Skip to main content
Emerging ThreatsMalware & Ransomware

Ransomware Attacks Soar to Record High in Q3 2026

Dimly lit hospital corridor with open doors and a laptop on a counter, screen glowing with a soft gradient.

"I'm often asked what I think lies ahead in the ransomware threat landscape, and it's notoriously difficult to predict. Figures frequently fluctuate and a sector might see a bit of an increase one month, only to see a slight decrease the next month. However, Q3 2026 is different. We're not seeing slight increases or decreases. We're seeing significant increases across all key sectors,” Rebecca Moody, head of data research at Comparitech, said.

Comparitech analysis: 2,627 claimed attacks in Q3 2026

Comparitech recorded 2,627 claimed ransomware attacks during July–September 2026, the highest quarterly volume the firm has identified. That total represents a 27% increase from Q2 2026 and a 61% rise compared with Q3 2025. Of the 2,627 attacks claimed by ransomware groups in Q3, 247 incidents have been confirmed by the entity involved, Comparitech found. The firm described the figures as “highly unusual” and “a significant cause for concern.”

Sector and country concentration: finance, technology, and the US

Growth in claimed attacks was concentrated in particular sectors. Finance saw the largest quarter-over-quarter rise at 72%, closely followed by technology at 70%. Other critical sectors also experienced notable jumps: education (up 50%), healthcare (39%), government (36%) and utilities (32%).

By country, the United States recorded the most claimed attacks in Q3 with 1,066 incidents — 41% of the total and a 34% increase from Q2. Germany followed with 121 claimed incidents, up 22%. Argentina and India posted the largest percentage increases in claimed attacks quarter-to-quarter, rising 150% and 116%, respectively.

AI and JadePuffer: a possible driver of scale and speed

Comparitech flagged developments in artificial intelligence as a possible explanation for the surge. The report noted that AI technology may be “enabling ransomware attackers to increase the scale and speed of campaigns, as well as their effectiveness.” In July, researchers identified the JadePuffer campaign, which was described in the report as being “believed to be the world’s first ransomware attack completely driven by AI.”

Triple extortion and The Gentlemen's actions against MIP Holdings

The report highlights a rise in triple extortion tactics, in which attackers not only encrypt systems and exfiltrate data but also target individuals affected by an incident. “A prime example is The Gentlemen's recent attack on MIP Holdings (a South African tech company). After being targeted by the group in June 2026, MIP paid a ransom to have stolen data deleted. Over the last few weeks, however, The Gentlemen has started adding MIP's clients to its data leak site in a bid to get a ransom out of them, too,” Moody said. She added that this demonstrates that paying a ransom is no guarantee the attacker will keep to their word about deleting stolen data.

Who’s behind the volume: Qilin, The Gentlemen, Clop, Direwolf — and demand sizes

Qilin and The Gentlemen were the most prolific claimants in Q3, claiming 357 and 342 attacks respectively — a 24% rise for Qilin and a 29% rise for The Gentlemen compared to Q2. Clop’s claimed volume rose sharply from one attack in Q2 to 48 in Q3, a 4,700% increase. Direwolf also increased claimed activity, up 1,450% over the same interval.

Monetary demands rose alongside volume. Comparitech reported the average ransomware demand in Q3 as $602,400. The largest known demand was $12.3m, issued by Everest against Swiss-based railway manufacturer Stadler Rail in July 2026; Stadler refused to pay and Everest subsequently leaked 201 GB of stolen data. Another notable case saw Rhysida demand $2.3m from the State of Berlin after compromising the authority’s network; after a public refusal to pay, the group published 5.7 TB of stolen data, including personal information of citizens.

What this means for technologists, policymakers, and affected enterprises

  • Technologists and security teams: the simultaneous rise in volume across finance, technology, education, healthcare, government and utilities — plus the reported role of AI and the appearance of JadePuffer — signals an environment where scale, speed and new tactics such as triple extortion will require focused monitoring.
  • Policymakers and regulators: the large national counts (the US with 1,066 claimed incidents) and high-profile leaks (201 GB from Stadler, 5.7 TB from Berlin) underline public-interest and cross-border data-exposure concerns that may shape regulatory attention.
  • Affected enterprises and procurement leaders: an average demand of $602,400 and individual demands as high as $12.3m demonstrate both the financial stakes and the limits of ransom payments, as shown in the MIP Holdings example where payment did not guarantee deletion of stolen data.

Q3 2026 closes as a landmark quarter: the highest quarterly tally Comparitech has recorded, sharp sectoral increases, new extortion techniques in active use, and AI-linked campaigns such as JadePuffer cited as a possible accelerating factor. The record raises a concrete question the data leave open — if AI-enabled operations and triple extortion continue to spread, will subsequent quarters match or exceed Q3’s unprecedented scale?

Source: Infosecurity Magazine — Q3 2026 Sets New Record for Ransomware Attacks (Comparitech analysis)