Ransomware went back up in July

· · Security

If you took the spring as a sign that ransomware was easing off, July undid it.

The UK research firm Comparitech counted 799 claimed attacks in July, up 19% on June's 668. That makes it the second-busiest month of 2026, just behind March, and the third busiest in 17 months. April, May, and June had all been comparatively quiet, and that lull is now over.

A word on what these figures are. They are attacks claimed by the criminal groups themselves, with only 51 confirmed by the victims. Attackers have every reason to exaggerate, and plenty of victims never say anything at all, which is a problem we have written about before. Treat the number as a direction of travel rather than a count.

Which way the sectors moved

The totals matter less than the movement underneath them, because the movement is where you might find yourself.

Finance rose 71% month on month, technology 62%, healthcare 46%, and education 44%. Going the other way, attacks on utilities fell 44%, legal firms 31%, and government agencies 11%.

The utilities drop is worth a note, because it runs against the headlines. Reporting on attacks against water systems has been prominent lately, but as The Register points out, those were not ransomware, and ransomware against utilities actually declined. Two different stories that are easy to merge into one.

Two groups now dominate. The Gentlemen claimed 135 victims in July and Qilin claimed 125, which between them is a third of everything recorded. Qilin is the group behind the 2024 attack on the pathology provider Synnovis that disrupted NHS services. The Gentlemen is newer and has already been linked to an attack on the UK consultancy Adaptavist Group. After those two, the numbers fall away sharply: DragonForce at 41, INC at 36, CRPx0 at 33, SafePay at 30.

What it changes for you

Honestly, not much, and that is rather the point.

Comparitech gave no data on how these groups get in. What is known about the two biggest suggests nothing exotic: Trend Micro has described The Gentlemen using stolen credentials, and Qilin told The Register it used unpatched vulnerabilities against Synnovis. Stolen logins and missing patches, in other words, which is where most of this has always started.

So the response to a 19% rise is not a new purchase. It is the same short list, done properly:

  • Backups you have actually restored from. Rebecca Moody of Comparitech makes the point that recent incidents have included data being wiped outright, not just encrypted or stolen, and that "backups of their backups" is what separates a bad week from an existential one. A backup nobody has tested is a hope, not a control.
  • A second step on every login, particularly anything reachable from the internet. Stolen credentials only work when the password is the whole test.
  • Patching that reaches the things nobody owns. The forgotten server, the appliance, the tool somebody installed once.

If your sector is on the rising list, this is a reasonable month to check those three rather than assume. If it is on the falling list, the same three still apply. Sector trends describe last month, and they are not a forecast about you.

Further reading

← All filings