Skip to content
Security & Trust

Ransomware hit a record 2,627 claimed attacks; 247 are confirmed so far

Comparitech's Q3 2026 count is mostly gang claims, so the public record is often the gang's version of events.

W
WebPulse Newsroom
AI-assisted · 4 min read
Share on X LinkedIn
Ransomware hit a record 2,627 claimed attacks; 247 are confirmed so far
In brief
  • Comparitech counted 2,627 ransomware attacks claimed in Q3 2026, a record. Victims had confirmed 247 of them so far, and that count can change.
  • Most of that count rests on gang claims alone, so the public record is often the gang's version. A claim can reach the public before an organization has settled its response.
  • Leaders should monitor leak sites for their own name and their suppliers', and decide in advance who confirms or denies a claim.

The loudest number in this quarter's ransomware data is also the least certain. Comparitech logged 2,627 ransomware attacks in Q3 2026, the highest quarterly total it has recorded. Victims had confirmed 247 of them at the time of the report. The other 2,380 rest, for now, on the gangs' own claims.

The 247 is a count to date, not a final figure. Comparitech notes that most breach reports arrive months after an attack, so confirmations can keep arriving after a quarter closes.

That gap is the story. For most of this record, the public version of events is the gang's version. Comparitech says a claim may stay unconfirmed because the gang is lying, or because the victim chose not to disclose. The count alone cannot tell leaders which. Treating this only as a question of attack volume misses that it is also a question of whose account the public reads.

2,627
Ransomware attacks logged in Q3 2026
Source: Comparitech, Ransomware roundup Q3 2026 (October 7, 2026)

What the record shows

Comparitech reports a 29 percent rise on Q2 2026, when it logged 2,030 attacks. Against Q3 2025, with 1,636 attacks, the rise is 61 percent. That works out to nearly 29 attacks a day.

The increase was broad. Education rose 50 percent from Q2, healthcare 39 percent, government 36 percent and businesses 27 percent. Within business, finance rose 72 percent, from 116 attacks to 199. Technology rose 70 percent, from 154 to 262. Manufacturers had the highest count of any business group, at 478.

Rebecca Moody, Comparitech's head of data research, told Infosecurity Magazine that this quarter differs from past ones. Figures usually swing up in one sector and down in another. This time, she said, the increases are significant across all key sectors.

How the number is built

Ransomware groups run public websites, often called leak sites. They post claims there and publish or auction stolen data when a victim does not pay. Comparitech counts those claims.

It calls an attack confirmed when the victim says ransomware was involved. It also uses that label when the victim acknowledges a cyber attack that matches a gang's claim. Otherwise the attack stays unconfirmed. Of the 2,627 attacks, 247 were confirmed and 2,380 were not, as of the report.

247
Attacks confirmed by the victim so far
Source: Comparitech, Ransomware roundup Q3 2026 (October 7, 2026)

Comparitech also warns that figures shift. Gang claims often arrive a month or more after the attack, so an incident can later move to a different quarter. When an attack is confirmed, it leaves the unconfirmed list.

Disclosure rules add another gap. US organizations must tell state officials about certain breaches, but not every country has such a law. The same incident can therefore be visible in one country and hidden in another.

Paying does not close the account

Comparitech reports a median ransom demand of $150,000 and an average of $602,400. The gap between the two means a few very large demands pull the average up. Most groups do not disclose demands, so the data is limited.

$150,000
Median ransom demand, Q3 2026 (average: $602,400)
Source: Comparitech, Ransomware roundup Q3 2026 (October 7, 2026)

The largest known demand was $12.3 million. Everest made it in July against Swiss rail manufacturer Stadler, after accessing a platform the company shared with a supplier. Stadler refused to pay, and Everest leaked 201 GB of data. The route in ran through a shared system, not only Stadler's own.

Moody pointed to a case that shows why paying settles little. The Gentlemen attacked South African tech company MIP Holdings in June 2026. MIP paid to have the stolen data deleted. In recent weeks, the group began listing MIP's clients on its leak site to extract ransom from them too. Moody said the tactic shows that paying does not ensure the attacker keeps its word. Comparitech's report notes a rise in this kind of triple extortion, which adds pressure on the individuals affected.

The consequences land on people, not only balance sheets. Saber Healthcare Group is notifying more than 427,000 people whose medical, Social Security and financial data was affected. Comparitech counted over 1.6 million people confirmed affected across 28 companies that disclosed numbers.

A possible driver, with limits

Infosecurity Magazine says a possible explanation is AI, which may let attackers run campaigns faster and at larger scale. It points to the JadePuffer campaign, identified in July and believed to be the first ransomware attack fully driven by AI. Comparitech's own figures do not test that link. Treat it as a hypothesis, not a finding.

What leaders should ask

The lesson here is that a leak site is part of how an incident becomes public. A gang's claim can reach the public before an organization has settled its response. Leaders can prepare for that with a few concrete questions.

First, who watches leak sites for our company name and for our key suppliers? Stadler's case shows a shared platform can be the way in. Second, who decides whether to confirm or deny a claim, and how fast? The Philippine hospital General Santos Doctors Hospital shows the risk. After Rhysida listed it in September, its first public line was that it had found no sign of a breach. It later retracted that statement and confirmed the attack. Third, if we pay, what is the plan for the data and for our clients, given the MIP case? Fourth, can we notify affected people quickly, since breach notices often arrive months after an attack?

A record quarter measures what criminals say they did. Your preparation decides how well you can answer them.

Produced by the WebPulse Newsroom with AI assistance from the original reporting credited below, and checked against that source by our editorial review. How we use AI.
Original reporting: Comparitech.

Share this insight