Global ransomware attacks reached a 2026 peak in July, with 894 publicly reported cases, according to the monthly threat intelligence report from NCC Group. This figure represents a significant 22% increase from June 2026 and is the highest monthly total recorded this year. The data underscores a persistent and escalating threat landscape, with the Industrials sector continuing to be the most heavily targeted industry. Geographically, North America and Europe remain the epicenters of ransomware activity, collectively accounting for 70% of all attacks.
July's surge in ransomware activity brings the total number of attacks closer to the all-time monthly highs seen in early 2025, indicating that threat actors are operating with high efficiency and success. The key findings from the report include:
The report highlights the activities of both established and emerging ransomware groups:
NCC Group also speculates on the future of ransomware, noting the potential for AI-driven agents like JADEPUFFER to automate and scale attacks, possibly contributing to future increases in attack volume.
The sustained high volume of ransomware attacks has a significant impact on businesses and critical infrastructure worldwide. The consequences of an attack include:
The heavy targeting of the Industrials sector is particularly concerning, as it can lead to disruptions in manufacturing and supply chains with real-world consequences.
Organizations must adopt a proactive stance to defend against ransomware.
A multi-layered defense strategy is essential to mitigate the risk of a successful ransomware attack.
Manufacturing remains top ransomware target, with attacks surging 40% year-over-year in H1 2026, shifting focus to Europe and smaller businesses.
A new report confirms manufacturing as the #1 ransomware target for the 4th year, with attacks surging 39.7% year-over-year in H1 2026. The threat landscape shows a geographic shift, with Europe (especially Germany) seeing an 85.4% increase in victims, while the US share drops. Attackers are increasingly targeting small-to-medium enterprises (SMEs). The group "The Gentlemen" remains highly active, claiming 142 manufacturing victims by mid-2026. New mitigation strategies emphasize External Attack Surface Management and robust network monitoring.
August 2026 saw ransomware attacks hit a new record high of 1,073 victims, with the Qilin group emerging as the most prolific threat actor, surpassing 'The Gentlemen'.
Ransomware activity continued its upward trend, reaching a new 2026 record in August with 1,073 publicly reported victims, a 12% increase from July. The industrial sector remained the primary target, accounting for 31% of attacks, and North America was the most impacted region. A significant shift in the threat actor landscape occurred, with the Qilin ransomware group becoming the most prolific, responsible for 15% of attributable attacks, thereby surpassing 'The Gentlemen' group. High-profile entities like Boston Dynamics and Manchester Airports Group were also mentioned as targets, highlighting the widespread impact.
The month of July concludes with 894 recorded ransomware attacks, a 22% increase from June and the highest monthly total for 2026.
NCC Group publishes its Monthly Threat Pulse report detailing the July ransomware statistics.

Cybersecurity professional with over 10 years of specialized experience in security operations, threat intelligence, incident response, and security automation. Expertise spans SOAR/XSOAR orchestration, threat intelligence platforms, SIEM/UEBA analytics, and building cyber fusion centers. Background includes technical enablement, solution architecture for enterprise and government clients, and implementing security automation workflows across IR, TIP, and SOC use cases.
CyberNetSec.io uses automation to assist source monitoring, deduplication, observable extraction, and structured intelligence generation. Published analysis follows human-defined editorial standards and adds defensive context including MITRE ATT&CK, D3FEND, STIX, and Sigma where applicable. Read our editorial policy.
Help others stay informed about cybersecurity threats
Every tactic, technique, and sub-technique used in this threat has been identified and mapped to the MITRE ATT&CK framework for consistent, actionable threat language.
Observables and indicators of compromise (IOCs) have been extracted and cataloged. Risk has been assessed and correlated with known threat actors and historical campaigns.
Detection rules, incident response steps, and D3FEND-aligned mitigation strategies are included so your team can act on this intelligence immediately.
Structured threat data is packaged as a STIX 2.1 bundle and can be visualized as an interactive graph — relationships between actors, malware, techniques, and indicators.
Sigma detection rules are derived from the threat techniques in this article and can be converted for deployment across any major SIEM or EDR platform.