LIVE
LATEST THREAT: China-Nexus Actor Exploits Critical VMware vCenter Flaw to Deploy Babuk-Derived Ransomware THREAT ALERT ACTIVE
Intelligence DB / Intel Report

Ransomware July 2026: 799 Attacks, Finance Up 71%, 146 Active Groups

July 2026 recorded 799 confirmed ransomware attacks — a 19% increase on June and the second-highest monthly total of the year. The Gentlemen led with 135 attacks, Qilin with 125. Finance, technology, and healthcare all saw significant month-on-month surges.

By Ransomware Tracker ·
ransomwaremonthly-reportJuly-2026statisticsThe GentlemenQilinDragonForceINCSafePayCRPx0financehealthcaretechnology
Threat Level
6/10
Sectors Targeted
finance
healthcare
technology
education
manufacturing

July 2026 recorded 799 confirmed ransomware attacks, according to Comparitech’s monthly roundup. That is a 19% increase from 668 in June, equivalent to nearly 26 attacks per day. The figure is the second-highest monthly total of 2026, behind only March’s 805.

Volume and Trend

The month’s volume continues a year that has shown no sign of the ransomware activity decline some analysts predicted following law enforcement disruptions to LockBit and ALPHV in 2024. Those disruptions reshaped the ecosystem — they did not reduce it. Ransomware in 2026 is characterised by a larger number of active groups operating at varying sophistication levels, with the top-tier operations (The Gentlemen, Qilin, DragonForce) maintaining volume while a long tail of smaller groups accounts for significant additional activity.

As of June 2026, 146 distinct ransomware groups were actively operating. Between April 2025 and March 2026, 61 new groups entered the market — more than one per week. The barriers to entry for ransomware-as-a-service affiliates have continued to fall, with pre-built infrastructure, tooling, and negotiation services available for established groups’ affiliate programmes.

Most Active Groups in July

The Gentlemen — 135 attacks (17% of total)

The Gentlemen maintained its position as the most prolific ransomware operation in July. Launched in mid-2025 from a Qilin affiliate dispute, the group’s 90% affiliate revenue share and selective crew model has produced consistent volume. July’s 135 claimed attacks bring the group’s 2026 total above 600. Their targeting profile spans government, healthcare, manufacturing, and education, with no sector-specific focus that would limit their attack surface.

Qilin — 125 attacks (16% of total)

Qilin’s July total continues the group’s strong 2026 run. Together, The Gentlemen and Qilin accounted for 33% of all July ransomware activity — a significant concentration in two groups that originally shared infrastructure lineage before The Gentlemen split.

DragonForce — 41 attacks

DragonForce’s July figure reflects the group’s continued operation following its 2026 pivot to a cartel model, providing infrastructure to other ransomware operations as well as running its own. Their C2 technique using Microsoft Teams TURN relay (Backdoor.Turn) continued to feature in technically sophisticated intrusions.

INC — 36 attacks

INC Ransom maintained consistent activity despite earlier reports of a Rust rewrite of their encryptor. The group targets mid-market organisations across sectors and has shown continued use of Veeam credential dumping for backup destruction prior to encryption.

CRPx0 — 33 attacks

CRPx0 is a relatively new entrant that has grown steadily through 2026. The group operates a leak site with a 72-hour payment deadline before publishing victim data. Their targeting skews toward North American small and mid-market businesses.

SafePay — 30 attacks

SafePay continues to operate as a consistent mid-tier group. The group previously targeted Veeam backup infrastructure and has demonstrated capability with VMware ESXi hypervisor encryption.

Sector Breakdown

Finance — 71% month-on-month increase

The largest sector surge in July. Financial services firms saw 71% more attacks than in June. This likely reflects a combination of opportunistic volume attacks against the sector and deliberate targeting — financial services organisations hold high-value data and have demonstrated willingness to pay to avoid regulatory disclosure implications.

Technology — 62% increase

Technology companies, including software vendors and IT services firms, saw a 62% increase. Technology sector targeting carries secondary risk: technology vendors with access to client environments represent potential supply-chain pivot points, mirroring the MSP targeting pattern.

Healthcare — 46% increase

Healthcare’s 46% increase continues a pattern of sustained targeting. Ransomware operators have demonstrably understood that healthcare organisations face pressure to restore operations quickly — backup destruction followed by encryption creates disproportionate operational harm in clinical environments.

Education — 44% increase

Education institutions typically have less mature security postures and complex user populations, making credential theft through phishing and infostealer malware straightforward. July’s increase partially reflects summer activity when institutions may have reduced security staffing.

Declines: Utility companies (-44%), legal firms (-34%), and government agencies (-11%) saw reduced volume in July. Government and legal declines may reflect seasonal patterns; utility sector reduction may reflect improved resilience posture following critical infrastructure-focused campaigns earlier in the year.

Geographic Distribution

The United States remained the most targeted country with 322 attacks (40% of global total). Germany followed with 40, Canada with 36, India with 30, the UK with 25, and France with 23. The US figure reflects both the concentration of potential targets and ransomware groups’ demonstrated preference for higher-paying markets.

Context: The Register’s Assessment

The Register’s August 7 analysis, headlined “Ransomware attacks spike as world distracted by AI,” noted that security budget conversations dominated by AI capabilities and AI security tools are consuming attention that might otherwise have gone to fundamental ransomware resilience measures: backup integrity, credential hygiene, network segmentation, and patching cadence. The framing is editorial rather than empirical, but it reflects a real tension in security investment allocation that security leaders are navigating.

Sources

// Related Intelligence
Intel Report

'Ransom Busters': A Rogue Affiliate Is Re-Extorting Its Own Gangs' Victims

Intel Report

Qilin's 443% Surge: Inside the RaaS Operation Now Leading the 2026 Ransomware Market

Intel Report

Ransomware Targeting Financial Services: 2026 Sector Intelligence Report