Advertisement

Ransomware cases climb to 2026 peak in August

Global ransomware activity rose to its highest monthly level of 2026 in August, with 1,073 known attacks recorded worldwide, according to NCC Group’s latest cyber threat intelligence data.

The total marked a 12% month-on-month increase, the security company said, extending a sharp mid-year rise in criminal extortion campaigns. Industrial organisations were hit hardest, accounting for 329 incidents, or 31% of the global total, while consumer discretionary businesses suffered 185 attacks, representing 17%.

North America remained the principal target, with 473 attacks, or 44% of all cases tracked during the month. Europe followed with 276 incidents, equal to 26%, while Asia accounted for 13%. The concentration in North America and Europe maintained a pattern seen throughout 2026, although ransomware operations continued to affect organisations across every major region.

Qilin emerged as the most active identified ransomware group in August, accounting for 15% of attacks and overtaking The Gentlemen, which had led activity in July. NCC Group said the figures illustrated how quickly the ransomware ecosystem can shift as established operators expand campaigns and newer groups enter the market.

The rise was especially pronounced in industrial environments, where attacks can disrupt manufacturing, logistics and other physical operations as well as corporate networks. NCC Group has previously found that industrial organisations were the most frequently targeted sector over the 12 months from March 2025, with 2,073 ransomware attacks during that period and an average share of 29.6% of observed activity.

August’s 31% share was also higher than the 28% recorded for industrial targets in July. Capital goods companies, machinery businesses and construction and engineering firms have been among the industrial sub-sectors facing sustained pressure, reflecting attackers’ interest in organisations where downtime can carry substantial operational and financial costs.

NCC Group also highlighted the activity of Aurora, a ransomware operation that emerged this year and has targeted organisations in manufacturing, legal services, research and development and transportation. Its digital forensics team examined an August case involving a transport-sector organisation where attackers exploited remote-access infrastructure, harvested credentials and encrypted a hypervisor before leaving a ransom demand.

The company said the Aurora intrusion reflected tactics already common among ransomware operators, including virtual private network exploitation and credential theft. Data extortion has also become an increasingly important objective alongside encryption, with some groups stealing information to pressure victims even when they do not lock large numbers of systems.

Among notable disruptions during August, Manchester Airports Group disclosed that customer information connected with services including parking, lounges, fast-track bookings and airport Wi-Fi had been exposed. Boston Scientific also experienced an intrusion affecting multiple information technology systems, disrupting manufacturing, shipping and customer order processing.

The figures underline the continued scale of ransomware-as-a-service, a model in which operators develop malicious tools and infrastructure while affiliates conduct intrusions and share proceeds. That structure has allowed criminal groups to broaden their reach, replace disrupted brands and recruit specialists for initial access, data theft, negotiation and money laundering.

Matt Hull, vice-president of cyber intelligence and response at NCC Group, said August was the second consecutive month to set a yearly high and pointed to artificial intelligence advances and geopolitical volatility among factors reshaping the threat environment. He said organisations needed resilience and response capabilities that could keep pace with changing attack methods.

NCC Group’s broader 2026 data show that ransomware volumes had already accelerated before August. The company recorded 665 attacks in June, while industrials accounted for 28% of that month’s total. Its second-quarter analysis logged 2,229 attacks, up 3% from the first quarter, with industrial companies responsible for 30% of cases.

The company has cautioned that public ransomware counts do not capture every intrusion. Some victims do not disclose attacks, some incidents never appear on extortion sites, and claims posted by criminal groups can be exaggerated or false. The monthly figures therefore provide a measure of observed activity rather than a complete count of all ransomware incidents worldwide.
Previous Post Next Post

Advertisement

Advertisement

نموذج الاتصال