Ransomware attacks jumped nearly 20 percent in July, with UK firm Comparitech counting 799 incidents, up from 668 in June.
Scale and shifting targets: finance, tech, pharma, medical billers, education
Comparitech’s tally places July as the second-busiest month of 2026 so far, with 799 incidents logged — narrowly behind March’s 805. The composition of victims shifted markedly: attacks on finance companies rose 71 percent month‑over‑month, tech firms 62 percent, pharmaceutical companies and medical billers 46 percent, and the education sector 44 percent. By contrast, attacks on utilities fell 44 percent; legal firms were down 31 percent and government agencies fell 11 percent, Comparitech reported.
Geography: the United States led targets
The United States was the most-targeted country in July, accounting for 322 of the 799 incidents recorded, Comparitech said. Germany ranked second with 40 incidents. Those numbers show a concentration of activity in the U.S. market during the month in question.

Audit-ready is a season. It shouldn't be.
Evidence in spreadsheets, controls drifting between audits, frameworks multiplying on flat headcount. Nubivance runs continuous compliance on Rapid7 Cyber GRC - SOC 2, HIPAA, ISO 27001, PCI, CMMC.
End the scrambleThe Gentlemen and Qilin: two gangs dominate July’s activity
Two named ransomware operations accounted for a significant share of the July wave. The Gentlemen, described in Comparitech’s data as a relative newcomer that has become prolific, claimed 135 victims in July. Qilin, the group behind the 2024 attack on pathology provider Synnovis that disrupted NHS services in the UK, claimed 125 victims. Together the two gangs accounted for nearly 33 percent of the attacks logged during the month.
Ingress methods and basic mitigations
Comparitech provided no direct data on how attackers gained initial access to victims in July. The reporting does note possible methods consistent with what other firms have observed: Trend Micro attributed The Gentlemen’s methodology to stolen credentials, while Qilin told The Register it abused zero-day vulnerabilities to break into Synnovis in June 2024. From those observed patterns the advised mitigations in the source are straightforward: ensure employees use a second secure factor to log in, keep systems updated, and make regular backups.
How finance, education, and healthcare will feel the pressure
- Finance companies: Comparitech recorded a 71 percent rise in attacks on finance firms in July. DeepStrike’s findings, cited in the same reporting, indicate that finance organizations nonetheless remain among the sectors likeliest to pay ransoms — with finance still paying roughly half the time — making them a high-return target for extortion.
- Education institutions: With a 44 percent increase in attacks, the education sector joins manufacturing and healthcare on DeepStrike’s list of most frequent payers, which helps explain the rise in attempts and the incentive for operators to keep targeting this sector.
- Healthcare and medical billers: Attacks on pharmaceutical companies and medical billers rose 46 percent. Healthcare and related organizations appear repeatedly as attractive targets in the data cited, reinforcing the urgency of simple mitigations — multi‑factor authentication, patching, and backups — that the reporting highlights.
All eyes may be on what AI is doing to the security landscape, but the source’s data is a reminder that old‑school extortion economics and established intrusion techniques remain decisive drivers of damage. The July spike — concentrated in sectors that research shows are most likely to pay ransoms, and driven in part by two prolific gangs claiming a large share of victims — leaves a clear behavioral prescription embedded in the facts: reduce credential theft and vulnerability exposure, and maintain recoverable backups. Those steps won’t eliminate ransomware, but the July numbers show they remain central to limiting impact.




