July was the worst month for ransomware victim claims in 2026 - or was it?
We shouldn't ignore agentic AI ransomware threats, but the claims of a new ransomware group might be skewing the numbers.
In July 2026, ransomware attacks reached a year-to-date high, with a total of 894 victim organization listings recorded. This increase was attributed to various factors, including the emergence of new ransomware groups and the use of agentic AI. NCC Group's research revealed that 10 cybercriminal groups were responsible for the majority of these attacks, with The Gentlemen accounting for 138 incidents.
The Gentlemen, Quilin, Deadlock, DragonForce, INC Ransom, CRPxO, SafePay, Global Secret Group, KryBit, and Akira were among the top groups.
The industrial sector faced the highest number of attacks, followed by consumer services, technology, critical services, finance, and healthcare. In the US, 41% of incidents occurred, while 29% were in Europe, 14% in Asia, and 9% in South America.
Several high-profile attacks were recorded in July, including a data breach at Ernst & Young that exposed client information and tax records, as well as attacks on Coca-Cola's Fairlife subsidiary and Analog Devices. However, the credibility of some ransomware groups, such as CRPxO, which claimed to have hacked 36 organizations, remains questionable due to a lack of evidence and a low barriers-to-entry for emerging groups.
Looking forward, the evolving nature of ransomware attacks, particularly those powered by AI, will continue to pose a significant threat to individuals and enterprises.
Written by urgent.news from ZDNet's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.