Skip to main content
Emerging ThreatsMalware & Ransomware

Ransomware Attacks Soar to Record 1073 in August

City street scene with modern and old buildings, pedestrians, and a bus.

“August was the second consecutive month of highest ransomware levels for the year, indicating a steady rise in global activity,” said Matt Hull, VP of cyber intelligence and response at NCC Group.

Record monthly total: 1,073 organizations hit in August

Analysis by NCC Group published on September 23 found that 1,073 companies were victims of ransomware in August 2026 — a record high for the year and a 12% rise from July, when 973 organizations were struck. The firm described August as the second consecutive month of peak activity for 2026, a signal that the upward trend observed mid-year did not abate.

Geography: North America bore 44% of incidents

Ransomware incidents in August showed a clear geographic concentration. North America accounted for 44% of known attacks, Europe for 26%, and Asia for 13%. South America, Africa and Oceania made up the remainder, with 6%, 2% and 2% respectively. Those proportions frame where response and mitigation efforts will most frequently be required if reporting patterns persist.

Sectoral focus: industrial operations and consumer services felt the most disruption

The industrial sector was the most targeted industry in August, responsible for almost a third — 31% — of all reported incidents. Other heavily affected sectors included consumer goods and service at 18%, healthcare at 12%, information technology at 11% and financial services at 6%. The distribution highlights that operational technology, supply chains and customer-facing services were common ransomware targets in August.

Qilin, The Gentlemen, and other prolific groups

For attacks that could be tied to named threat actors, NCC Group attributed 164 incidents to Qilin and 116 incidents to The Gentlemen — two groups that the report says have traded places repeatedly this year as the most prolific operators. Other frequently attributed groups included Clop (89 incidents), Dire Wolf (43) and INC Ransom (43).

The report also warned of a tactical shift by some criminal groups: rather than prioritizing encryption, certain actors are moving “away from encryption in favour of going straight for outright data theft and extortion,” a change that can intensify pressure on victims and alter the calculus for response and disclosure.

Notable incidents: Boston Dynamics targeted; Manchester Airport Group breached

The NCC summary named two high-profile events in August. One was a cyber-attack that targeted Boston Dynamics; another was a data breach affecting Manchester Airport Group. The Manchester Airport Group case was cited specifically as an example of the move toward direct data theft and extortion, reinforcing the report’s point about shifting attacker behavior.

NCC Group recommendations and what technologists, policymakers, and enterprises will watch

Matt Hull linked the rise in activity to multiple drivers: “A combination of factors is driving this increase including rapid advancements in AI and ongoing geopolitical volatility which are fuelling state-sponsored threats. As the threat landscape evolves, organisations must ensure their resilience and response capabilities keep pace,” he added. NCC Group recommended that organizations prepare a defence plan and a strategy playbook that can be used if an attack occurs, and that they conduct tabletop exercises to identify and close gaps in cybersecurity strategy.

  • Technologists and security teams: will use tabletop exercises and playbooks to test and sharpen incident responses, prioritizing resilience and the ability to react if attackers skip encryption and go straight to data theft.
  • Policymakers and regulators: will need to monitor how rapid advancements in AI and geopolitical volatility are cited as drivers of increased activity, particularly where NCC links those trends to a rise in state-sponsored threats.
  • Affected enterprises and procurement leaders: will be pressured to adopt defined defence plans and to close strategic gaps identified by exercises, especially in sectors highlighted by NCC such as industrial, consumer goods and healthcare.

August’s figures — 1,073 victims and a month-on-month 12% rise — leave a clear prompt: defenders have an explicit set of recommendations to follow, and the report identifies where and how attackers concentrated their efforts. Whether organizations will adopt the playbooks and rehearsal practices NCC recommends will be the immediate test of whether the steady rise in ransomware activity translates into longer-term operational change.

https://www.infosecurity-magazine.com/news/ransomware-attacks-reach-record/