Breaking
Cyber CrimeDeveloping Story

Ransomware Activity Rebounds in July

New data indicates a sharp rise in ransomware incidents throughout July 2026, breaking a multi-month period of lower activity.

··1 hour ago·3 min read
A close up of a computer screen with green text
Photo by wesfly on Unsplash

A Shift in Threat Landscape

The frequency of ransomware incidents experienced a notable escalation in July 2026, reversing the downward trend observed throughout the second quarter of the year. After a period of relative quiet across April, May, and June, the volume of reported attacks rose significantly, marking a return to heightened operational levels for malicious actors.

Data compiled by Comparitech identified a total of 799 claimed ransomware attacks during the month of July. This figure represents a 19% increase compared to the activity levels recorded in June. When viewed against broader historical data, this surge positions July as the second most active month of 2026 and the third highest month for ransomware volume over the past 17 months.

Targeted Industry Sectors

The resurgence in activity was not distributed evenly across the economy. Specific sectors faced a disproportionate share of the escalation, with finance and technology entities bearing the brunt of the increased assault. The rapid rise in attacks suggests a focused shift in targeting strategies during the mid-summer period.

  • Finance: 71% increase in attacks
  • Technology: 62% increase in attacks
  • Healthcare: 46% increase in attacks
  • Education: 44% increase in attacks

The impact was also geographically concentrated, with organizations based in the United States seeing a 31% rise in incidents from June to July. High-profile cases underscore the operational severity of these campaigns, such as the disruption caused to the Romanian government's land registry agency, which suffered from a wiped database, and the forced closure of facilities at the US healthcare provider AnMad.

The Proliferation of Key Actors

Two specific threat groups, The Gentlemen and Qilin, maintain a dominant position in the current ransomware ecosystem. According to the analysis, these two entities were responsible for 33% of all claimed attacks in July. The Gentlemen accounted for 135 incidents, while Qilin was linked to 125.

This ongoing competition between the groups follows a trend identified earlier this year. Research from ReliaQuest previously indicated that The Gentlemen had overtaken the historically dominant Qilin outfit as the primary threat actor behind extortion campaigns between March and May 2026. Other active groups identified in the July data include DragonForce with 41 attacks, INC with 36, CRPx0 with 33, and SafePay with 30.

These attacks highlight how ransomware groups hit organizations in various different ways – taking down key systems, stealing troves of data, and even deleting massive datasets. Never has it been more important for organisations to ensure they're carrying out regular backups (and backups of their backups!) so they can reset systems and restore data as quickly as possible if the worst does happen.

— Rebecca Moody, head of data research at Comparitech

Implications for Organizational Defense

The rebound in ransomware activity serves as a reminder of the volatility inherent in cyber extortion trends. For organizations, the data suggests that reliance on static security postures may be insufficient as threat actors demonstrate the ability to rapidly scale their operations after periods of dormancy. The focus on data deletion and system disruption, as seen in the recent incidents involving government and healthcare entities, highlights the critical necessity for robust, redundant backup strategies.

As these groups continue to compete for prominence, the resulting pressure on targeted sectors could persist, necessitating a heightened state of readiness. The ability to restore operations from clean, air-gapped backups remains the primary mechanism for mitigating the long-term impact of a successful encryption or data-wiping event.

#ransomware#cybersecurity#threat intelligence#data breach

Sources

Iliyas

Editor, Xploitwire

This article was researched and drafted through our automated editorial pipeline from the sources listed above, then checked against those sources through our automated fact-check process, under the editorial policies set by Iliyas. Our Automation Policy →

← Back to all stories