“These attacks highlight how ransomware groups hit organizations in various different ways – taking down key systems, stealing troves of data, and even deleting massive datasets. Never has been more important for organisations to ensure they're carrying out regular backups (and backups of their backups!) so they can reset systems and restore data as quickly as possible if the worst does happen." — Rebecca Moody, head of data research at Comparitech
799 claimed attacks in July; a 19% month-on-month surge
Ransomware activity rebounded sharply in July, with Comparitech recording 799 claimed attacks — a 19% increase from June. That total made July the second-highest month of 2026 and the third-highest month for ransomware in the past 17 months, reversing a relative lull reported across April, May and June. The raw count and the month-on-month climb underscore that the short mid-year quiet was brief and that adversaries returned to large-scale operations as July closed.
Finance, technology, healthcare and education saw the steepest spikes
Comparitech's sector breakdown shows concentrated pressure on several critical industries. Finance experienced the largest month-to-month increase, jumping 71% in July. Technology rose 62%, healthcare 46% and education 44% — all markedly above the overall 19% uptick. Comparitech highlighted high-impact incidents that illustrate the stakes: an attack on US healthcare provider AnMad led to facility closures, while the Romanian government's land registry agency suffered a wipe of an entire database that triggered significant disruption to the country's real estate market.

This site is the portfolio.
OSINTSights runs on Cloudflare Workers, D1, R2, and Vectorize, with an AI pipeline on Hetzner ARM. Nubivance designed, built, and operates it. We do the same for clients.
See what we buildUS organizations were targeted more frequently — up 31%
Geography shifted in July as well. Comparitech found attacks against US-based organizations rose by 31% from June. The data points to a notable reorientation of activity toward the United States during the month, reinforcing the operational impact illustrated by the AnMad healthcare outage. Separately, the Romanian land registry incident demonstrates that the effects are not confined to the US: a single successful intrusion can cascade into national-market disruption when critical public systems are hit.
The Gentlemen and Qilin: 33% of July’s attacks and an ongoing rivalry
Two ransomware groups accounted for a substantial share of July’s activity. The Gentlemen claimed 135 attacks and Qilin 125; together the two accounted for 33% of all recorded attacks in the month. Comparitech described these figures as continuation of a "battle" for supremacy between the strains. Supporting that narrative, ReliaQuest's analysis found The Gentlemen emerged as the most prolific cyber-extortion actor between March and May 2026, supplanting the previously dominant Qilin. Other active groups in July included DragonForce (41 attacks), INC (36), CRPx0 (33) and SafePay (30), but none approached the scale of the top two actors.
What this means for technologists, policymakers, and affected enterprises
- Technologists and security teams: The July spike and the concentration of attacks in finance, technology, healthcare and education suggest defenders should prioritise robust backup regimes and rapid recovery playbooks — a point stressed by Rebecca Moody’s recommendation to maintain backups of backups. Teams will also be watching the tactics and targeting patterns of The Gentlemen and Qilin, given their outsized share of activity.
- Policymakers and regulators: A 31% rise in attacks against US-based organizations and the wiping of a national land registry database in Romania signal that ransomware can produce systemic consequences for markets and public services. Regulators may take particular note of incidents that force facility closures or disrupt property transactions when assessing resilience requirements for critical services.
- Affected enterprises and procurement leaders: The sector-specific jumps — especially the 71% increase in finance — underline the need for continuity planning in high-risk sectors. The AnMad closure and the Romanian registry wipe are concrete examples of how operational disruption can follow successful extortion campaigns, reinforcing the business case for tested restoration procedures and contractual assurances from suppliers.
July's data offers a clear, if unwelcome, lesson: after a brief spring lull, ransomware creators remained capable and adaptive, concentrating efforts on high-value sectors and using both disruption and data destruction. The concentration of claims around The Gentlemen and Qilin points to an intensifying contest among criminal groups that defenders and policymakers will not be able to ignore. For now, the immediate practical action — as Comparitech's head of data research advised — is mundane but essential: ensure backups, and back up those backups.




