Global Ransomware Attacks Reach Record High for 2026 in August
Share
Global ransomware attacks reached a new peak for 2026 in August, with 1,073 organisations falling victim to cyber extortion campaigns. Analysis from the NCC Group shows this represents a 12% increase in activity compared to the 973 incidents recorded during July.
The industrial sector was the most heavily targeted industry during the month, accounting for 31% of all reported ransomware incidents. Other sectors facing significant disruption included consumer goods and services (18%), healthcare (12%), information technology (11%), and financial services (6%).
Geographic Trends and Sector Vulnerabilities
North America was the most common target for ransomware attacks, accounting for 44% of incidents. Europe accounted for 26% of known attacks, while Asia saw 13%. The remaining incidents were spread across South America (6%), Africa (2%), and Oceania (2%).
The evolution of attack methods, including automated AI-driven intrusions, highlights the growing sophistication of modern threat actors. This complexity was evident in recent high-profile cases, such as the attack on Boston Dynamics and a data breach affecting the Manchester Airport Group.
The incident involving Manchester Airport Group serves as a signal that some cybercriminal groups are moving away from traditional file encryption. Instead, they are increasingly opting for direct data theft and extortion.
Prolific Threat Actors
In terms of attribution, Qilin and The Gentlemen have emerged as the most dominant threat actors of the year. During August, 164 incidents were linked to Qilin, while 116 were attributed to The Gentlemen. Other highly active groups included Clop (89), Dire Wolf (43), and INC Ransom (43).
Matt Hull, VP of cyber intelligence and response at NCC Group, stated that the steady rise in global activity is being driven by rapid advancements in AI and ongoing geopolitical volatility, which is fueling state-sponsored threats. He advised that organisations must ensure their resilience and response capabilities keep pace with the evolving landscape.
To prepare for potential breaches, the NCC Group recommends that organisations implement a formal defence plan and a strategic playbook to minimise operational impact. They also suggested conducting regular tabletop exercises to identify and close security gaps before they can be exploited by attackers.




Leave a Reply