Black Kite reports 7,551 publicly disclosed ransomware victims from Apr-2025 to Mar-2026, +24.9% YoY, with a 60% acceleration in the second half (ending at 861 victims in March 2026, highest monthly total in four years). The ecosystem is becoming more fragmented (146 active groups by Jun 2026; Qilin >1,300 victims), and post-disclosure exposure persists—stealer log exposure is up 175% and 43.5% of victims still had critical patch vulnerabilities. The report attributes the worsening to AI lowering attacker operational costs and barriers to entry, prompting recommended action around vulnerability exploitation-in-the-wild, third-party risk management beyond questionnaires, and stronger identity verification/vishing defenses.
This is less a single-company cyber headline than a signal that attack costs are falling faster than defender budgets can adapt. That tends to shift spend toward identity, third-party risk, help-desk hardening, and continuous exposure monitoring, which is structurally constructive for security vendors with workflow integration and enterprise trust, while being mildly negative for large software platforms that sit in the path of vendor connectivity.
ORCL is the cleaner watch item because legacy ERP and integration-heavy estates are where operational ransomware becomes a board-level problem; the financial damage is usually not license churn, but longer security reviews, more conservative module rollouts, and higher services burden around migrations and controls. CRM faces a similar trust overhang through ecosystem connectors and OAuth workflows, but the more likely impact is friction at the margin on enterprise procurement rather than a demand air pocket; this is a valuation/multiple issue, not a core growth thesis break.
The second-order winner is the security stack: identity, privileged access, email protection, and third-party risk management should see better budget priority over the next 1-3 quarters as buyers respond to higher incident frequency. The contrarian point is that AI is helping attackers scale, but it is not yet creating a step-function in breach sophistication; that argues for persistent elevated volumes, not panic-level discounting of all software. What would falsify the bearish read on ORCL/CRM is evidence on upcoming earnings calls that incident-related security spending is not tightening procurement, or that ransomware volumes decelerate and vendor due-diligence cycles normalize.
AI-powered research, real-time alerts, and portfolio analytics for institutional investors.
Request TrialOverall Sentiment
moderately negative
Sentiment Score
-0.35
Ticker Sentiment