Ransomware Attacks Surge 19% in July, Targeting Finance and Tech Sectors
Ransomware attacks saw a significant 19% increase in July, with finance, technology, and healthcare industries bearing the brunt of the surge.

Ransomware attacks experienced a notable resurgence in July 2026, marking a 19% increase compared to the previous month, according to new analysis by Comparitech. This surge follows a relative lull observed in the second quarter of the year, indicating a renewed and intensified focus on specific sectors by threat actors.
Comparitech's analysis documented a total of 799 claimed ransomware attacks in July, positioning it as the second-highest month for such incidents in 2026. This figure also represents the third-highest monthly total over the past 17 months, underscoring the persistent and growing threat of ransomware.
The finance sector was particularly hard-hit, experiencing a 71% month-over-month increase in attacks. The technology sector followed closely with a 62% rise, while healthcare and education also saw significant increases of 46% and 44%, respectively. This concentrated targeting suggests that these industries hold particularly valuable data or offer critical infrastructure that ransomware groups aim to disrupt.
Beyond specific sectors, the United States also observed a substantial uptick in ransomware attacks, with a 31% increase in July compared to June. This broad geographical and sectoral impact highlights the widespread nature of the current ransomware threat landscape.
Several high-profile incidents underscored the severity of the July surge. The analysis highlighted an attack on US healthcare provider AnMad, which led to the temporary closure of its facilities. Additionally, the Romanian government's land registry agency fell victim to an incident that resulted in the complete wiping of its database, causing significant disruption to the country's real estate market.
Rebecca Moody, head of data research at Comparitech, emphasized the diverse tactics employed by ransomware groups, including system takedowns, data theft, and data deletion. She stressed the critical importance of robust backup strategies, including "backups of their backups," to enable rapid recovery in the event of a successful attack.
The report also identified the dominant ransomware strains in July, with 'The Gentlemen' and 'Qilin' groups collectively accounting for 33% of all attacks. 'The Gentlemen' claimed 135 attacks, while Qilin was responsible for 125. This continued dominance suggests an ongoing competition for supremacy between these two prominent ransomware operations.
While 'The Gentlemen' and Qilin led the pack, other active groups included DragonForce with 41 attacks, INC with 36, CRPx0 with 33, and SafePay with 30. The sustained high volume of attacks from these groups underscores the need for continuous vigilance and proactive defense measures across all targeted industries.