Ransomware Attacks Hit Record High in August 2026, Industrial Sector Most Targeted
Global ransomware attacks surged to a record high in August 2026, with over 1000 organizations falling victim, primarily within the industrial sector.

Global ransomware attacks reached an unprecedented peak in August 2026, with analysis revealing that 1073 organizations fell victim to cyber extortion campaigns. This figure represents a significant 12% increase from July, underscoring the persistent and escalating threat posed by ransomware to businesses worldwide. The data, compiled by NCC Group's Cyber Threat Intelligence Report, highlights a concerning trend of rising attack volumes.
North America remained the most frequent target, accounting for 44% of all ransomware incidents in August. Europe followed with 26% of known attacks, while Asia experienced 13%. Other regions, including South America, Africa, and Oceania, saw smaller but still notable percentages of victims, indicating a global reach for these malicious operations.
The industrial sector bore the brunt of these attacks, representing nearly a third (31%) of all reported incidents. This focus on industrial targets suggests threat actors are increasingly seeking to disrupt critical infrastructure and supply chains for maximum impact and leverage. Other heavily affected sectors included consumer goods and services (18%), healthcare (12%), information technology (11%), and financial services (6%), demonstrating the broad applicability of ransomware across diverse industries.
Notable incidents highlighted in the report include attacks on Boston Dynamics and a data breach affecting Manchester Airport Group. The latter case serves as a stark reminder that some cyber-criminal groups are shifting their tactics from solely encrypting data to outright data theft and extortion, increasing pressure on victims to pay.
Among identified threat actors, the Qilin ransomware group was attributed to 164 incidents, while "The Gentlemen" group was linked to 116. These two actors have been particularly prolific throughout 2026, frequently vying for the top spot in terms of attack volume. Other significant ransomware groups active during August included Clop (89 attributions), Dire Wolf (43), and INC Ransom (43).
Matt Hull, VP of cyber intelligence and response at NCC Group, noted that August marked the second consecutive month of record-high ransomware levels for the year. He attributed this surge to a confluence of factors, including rapid advancements in AI, which can be leveraged to automate and enhance attack capabilities, and ongoing geopolitical volatility that fuels state-sponsored threats and creates opportunities for cybercriminals.
In response to the escalating threat, the report emphasizes the critical need for organizations to develop robust defense plans and response strategies. This includes having a clear playbook to minimize impact during an incident and regularly engaging in tabletop exercises to identify and close security gaps before they can be exploited by attackers. Proactive preparation and resilience are paramount in the face of evolving cyber threats.
The increasing sophistication and volume of ransomware attacks, coupled with the evolving tactics of threat actors and the potential influence of AI, necessitate a continuous reassessment of cybersecurity postures. Organizations must prioritize strengthening their defenses, improving incident response capabilities, and staying informed about emerging threats to mitigate the growing risk of cyber extortion.