Play Ransomware Scores Just 13% Prevention as Evasion Techniques Bypass Security Controls
Brief
Play ransomware recorded the weakest prevention result in Picus Blue Report 2026 data, with only 13% of tested attack activity stopped by security controls .
The result shows a growing problem for defenders, organizations may have many security products, but those tools do not always prevent the techniques attackers use in real intrusions.
Picus analyzed ten ransomware families with the lowest prevention scores, including Play, BlackByte, LockBit, BabLock, Magniber, FAUST, Sodinokibi/REvil, Hive, BlackKingdom, and Maori. Prevention scores ranged from 13% for Play to 38% for Hive, BlackKingdom, and Maori.
The research focused on two MITRE ATT&CK areas, Stealth and Defense Impairment. These tactics help ransomware stay hidden, avoid detection, weaken endpoint security, and remove evidence before encryption begins.
