Ransomware Attacks Surge to Record High in Q3 2026
Ransomware attacks reached an unprecedented quarterly volume in Q3 2026, with a 27% increase over the previous quarter and a 61% rise year-over-year, impacting critical sectors globally.

Ransomware attacks hit an all-time quarterly high in the third quarter of 2026, with threat intelligence firm Comparitech documenting a total of 2,627 claimed attacks between July and September. This figure represents a substantial 27% increase from the second quarter of 2026 and a significant 61% jump compared to the same period in 2025, underscoring the escalating and persistent threat posed by ransomware.
The finance and technology sectors bore the brunt of this surge, experiencing the most dramatic growth in ransomware incidents. Finance saw a 72% increase in attacks, closely followed by technology with a 70% rise. Other vital sectors also faced a significant uptick, including education (up 50%), healthcare (up 39%), government (up 36%), and utilities (up 32%), highlighting the widespread impact across essential industries.
Comparitech's analysis revealed that out of the 2,627 attacks claimed, 247 have been confirmed by the involved entities. Rebecca Moody, head of data research at Comparitech, expressed significant concern over these figures, noting that the increases are not marginal but substantial across all key sectors. This trend deviates from the typical fluctuations seen in the ransomware landscape, suggesting a more profound shift in attacker capabilities or motivations.
One potential driver for this record-breaking quarter is the rapid advancement and adoption of Artificial Intelligence (AI) technologies. AI is enabling ransomware attackers to scale their campaigns more rapidly, increase their effectiveness, and potentially automate aspects of the attack lifecycle. The emergence of campaigns like JadePuffer, identified earlier in the year as potentially the world's first AI-driven ransomware attack, signals a new era of automated cyber threats.
Furthermore, the report highlighted a disturbing trend in the adoption of triple extortion tactics by ransomware groups. Beyond encrypting data and exfiltrating sensitive information, attackers are increasingly targeting individuals impacted by the breach. This tactic, exemplified by The Gentlemen's attack on MIP Holdings, involves threatening to release client data to pressure the primary victim into paying, demonstrating that ransom payments offer no guarantee of data deletion or security.
The financial demands associated with these attacks also remain substantial. The average ransomware demand in Q3 2026 stood at $602,400. The most significant known demand was $12.3 million issued to Swiss railway firm Stadler Rail by the Everest group, which proceeded to leak 201 GB of data after the company refused to pay. Similarly, Rhysida demanded $2.3 million from the State of Berlin, subsequently leaking 5.7 TB of stolen citizen data after the state refused to comply.
In terms of group activity, Qilin and The Gentlemen emerged as the most prolific ransomware operations, claiming 357 and 342 attacks respectively, marking increases of 24% and 29% in their activity compared to Q2. Clop saw a staggering 4700% increase in claimed attacks, rising from one in Q2 to 48 in Q3, while Direwolf experienced a 1450% surge. Geographically, the United States remained the most targeted country, accounting for 1,066 attacks (41% of the total), a 34% increase from the previous quarter. Germany followed with 121 attacks, and Argentina and India saw the largest percentage increases, up by 150% and 116% respectively.
The escalating volume and sophistication of ransomware attacks, coupled with evolving extortion tactics and the potential influence of AI, paint a grim picture for the cybersecurity landscape. The record-breaking Q3 2026 figures serve as a stark warning to organizations across all sectors, emphasizing the critical need for robust defenses, proactive threat intelligence, and comprehensive incident response strategies.