Ransomware’s quiet comeback: July attacks jumped 19% as AI grabbed the headlines

For all the industry’s attention on AI agents breaking out of test environments, the old-fashioned business of digital extortion quietly had one of its best months of the year. Ransomware attacks jumped nearly 19 percent in July, with the UK research firm Comparitech counting 799 publicly claimed incidents against 668 in June, roughly 26 attacks a day. Only March, with 805, was busier this year, and the 51 attacks confirmed by the victims themselves understate a tally built mostly on the claims of criminal crews. The surge ends a relatively quiet stretch: after a heavy start to 2026, April, May, and June had all slowed, and July’s rebound is the clearest signal yet that the lull was a pause, not a trend.

The most instructive part of the data is who got hit. The sectors that dominate the security headlines (utilities, with the string of suspected Iran-linked attacks on US water systems) were not the ones under ransomware pressure. Attacks on utility companies actually fell 44 percent in July, and those water-system incidents were not ransomware at all. The real growth was in industries that pay: finance companies saw attacks rise 71 percent, tech firms 62 percent, pharmaceutical manufacturers and medical billers 46 percent, and education 44 percent. That pattern tracks the economics of extortion. Pentesting firm DeepStrike’s study of who actually pays finds the most frequent payers are manufacturers, schools and hospitals, and financial institutions. Even the least compliant sector, finance, still forked over a ransom 51 percent of the time. Attackers, in other words, are following the money.

The geography tells a similar story of concentration and new markets. The United States absorbed 322 of the month’s 799 attacks, roughly 40 percent of the global total, up 31 percent from June. Germany, the second most-targeted country, saw just 40. The sharpest increases were in emerging target pools: Argentina’s count jumped 320 percent from five to 21 incidents, while India rose 76 percent, the UK 67 percent, and Australia 56 percent. Among the most active crews, a familiar name is being overtaken by a newcomer. Qilin, responsible for the 2024 Synnovis breach that threw UK pathology services into disarray, took credit for 125 attacks in July. The Gentlemen, a newer operation that has scaled quickly and earlier claimed the intrusion at UK consultancy Adaptavist Group, topped the month with 135. Together the two outfits account for nearly a third of all attacks logged. Their ingress methods are equally familiar: Trend Micro attributes The Gentlemen’s success largely to stolen credentials, while Qilin has told The Register it abused zero-day vulnerabilities to breach Synnovis.

The victims’ stories put numbers in context. AnMed, a US hospital network, had systems locked on July 26 with screens demanding payment within 72 hours. Fairlife, the Coca-Cola-owned dairy company, was crippled on July 16 and took roughly ten days to restore most production, with the Anubis gang claiming it and the theft of a terabyte of data. Swiss rail manufacturer Stadler endured its second ransomware attack ever, declining to meet a demand of ten million Swiss francs. Behind each headline is the same lesson the researchers keep repeating: multi-factor authentication, disciplined patching, and reliable backups remain the defenses that matter, because the attackers’ methods have barely changed even as their targets have.

Instead of chasing clicks, we focus on delivering reliable information. Your support helps us stay on that path.

Back evidence-based news

The AI-distraction framing of the month is partly fair and partly misleading. Yes, security teams and vendors are pouring attention into agentic threats, and the first end-to-end agentic ransomware attacks are now being documented. But the July numbers show that the legacy crime wave needs no new technology, just credential theft, unpatched systems, and victims who pay. The crews are not watching the AI spectacle; they are working through their queues. The quieter risk is that defenders, transfixed by the novel threat, let the old one compound.

Sources: Ransomware attacks spike as world distracted by AI (The Register, Aug 7, 2026); Ransomware roundup: July 2026 (Comparitech, Aug 5, 2026); Ransomware Surges in July After Q2 Lull (Infosecurity Magazine, Aug 2026); Ransomware Payout Statistics (DeepStrike, 2025); Unmasking The Gentlemen ransomware (Trend Micro, 2025)

Scroll to Top