Close Menu
NCIJ Network NCIJ Network
    What's Hot

    American Bureau of Shipping subsidiary hit with $59.4M Cotemar claim in New York after two court losses

    August 26, 2026

    Palantir’s Showmanship Finds Willing U.K. Marks

    August 26, 2026

    Steve Buscemi was hospitalized after NYC attack, but it happened in 2024

    August 26, 2026
    Facebook X (Twitter) Instagram
    Trending
    • American Bureau of Shipping subsidiary hit with $59.4M Cotemar claim in New York after two court losses
    • Palantir’s Showmanship Finds Willing U.K. Marks
    • Steve Buscemi was hospitalized after NYC attack, but it happened in 2024
    • ‘In Ceuta, they are eating the cats’: Fake images and a persistent rumour
    • How Trump Folded the Graham Family Dynasty Into His Own
    • With Nige still sulking, it was left to Honest Bob to unveil Reform UK’s latest ‘policies’ | John Crace
    • Meta Will Pay Up to $16.7 Billion to Settle Its Social Media Harms Case—and That’s Not All
    • NovaCookies Campaigns Abuse Genuine Docusign Notifications to Steal Microsoft 365 Sessions
    • About
      • Our Team
      • Editorial Policy
      • Editorial Independence
      • International Support
    • Trust & Standards
      • AI Usage Policy
      • Conflict of Interest Policy
      • Corrections Policy
      • Ethics Policy
      • Fact-Checking Policy
      • Source Protection
    • Get Involved
      • Guide for Sources
      • Support Independent Journalism
    • Legal
      • Cookie Policy
      • Privacy Policy
      • Terms of Use
    Facebook X (Twitter) Instagram
    NCIJ Network NCIJ Network
    Wednesday, August 26
    • Home
    • World
    • Ai
    • Business
    • Politics
    • Health
    • Crypto
    • Science
    • Technology
    • Cybersecurity
    • Defense & Security
    • Economy
    • Energy
    • Europe
    • More
      • Fact Check
      • Investigations
      • Opinion & Analysis
      • Environment
    NCIJ Network NCIJ Network
    Home»Technology

    July was the worst month for ransomware victim claims in 2026 – or was it?

    NCIJ NETWNCIJ NETWORKBy NCIJ NETWNCIJ NETWORKAugust 26, 2026 Technology No Comments5 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Yuliya Taba / iStock / Getty Images Plus via Getty Images

    Follow ZDNET: Add us as a preferred source on Google.


    ZDNET’s key takeaways

    • Ransomware activity hit a year-to-date high of 894 victim organization listings in July.
    • The Gentleman, new ransomware groups, and agentic AI are responsible.
    • However, cybercriminal egos might be inflating the numbers.

    New NCC Group research says that July 2026 saw a spike in ransomware activity, with a year-to-date record of 894 victim listings recorded in the month alone. But what’s actually behind it? 

    Also: Why this fully agentic ransomware attack is giving researchers nightmares

    According to NCC Group’s July threat advisory report, published on Wednesday, global ransomware attacks increased by 22% in July 2026, compared to June 2026. This was also when the first incident of a fully agentic AI ransomware attack chain was also recorded. 

    Almost a third of attacks were launched against the industrial sector. Other popular targets were consumer services and technology, critical services, finance, and healthcare. In total, 41% of recorded incidents occurred in the US; 29% in Europe, 14% in Asia, and 9% in South America.

    Which ransomware groups were responsible?

    NCC Group data reveals that 10 cybercriminal groups were attributed to most of these ransomware attacks against businesses, ranked as follows:

    • The Gentlemen: 138
    • Quilin: 127
    • Deadlock: 84
    • DragonForce: 43
    • INC Ransom: 38
    • CRPxO: 36
    • SafePay: 33
    • Global Secret Group: 31
    • KryBit: 25
    • Akira: 22

    Also: What is ransomware? Everything you need to know and how to reduce your risk

    Significant attacks

    Numbers are one thing, but high rates don’t automatically mean severe attacks or even successful extortion. However, there were some notable incidents in July. 

    • Ernst & Young (EY): A data breach in July led to the exposure of client information and tax records. Ransomware group ShinyHunters claimed responsibility.
    • Coca-Cola’s Fairlife: Coca-Cola subsidiary Fairlife suffered a ransomware attack, thought to be the work of Anubis, which claimed to have stolen over 1TB of data.
    • Analog Devices: After the fact, ExfilSquad extortion group claimed to have stolen 570,000 records, but that claim has not been verified. 

    A note on the numbers

    The reputation of a cybercriminal group, especially one that has just emerged, is based not just on the ransomware it uses or the service it offers — known as Ransomware-as-a-Service (RaaS) — but also on how many victims it has claimed and which organizations they are. 

    Also: A low-tech solution from the past may be your best defense against AI deepfakes

    So, it’s possible that new groups will try to stroke their own egos and carve out a solid reputation without the evidence to back it up. In particular, we are talking about CRPxO, a new criminal entity that claimed to have hacked 36 organizations shortly after its emergence in July. 

    CRPxO operates a RaaS model and offers criminal affiliates a 70% share of ransomware payments, with a low $333 cost of entry, according to an AI-generated recruitment video. There’s evidence of a leak site — used to publicly pressure victims to pay up under the threat of having their information leaked online — a Telegram channel, and Tor-hosted infrastructure. However, 36 successful attacks, with alleged high-value victims including Johnson & Johnson and Turkish Airlines (there has been no confirmation of this), seem like a lot for a new entry.

    Without CRPxO releasing datasets, no victim confirmation, and an “inconsistent quality of evidence,” NCC Group assessed this group’s credibility as “low to moderate.” 

    Also: AI is finding bugs faster than humans can fix them: How enterprise security teams must adapt

    “Looking ahead, the group’s low barrier to entry and relatively generous affiliate revenue share may allow it to attract more affiliates and increase the number of claimed attacks in the near term,” NCC Group said in the report. “However, the long-term success of the ransomware group will likely depend on its ability to show credible victim compromises and maintain trust among potential affiliates.”

    CRPxO’s case is important because it reflects what we’ve previously found in ransomware rates and spikes: the numbers can’t always accurately reflect what is really going on. Data from earlier this year, released by NCC Group and Check Point, revealed that, quarter after quarter, a single threat actor, CiOP, was impacting ransomware rates. 

    July’s ransomware takeaways

    July 2026 saw a surge in ransomware activity, accounting for 894 organization victims, a 22% increase month-on-month. However, as shown in the case of CRPxO, leak sites and boasting are as much about street credibility as anything else, and so we should consider this spike with reservations.

    Also: Hackers are hunting for your private photos, FBI warns: 6 ways to avoid a sextortion nightmare

    Still, that’s not to say ransomware isn’t a serious and devastating problem for everyone, from individuals to enterprises. A successful attack can lead to data theft and exposure, destruction, reputational harm, and a serious blow to bank balances — and while they remain profitable, we should expect new ransomware groups to appear and for this illicit industry to continue. 

    We also have to keep a close eye on how AI-powered ransomware attacks continue to evolve. Revealed in early July, JadePuffer is believed to be the first documented case of a ransomware attack powered by AI from start to finish. With other ransomware operators experimenting with LLMs, by this time next year, cybersecurity firms could be splitting their ransomware rate figures between human and AI-controlled attacks. 

    claims July month ransomware Victim worst
    NCIJ NETWNCIJ NETWORK
    • Website

    Keep Reading

    Meta Will Pay Up to $16.7 Billion to Settle Its Social Media Harms Case—and That’s Not All

    Claims people are posing as ‘Home Affairs Officers’ to rob houses are a hoax – Full Fact

    Trump claims CIA director’s surprise visit to Russia is ‘semi-routine’ despite mounting speculation – live | Trump administration

    PeopleFinders’ New Website Runs Background Checks on Your Dates

    CISA: Over 100 Internet-Exposed Water Systems Targeted in July Cyberattacks

    QueryStory wants you to believe what AI is telling you

    Add A Comment
    Leave A Reply Cancel Reply

    Editors Picks

    American Bureau of Shipping subsidiary hit with $59.4M Cotemar claim in New York after two court losses

    August 26, 2026

    Palantir’s Showmanship Finds Willing U.K. Marks

    August 26, 2026

    Steve Buscemi was hospitalized after NYC attack, but it happened in 2024

    August 26, 2026

    ‘In Ceuta, they are eating the cats’: Fake images and a persistent rumour

    August 26, 2026
    Latest Posts

    Andy Burnham wants to fix social care. It’s personal for him and for a lot of us too | John Crace

    July 29, 2026

    France orders Russian journalist Xenia Fedorova to leave country over alleged Kremlin propaganda

    July 29, 2026

    Russia-Ukraine War: The Wildberries Theory of Moscow’s Defeat

    July 29, 2026

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    NCIJ Network is an independent digital news platform delivering trusted investigative journalism, European and global news, in-depth analysis, and fact-based reporting with accuracy, transparency, and integrity.

    Facebook X (Twitter) Instagram Pinterest YouTube

    American Bureau of Shipping subsidiary hit with $59.4M Cotemar claim in New York after two court losses

    August 26, 2026

    Palantir’s Showmanship Finds Willing U.K. Marks

    August 26, 2026

    Steve Buscemi was hospitalized after NYC attack, but it happened in 2024

    August 26, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.