Ransomware Activity Rebounds in July
New data indicates a sharp rise in ransomware incidents throughout July 2026, breaking a multi-month period of lower activity.
A Shift in Threat Landscape
The frequency of ransomware incidents experienced a notable escalation in July 2026, reversing the downward trend observed throughout the second quarter of the year. After a period of relative quiet across April, May, and June, the volume of reported attacks rose significantly, marking a return to heightened operational levels for malicious actors.
Data compiled by Comparitech identified a total of 799 claimed ransomware attacks during the month of July. This figure represents a 19% increase compared to the activity levels recorded in June. When viewed against broader historical data, this surge positions July as the second most active month of 2026 and the third highest month for ransomware volume over the past 17 months.
Targeted Industry Sectors
The resurgence in activity was not distributed evenly across the economy. Specific sectors faced a disproportionate share of the escalation, with finance and technology entities bearing the brunt of the increased assault. The rapid rise in attacks suggests a focused shift in targeting strategies during the mid-summer period.
- Finance: 71% increase in attacks
- Technology: 62% increase in attacks
- Healthcare: 46% increase in attacks
- Education: 44% increase in attacks
The impact was also geographically concentrated, with organizations based in the United States seeing a 31% rise in incidents from June to July. High-profile cases underscore the operational severity of these campaigns, such as the disruption caused to the Romanian government's land registry agency, which suffered from a wiped database, and the forced closure of facilities at the US healthcare provider AnMad.
The Proliferation of Key Actors
Two specific threat groups, The Gentlemen and Qilin, maintain a dominant position in the current ransomware ecosystem. According to the analysis, these two entities were responsible for 33% of all claimed attacks in July. The Gentlemen accounted for 135 incidents, while Qilin was linked to 125.
This ongoing competition between the groups follows a trend identified earlier this year. Research from ReliaQuest previously indicated that The Gentlemen had overtaken the historically dominant Qilin outfit as the primary threat actor behind extortion campaigns between March and May 2026. Other active groups identified in the July data include DragonForce with 41 attacks, INC with 36, CRPx0 with 33, and SafePay with 30.
These attacks highlight how ransomware groups hit organizations in various different ways – taking down key systems, stealing troves of data, and even deleting massive datasets. Never has it been more important for organisations to ensure they're carrying out regular backups (and backups of their backups!) so they can reset systems and restore data as quickly as possible if the worst does happen.
— Rebecca Moody, head of data research at Comparitech
Implications for Organizational Defense
The rebound in ransomware activity serves as a reminder of the volatility inherent in cyber extortion trends. For organizations, the data suggests that reliance on static security postures may be insufficient as threat actors demonstrate the ability to rapidly scale their operations after periods of dormancy. The focus on data deletion and system disruption, as seen in the recent incidents involving government and healthcare entities, highlights the critical necessity for robust, redundant backup strategies.
As these groups continue to compete for prominence, the resulting pressure on targeted sectors could persist, necessitating a heightened state of readiness. The ability to restore operations from clean, air-gapped backups remains the primary mechanism for mitigating the long-term impact of a successful encryption or data-wiping event.
Sources
- Infosecurity Magazine Original source
- analysis Also reporting
Continue Reading
Rust Developers Hit by Fake Job Call Scam
Rust team members and crate owners are being targeted by attackers who pose as recruiters to hijack credentials and push malicious packages.
Jade Sleet's macOS backdoors hit IT vendor
SentinelOne tied North Korea's Jade Sleet to an India-based IT services breach that deployed two Rust macOS backdoors on a DevOps engineer's MacBook.
Gang-on-Gang Hack Hits Clop Leak Site
ShinyHunters claims it stole private keys and server data from rival Clop, defacing the ransomware group's dark web leak site.