Americas Ransomware Trends H1 2026: Qilin, Akira, and Exploitation of Ivanti and Fortinet Infrastructure
In H1 2026, the Americas emerged as the global epicenter for ransomware, accounting for 57% of worldwide incidents (2,188 total). The landscape is transitioning to extortion-centric models, where actors prioritize exfiltrating high-leverage data—such as legal and patient records—over encryption. Technical indicators show significant integration of AI to accelerate Active Directory enumeration and malware generation, increasing operational "signal speed." Attackers are actively weaponizing vulnerabilities in edge infrastructure, specifically Ivanti, Fortinet, Cisco, SolarWinds, and Palo Alto Networks appliances. The market is bifurcated: North America features a hyper-competitive RaaS ecosystem led by Qilin and Akira, while South America is a consolidating market dominated by 'The Gentlemen.'
LockBit 5.0, StealBit, Insight Hospital, and Capital Health: Double-Extortion Healthcare Campaigns
LockBit ransomware operators, employing the evolved LockBit 5.0 ("ChuongDong") variant and the StealBit exfiltration tool, have executed successful double-extortion campaigns against Insight Hospital and Medical Center and Capital Health. The Insight Hospital breach involved the exfiltration of ~200 GB of sensitive PHI/PII, including Social Security numbers and treatment records. Capital Health suffered a massive 7 TB data theft, resulting in a $4.5 million legal settlement. These attacks leverage advanced evasion techniques, including EtwEventWrite API patching and cross-platform payloads (Windows, Linux, and ESXi), to bypass modern security defenses and leverage stolen data on dark web leak sites to maximize extortion pressure.