179,000+ records compromised
A new report from Comparitech reveals that ransomware attacks against government organizations have reached a new intensity, with an average of one successful attack per day during the first half of 2026. The study documented 187 separate incidents globally, a 13% rise compared to the second half of 2025. These attacks have led to significant operational downtime, disruption of public services, and data breaches affecting nearly 179,000 individuals. The United States remains the most targeted nation, though the number of attacks has slightly decreased. The report identifies The Gentlemen, Qilin, and LockBit as the most prolific threat groups targeting this sector.
The report underscores that government agencies are highly attractive targets due to the critical services they provide and the sensitive citizen data they hold, creating immense pressure to pay ransoms to restore operations and prevent data leaks.
The attacks on government agencies leverage a variety of common ransomware TTPs. While specific vectors for each of the 187 incidents vary, the general attack chain involves:
T1566 - Phishing campaigns targeting government employees, exploitation of unpatched public-facing services (T1190 - Exploit Public-Facing Application), or use of stolen credentials purchased on the dark web (T1078 - Valid Accounts).T1486 - Data Encrypted for Impact) and exfiltrating sensitive data for double extortion (T1567 - Exfiltration Over Web Service). Attackers also frequently attempt to disable recovery options (T1490 - Inhibit System Recovery).This is a trend report; no specific IOCs were provided.
Government IT teams should proactively hunt for generic ransomware precursors:
command_line_patternnltest /dclist:process_namemimikatz.exenetwork_traffic_patternlog_sourceGiven the high frequency of attacks, government agencies must prioritize foundational cybersecurity hygiene:
New details on H1 2026 government ransomware attacks include a 23% decrease in US incidents, specific financial impacts, and further emphasis on The Gentlemen's prominence.
Further analysis of the H1 2026 government ransomware report reveals that while the US remains the most targeted nation, it experienced a 23% decrease in attacks. The report also provides concrete examples of financial impact, such as Murray County's $200,000 ransom payment and South Africa's Land and Agricultural Development Bank successfully restoring systems after refusing a $3.1 million demand. The 'The Gentlemen' group is further highlighted as the most prolific actor, with additional TTP details for Qilin (spearphishing links) and LockBit (public-facing app exploits, Cobalt Strike) now included. Detection and mitigation strategies are also updated with specific D3FEND and MITRE ATT&CK references.
Median ransomware demands for government targets fell sharply from $500K to $100K in H1 2026, indicating a shift to higher volume, lower value attacks.
A new analysis of the Comparitech report reveals a significant shift in ransomware attacker strategy targeting government entities. The median ransom demand plummeted from $500,000 in H2 2025 to just $100,000 in H1 2026. This suggests threat actors like The Gentlemen, Qilin, and LockBit may be adopting a 'higher volume, lower value' approach, aiming for more frequent, smaller payouts from a broader range of government targets. This could lead to an increased number of incidents, even if individual financial impact is reduced, as smaller entities might be more inclined to pay lower ransoms quickly.
Start of the six-month period analyzed by the Comparitech report.
End of the six-month period, during which 187 ransomware attacks against governments were recorded.
Comparitech publishes its report on government ransomware attacks.

Cybersecurity professional with over 10 years of specialized experience in security operations, threat intelligence, incident response, and security automation. Expertise spans SOAR/XSOAR orchestration, threat intelligence platforms, SIEM/UEBA analytics, and building cyber fusion centers. Background includes technical enablement, solution architecture for enterprise and government clients, and implementing security automation workflows across IR, TIP, and SOC use cases.
CyberNetSec.io uses automation to assist source monitoring, deduplication, observable extraction, and structured intelligence generation. Published analysis follows human-defined editorial standards and adds defensive context including MITRE ATT&CK, D3FEND, STIX, and Sigma where applicable. Read our editorial policy.
Help others stay informed about cybersecurity threats
Every tactic, technique, and sub-technique used in this threat has been identified and mapped to the MITRE ATT&CK framework for consistent, actionable threat language.
Observables and indicators of compromise (IOCs) have been extracted and cataloged. Risk has been assessed and correlated with known threat actors and historical campaigns.
Detection rules, incident response steps, and D3FEND-aligned mitigation strategies are included so your team can act on this intelligence immediately.
Structured threat data is packaged as a STIX 2.1 bundle and can be visualized as an interactive graph — relationships between actors, malware, techniques, and indicators.
Sigma detection rules are derived from the threat techniques in this article and can be converted for deployment across any major SIEM or EDR platform.