Ransomware Activity Surged 22% in July, Reaching 2026 Peak

Ransomware Attacks Hit 2026 High in July, NCC Group Reports

HIGH
August 26, 2026
September 23, 2026
m read
RansomwareThreat IntelligenceThreat Actor

Related Entities(initial)

Threat Actors

CRPxOThe Gentlemen

Organizations

NCC Group

Other

JADEPUFFER

Full Report(when first published)

Executive Summary

Global ransomware attacks reached a 2026 peak in July, with 894 publicly reported cases, according to the monthly threat intelligence report from NCC Group. This figure represents a significant 22% increase from June 2026 and is the highest monthly total recorded this year. The data underscores a persistent and escalating threat landscape, with the Industrials sector continuing to be the most heavily targeted industry. Geographically, North America and Europe remain the epicenters of ransomware activity, collectively accounting for 70% of all attacks.


Threat Overview

July's surge in ransomware activity brings the total number of attacks closer to the all-time monthly highs seen in early 2025, indicating that threat actors are operating with high efficiency and success. The key findings from the report include:

  • Total Attacks: 894 cases in July, a 22% month-over-month increase.
  • Top Targeted Industry: The Industrials sector was the most victimized, representing 28% of all attacks. This includes manufacturing, engineering, and construction firms, which are often prime targets due to their low tolerance for operational downtime.
  • Top Targeted Regions: North America (41%) and Europe (29%) were the most affected regions, consistent with trends throughout the year.

Threat Actor Analysis

The report highlights the activities of both established and emerging ransomware groups:

  • Established Actors: One prominent group, identified as "The Gentlemen," was highly active, claiming responsibility for 15% of all attacks recorded in July. The continued dominance of such groups demonstrates the effectiveness of the Ransomware-as-a-Service (RaaS) model.
  • New Entrants: A new group named "CRPxO" emerged in July, claiming 36 victims. NCC Group notes that such claims from new groups should be treated with caution, as they often exaggerate their impact to build a reputation in the cybercriminal underground.

NCC Group also speculates on the future of ransomware, noting the potential for AI-driven agents like JADEPUFFER to automate and scale attacks, possibly contributing to future increases in attack volume.


Impact Assessment

The sustained high volume of ransomware attacks has a significant impact on businesses and critical infrastructure worldwide. The consequences of an attack include:

  • Financial Loss: Costs associated with ransom payments, recovery efforts, legal fees, and regulatory fines.
  • Operational Disruption: Significant downtime for critical business systems, leading to lost revenue and productivity.
  • Data Breach: Double-extortion tactics, where attackers not only encrypt data but also steal it and threaten to leak it publicly, have become standard practice.
  • Reputational Damage: Loss of customer trust and damage to the company's brand.

The heavy targeting of the Industrials sector is particularly concerning, as it can lead to disruptions in manufacturing and supply chains with real-world consequences.


Detection & Response

Organizations must adopt a proactive stance to defend against ransomware.

  • Detection: Deploy EDR/XDR solutions to detect common ransomware TTPs, such as the disabling of security tools, mass file encryption, and deletion of volume shadow copies. Monitor for lateral movement using tools like Cobalt Strike and Brute Ratel.
  • Response: An effective incident response plan is crucial. This should include steps to isolate affected systems, engage incident response specialists, and restore from secure, offline backups. The decision to pay a ransom should be carefully considered with legal counsel, as it does not guarantee data recovery and funds criminal enterprises.

Mitigation

A multi-layered defense strategy is essential to mitigate the risk of a successful ransomware attack.

  • Patch Management (M1051): Promptly patch vulnerabilities in internet-facing systems, which are a primary initial access vector for ransomware groups.
  • Multi-factor Authentication (M1032): Enforce MFA on all remote access services (VPNs, RDP), email accounts, and critical system logins.
  • Network Segmentation (M1030): Segment networks to prevent the rapid lateral movement of ransomware. Isolate critical systems from the general corporate network.
  • Backups: Maintain regular, tested, and offline/immutable backups of critical data. This is the most important tool for recovery without paying a ransom.
  • User Training (M1017): Educate employees to recognize and report phishing emails, which remain a common entry point for ransomware attacks.

Timeline of Events

1
July 31, 2026
The month of July concludes with 894 recorded ransomware attacks, a 22% increase from June and the highest monthly total for 2026.
2
August 26, 2026
NCC Group publishes its Monthly Threat Pulse report detailing the July ransomware statistics.
3
August 26, 2026
This article was published

Article Updates

September 17, 2026

Severity increased

Manufacturing remains top ransomware target, with attacks surging 40% year-over-year in H1 2026, shifting focus to Europe and smaller businesses.

A new report confirms manufacturing as the #1 ransomware target for the 4th year, with attacks surging 39.7% year-over-year in H1 2026. The threat landscape shows a geographic shift, with Europe (especially Germany) seeing an 85.4% increase in victims, while the US share drops. Attackers are increasingly targeting small-to-medium enterprises (SMEs). The group "The Gentlemen" remains highly active, claiming 142 manufacturing victims by mid-2026. New mitigation strategies emphasize External Attack Surface Management and robust network monitoring.

September 23, 2026

Severity increased

August 2026 saw ransomware attacks hit a new record high of 1,073 victims, with the Qilin group emerging as the most prolific threat actor, surpassing 'The Gentlemen'.

Ransomware activity continued its upward trend, reaching a new 2026 record in August with 1,073 publicly reported victims, a 12% increase from July. The industrial sector remained the primary target, accounting for 31% of attacks, and North America was the most impacted region. A significant shift in the threat actor landscape occurred, with the Qilin ransomware group becoming the most prolific, responsible for 15% of attributable attacks, thereby surpassing 'The Gentlemen' group. High-profile entities like Boston Dynamics and Manchester Airports Group were also mentioned as targets, highlighting the widespread impact.

Timeline of Events

1
July 31, 2026

The month of July concludes with 894 recorded ransomware attacks, a 22% increase from June and the highest monthly total for 2026.

2
August 26, 2026

NCC Group publishes its Monthly Threat Pulse report detailing the July ransomware statistics.

Sources & References(when first published)

Article Author

Jason Gomes

Jason Gomes

• Cybersecurity Practitioner

Cybersecurity professional with over 10 years of specialized experience in security operations, threat intelligence, incident response, and security automation. Expertise spans SOAR/XSOAR orchestration, threat intelligence platforms, SIEM/UEBA analytics, and building cyber fusion centers. Background includes technical enablement, solution architecture for enterprise and government clients, and implementing security automation workflows across IR, TIP, and SOC use cases.

Threat Intelligence & AnalysisSecurity Orchestration (SOAR/XSOAR)Incident Response & Digital ForensicsSecurity Operations Center (SOC)SIEM & Security AnalyticsCyber Fusion & Threat SharingSecurity Automation & IntegrationManaged Detection & Response (MDR)

Editorial Standards & Analyst Review

CyberNetSec.io uses automation to assist source monitoring, deduplication, observable extraction, and structured intelligence generation. Published analysis follows human-defined editorial standards and adds defensive context including MITRE ATT&CK, D3FEND, STIX, and Sigma where applicable. Read our editorial policy.

Tags

Double ExtortionIndustrialsNCC GroupRansomwareThreat Intelligence

📢 Share This Article

Help others stay informed about cybersecurity threats

🎯 MITRE ATT&CK Mapped

Every tactic, technique, and sub-technique used in this threat has been identified and mapped to the MITRE ATT&CK framework for consistent, actionable threat language.

🧠 Enriched & Analyzed

Observables and indicators of compromise (IOCs) have been extracted and cataloged. Risk has been assessed and correlated with known threat actors and historical campaigns.

🛡️ Actionable Guidance

Detection rules, incident response steps, and D3FEND-aligned mitigation strategies are included so your team can act on this intelligence immediately.

🔗 STIX Visualizer

Structured threat data is packaged as a STIX 2.1 bundle and can be visualized as an interactive graph — relationships between actors, malware, techniques, and indicators.

⚡ Sigma Generator

Sigma detection rules are derived from the threat techniques in this article and can be converted for deployment across any major SIEM or EDR platform.