Ransomware Activity Rebounds in July
New data indicates a sharp rise in ransomware incidents throughout July 2026, breaking a multi-month period of lower activity.
A Shift in Threat Landscape
The frequency of ransomware incidents experienced a notable escalation in July 2026, reversing the downward trend observed throughout the second quarter of the year. After a period of relative quiet across April, May, and June, the volume of reported attacks rose significantly, marking a return to heightened operational levels for malicious actors.
Data compiled by Comparitech identified a total of 799 claimed ransomware attacks during the month of July. This figure represents a 19% increase compared to the activity levels recorded in June. When viewed against broader historical data, this surge positions July as the second most active month of 2026 and the third highest month for ransomware volume over the past 17 months.
Targeted Industry Sectors
The resurgence in activity was not distributed evenly across the economy. Specific sectors faced a disproportionate share of the escalation, with finance and technology entities bearing the brunt of the increased assault. The rapid rise in attacks suggests a focused shift in targeting strategies during the mid-summer period.
- Finance: 71% increase in attacks
- Technology: 62% increase in attacks
- Healthcare: 46% increase in attacks
- Education: 44% increase in attacks
The impact was also geographically concentrated, with organizations based in the United States seeing a 31% rise in incidents from June to July. High-profile cases underscore the operational severity of these campaigns, such as the disruption caused to the Romanian government's land registry agency, which suffered from a wiped database, and the forced closure of facilities at the US healthcare provider AnMad.
The Proliferation of Key Actors
Two specific threat groups, The Gentlemen and Qilin, maintain a dominant position in the current ransomware ecosystem. According to the analysis, these two entities were responsible for 33% of all claimed attacks in July. The Gentlemen accounted for 135 incidents, while Qilin was linked to 125.
This ongoing competition between the groups follows a trend identified earlier this year. Research from ReliaQuest previously indicated that The Gentlemen had overtaken the historically dominant Qilin outfit as the primary threat actor behind extortion campaigns between March and May 2026. Other active groups identified in the July data include DragonForce with 41 attacks, INC with 36, CRPx0 with 33, and SafePay with 30.
These attacks highlight how ransomware groups hit organizations in various different ways – taking down key systems, stealing troves of data, and even deleting massive datasets. Never has it been more important for organisations to ensure they're carrying out regular backups (and backups of their backups!) so they can reset systems and restore data as quickly as possible if the worst does happen.
— Rebecca Moody, head of data research at Comparitech
Implications for Organizational Defense
The rebound in ransomware activity serves as a reminder of the volatility inherent in cyber extortion trends. For organizations, the data suggests that reliance on static security postures may be insufficient as threat actors demonstrate the ability to rapidly scale their operations after periods of dormancy. The focus on data deletion and system disruption, as seen in the recent incidents involving government and healthcare entities, highlights the critical necessity for robust, redundant backup strategies.
As these groups continue to compete for prominence, the resulting pressure on targeted sectors could persist, necessitating a heightened state of readiness. The ability to restore operations from clean, air-gapped backups remains the primary mechanism for mitigating the long-term impact of a successful encryption or data-wiping event.
Sources
- Infosecurity Magazine Original source
- analysis Also reporting
Continue Reading
ChainDrop Worm Exploits npm Ecosystem
A self-propagating malware campaign has compromised over 1,300 npm packages, leveraging legitimate GitHub workflows to spread.
Beacon CRM Breach Exposes UK Charities
A cyberattack on the CRM provider Beacon has resulted in the potential theft of sensitive database backups for numerous UK charities.
Physical Attacks Targeting Crypto Wealth
New data reveals a surge in violent physical thefts targeting cryptocurrency holders, with millions lost in the first half of 2026.