aggregate damage cost and evidence from FBI IC3 / Check Point Research
Compuloop evidence card for INC / LYNX / SINOBI. Data source: FBI IC3 / Check Point Research. Logo source: Check Point, used for editorial identification; no endorsement is implied. Monetary figures converted to AUD using RBA rates published 28 July 2026.

4. BianLian: Not publicly disclosed

DOCUMENTED SIGNALNot publicly disclosedverified aggregate damage costOfficial joint advisory

A joint FBI, CISA and ASD ACSC advisory says BianLian has targeted organisations in multiple US critical-infrastructure sectors as well as Australian critical-infrastructure organisations and private enterprises. The group moved away from primarily encrypting systems and toward data theft followed by extortion.

That shift matters. A business can restore every server and still face privacy, legal and reputational harm if sensitive data has been copied. Backups remain essential, but they are not a complete control for a data-extortion event.

Look out for: remote access through compromised credentials, unusual use of legitimate administration tools, data staged into large archives and outbound transfers to unfamiliar destinations. Test whether monitoring can detect theft before encryption or an extortion email makes the incident obvious.

2026 ransomware watchlist card for BIANLIAN, showing NOT PUBLIC verified aggregate damage cost and evidence from FBI / CISA / ASD ACSC
Compuloop evidence card for BIANLIAN. Data source: FBI / CISA / ASD ACSC. Logo source: Australian Government, used for editorial identification; no endorsement is implied. Monetary figures converted to AUD using RBA rates published 28 July 2026.

5. Play: About 900 entities

DOCUMENTED SIGNALAbout 900 entitiesaffected by May 2025Official joint advisory

The FBI, CISA and ASD ACSC Play advisory reported approximately 900 affected entities by May 2025. Play has used a double-extortion model and recompiled its ransomware binary for individual attacks, creating unique hashes that weaken simplistic blocklists.

Play was still moving in 2026. Check Point recorded 121 claimed victims in Q1 2026, a 64% quarter-on-quarter increase. That does not tell us the total damage bill, and no verified aggregate cost is publicly available.

Look out for: unpatched edge devices, exposed remote services, valid-account abuse and lateral movement that blends into ordinary administrator traffic. Use multi-factor authentication, patch internet-facing systems promptly and collect logs centrally so an attacker cannot erase the only copy.

2026 ransomware watchlist card for PLAY, showing 900 affected entities reported by May 2025 and evidence from FBI / CISA / ASD ACSC
Compuloop evidence card for PLAY. Data source: FBI / CISA / ASD ACSC. Logo source: CISA, used for editorial identification; no endorsement is implied. Monetary figures converted to AUD using RBA rates published 28 July 2026.

6. RansomHub: Approximately A$50.2 million

DOCUMENTED SIGNALApproximately A$50.2 millionHalliburton expense, converted to AUDCost confirmed; actor link unconfirmed

The FBI, CISA, MS-ISAC and HHS advisory describes RansomHub affiliates using phishing, stolen credentials and exploitation of public-facing applications, followed by data theft, encryption and pressure to pay.

Halliburton’s 2024 financial disclosure recorded cybersecurity-incident expense equivalent to approximately A$50.2 million. RansomHub publicly claimed responsibility, but Halliburton’s filings did not identify the actor. Therefore, the cost is confirmed for the incident while the RansomHub attribution remains a public claim, not a company-confirmed fact.

Look out for: a false sense of certainty created by a criminal leak-site post. During an incident, preserve evidence, separate verified findings from attacker claims and maintain one approved communications record for customers, insurers, regulators and staff.

2026 ransomware watchlist card for RANSOMHUB, showing A$50.2M incident expense, converted to AUD and evidence from Halliburton SEC filing / CISA
Compuloop evidence card for RANSOMHUB. Data source: Halliburton SEC filing / CISA. Logo source: Halliburton, used for editorial identification; no endorsement is implied. Monetary figures converted to AUD using RBA rates published 28 July 2026.

7. LockBit: Approximately A$717.7 million+

DOCUMENTED SIGNALApproximately A$717.7 million+ransom payments, converted to AUDUS DOJ estimate; RBA currency conversion

The US Department of Justice says LockBit victims made ransom payments equivalent to at least approximately A$717.7 million and incurred substantial additional losses that were not precise enough to convert responsibly. The DOJ’s dedicated LockBit case page records more than 2,500 victims across at least 120 countries.

International law-enforcement action disrupted LockBit infrastructure, yet Check Point recorded 163 claimed victims in Q1 2026. A takedown can raise the operator’s cost and expose members, but it does not instantly remove affiliates, stolen access or copied tooling.

Look out for: assuming a well-publicised disruption has removed the threat. Keep controls aimed at common intrusion paths: phishing-resistant MFA for privileged users, rapid patching, application allow-listing, segmented backups and tested isolation procedures.

2026 ransomware watchlist card for LOCKBIT, showing A$717.7M+ ransom payments, converted to AUD and evidence from US Department of Justice
Compuloop evidence card for LOCKBIT. Data source: US Department of Justice. Logo source: US Department of Justice, used for editorial identification; no endorsement is implied. Monetary figures converted to AUD using RBA rates published 28 July 2026.

8. DragonForce: Approximately A$250.4 million

DOCUMENTED SIGNALApproximately A$250.4 millionM&S incident costs, converted to AUDCost confirmed; actor attribution unconfirmed

Marks & Spencer reported FY25/26 cyber-incident costs equivalent to approximately A$250.4 million. The retailer had earlier estimated an effect equivalent to approximately A$572.2 million on operating profit before mitigation. Those are company-published business figures, not ransom amounts.

Google Threat Intelligence said public reporting suggested tactics consistent with UNC3944 and deployment of DragonForce ransomware at a UK retailer, but Google did not independently confirm that attribution. M&S also did not name the actor. The article keeps that uncertainty beside the cost rather than hiding it in a footnote.

Separately, GuidePoint ranked DragonForce third by claimed victims in Q2 2026. Look out for: social engineering aimed at help desks, identity resets and remote-access enrolment. Strong technology can still be bypassed when an attacker persuades a person to change the attacker’s access.

2026 ransomware watchlist card for DRAGONFORCE, showing A$250.4M M&S incident costs, converted to AUD and evidence from M&S results / Google Threat Intelligence
Compuloop evidence card for DRAGONFORCE. Data source: M&S results / Google Threat Intelligence. Logo source: Marks & Spencer, used for editorial identification; no endorsement is implied. Monetary figures converted to AUD using RBA rates published 28 July 2026.

9. SafePay: 22 claimed victims

DOCUMENTED SIGNAL22 claimed victimsin Q1 2026Threat-intelligence count

Check Point recorded 22 SafePay claimed victims in Q1 2026, down 77% from 97 in the previous quarter. Its data-leak site was marked inactive from mid-March into early April. Lower public activity is a signal to monitor, not proof that operators or access have disappeared.

Check Point’s SafePay profile describes an operation that can move from initial compromise to ransomware deployment in less than 24 hours. It also cites the 2024 incident at UK telematics company Microlise as an early high-profile claim.

Look out for: slow escalation between identity, network and endpoint teams. A fast intrusion demands pre-agreed thresholds for disabling accounts, isolating devices and blocking remote access. No verified aggregate damage cost is public, so the activity count is shown instead.

2026 ransomware watchlist card for SAFEPAY, showing 22 claimed victims in Q1 2026 and evidence from Check Point Research
Compuloop evidence card for SAFEPAY. Data source: Check Point Research. Logo source: Check Point, used for editorial identification; no endorsement is implied. Monetary figures converted to AUD using RBA rates published 28 July 2026.

10. Medusa: More than 300 victims

DOCUMENTED SIGNALMore than 300 victimsreported by February 2025Official joint advisory

A joint FBI, CISA and MS-ISAC advisory said Medusa had affected more than 300 victims by February 2025. Targeted sectors included medical, education, legal, insurance, technology and manufacturing organisations.

Medusa affiliates use a ransomware-as-a-service model. The advisory describes common paths such as phishing and exploitation of unpatched vulnerabilities. It also documents double extortion: stealing data before encrypting systems, then threatening publication.

Look out for: patch backlogs, flat networks and security alerts that have no named owner. Maintain an asset inventory, prioritise internet-facing vulnerabilities, require MFA for remote access and rehearse a response that can preserve evidence while restoring essential services. A verified aggregate loss figure is not publicly disclosed.

2026 ransomware watchlist card for MEDUSA, showing 300+ victims reported by February 2025 and evidence from FBI / CISA / MS-ISAC
Compuloop evidence card for MEDUSA. Data source: FBI / CISA / MS-ISAC. Logo source: Federal Bureau of Investigation, used for editorial identification; no endorsement is implied. Monetary figures converted to AUD using RBA rates published 28 July 2026.

What Australian businesses should check this month

The names will change. The controls below remain useful because they address the common paths that ransomware affiliates exploit. They also align with the ASD Essential Eight and official ransomware guidance.

  • Identity: require MFA for remote access and administrators; remove dormant accounts; review emergency access.
  • Internet-facing systems: inventory VPNs, firewalls, remote tools and web applications; patch by risk and exposure.
  • Privileges: separate daily and administrative accounts; reduce standing access; alert on role changes.
  • Endpoints: use application control and endpoint detection; investigate disabled protection or unusual remote tools.
  • Data movement: detect large archives, unusual cloud uploads and outbound transfers before encryption begins.
  • Backups: keep isolated, immutable or offline copies; protect backup administration separately; test real restores.
  • Segmentation: stop one compromised account or device from reaching every server, cloud tenant and backup system.
  • Response: assign decision owners, preserve logs, document insurer and legal contacts, and rehearse service isolation.

Compuloop can turn this list into a scoped Essential Eight review, cybersecurity assessment or backup recovery test for an Australian business. The goal is a prioritised improvement plan, not a fear-based product list.

If ransomware is already suspected

Do not rush to wipe systems or negotiate from an employee’s personal email. First, isolate affected devices and accounts where this can be done safely, preserve logs and volatile evidence, activate the incident plan and contact qualified legal, insurance and forensic advisers. Keep operational recovery separate from public attribution until evidence supports it.

Australian organisations can use ReportCyber and the Australian Cyber Security Centre’s ransomware guidance. If people may be at risk or sensitive data may have been accessed, involve the appropriate privacy, safety and regulatory functions promptly.

Ransomware readiness is a business-continuity exercise

Review managed IT support, Microsoft 365 security, cybersecurity services and data backup solutions. Each link leads to a real service, not a generic sales form.

Find the weak point before an extortion crew does

Book a practical ransomware-readiness review covering identity, endpoints, remote access, backups, monitoring and incident response.

Request a ransomware reviewCall 1300 007 613Email Compuloop

Questions businesses ask about ransomware in 2026

Are these really the top ten computer viruses of 2026?

They are the ten ransomware variants most frequently reported to the FBI in 2025, checked against current 2026 activity. Most are criminal service operations rather than self-spreading computer viruses.

Does a leak-site victim count prove every breach?

No. Leak-site listings are attacker claims. They help measure activity, but can include duplicates, misidentification or organisations that have not confirmed an incident.

Why do some threats have no damage-cost figure?

Because no defensible aggregate figure is public. Ransom demands, payments, recovery costs and total economic harm are different measures. “Not publicly disclosed” is more accurate than an estimate presented as fact.

Will backups stop ransomware?

Backups can restore systems, but they do not prevent stolen data being published. Effective preparation also needs identity controls, endpoint protection, segmentation, logging, data-loss monitoring and a rehearsed response.

What is the first practical step for a small business?

Confirm MFA coverage, internet-facing assets, administrator accounts and whether a recent backup can actually be restored. Those checks often expose the most urgent work quickly.

Sources and editorial standards