Skip to content
Security & Trust

Ransomware Hit a Record 1,073 Organizations in August 2026

NCC Group links the 12% rise to AI and geopolitical volatility, per Hull; industrial firms led August's incident mix.

W
WebPulse Newsroom
AI-assisted · 4 min read
Share on X LinkedIn
Ransomware Hit a Record 1,073 Organizations in August 2026

Photo: Stéf -b. / Pexels

Key finding

Organizations hit by ransomware in August 2026: 1,073 (Source: NCC Group Cyber Threat Intelligence Report, published September 23, 2026)

A Record Month for Cyber Extortion

Ransomware attacks hit 1,073 organizations worldwide in August 2026, the highest monthly total recorded so far this year, according to NCC Group's Cyber Threat Intelligence Report, published September 23. That total is up 12% from the 973 organizations hit in July, making it the second straight month of record activity for 2026. NCC Group's VP of cyber intelligence and response, Matt Hull, described the trend as a 'steady rise in global activity.'

1,073
Organizations hit by ransomware in August 2026
Source: NCC Group Cyber Threat Intelligence Report, published September 23, 2026

For budget-signers, the trend line matters more than any single incident. Two consecutive record months suggest attackers now have more capacity to run campaigns, not that one novel exploit is responsible. Hull pointed to two drivers behind that capacity: faster-moving AI tools available to attackers and ongoing geopolitical instability that he said is fueling state-sponsored activity. Neither driver points to a specific software flaw — both describe a broader increase in the volume and speed of attacks industry-wide.

12%
Month-over-month increase from July's 973 incidents
Source: NCC Group Cyber Threat Intelligence Report, September 23, 2026

Which Sectors and Regions Took the Hit

North America accounted for 44% of August's ransomware incidents, Europe for 26% and Asia for 13%, with South America, Africa and Oceania making up the remaining 10% between them, per NCC Group's regional breakdown. Industrial companies made up roughly 31% of August's reported incidents, the largest share of any sector for the month, with consumer goods and services next at 18%, followed by healthcare (12%), information technology (11%) and financial services (6%). NCC Group presents this as a snapshot of August's incident mix rather than a change from prior months.

31%
Share of August incidents targeting the industrial sector
Source: NCC Group Cyber Threat Intelligence Report, September 23, 2026

The Extortion Playbook Is Shifting

NCC Group singled out two August incidents as illustrative: an attack on robotics firm Boston Dynamics and a data breach affecting Manchester Airport Group. The airport group case fits a broader move by some ransomware crews away from file encryption toward straight data theft and extortion — a separate development from the monthly volume increase, but one that matters operationally, since restoring from backup does nothing to stop a threat to publish stolen data.

Attribution data shows a small number of groups still drive most named incidents. Qilin was linked to 164 August attacks and The Gentlemen to 116; the two have traded the top spot for most active operator through 2026. Clop (89), Dire Wolf (43) and INC Ransom (43) followed.

164
August incidents attributed to Qilin, the most active named group
Source: NCC Group Cyber Threat Intelligence Report, September 23, 2026

What to Ask Your Team

NCC Group's own recommendation is unglamorous but specific: a written ransomware defense plan, tested through tabletop exercises rather than left as an untested document. Budget-signers can use the sector and tactic breakdown as a checklist — ask whether your organization's sector tracks against NCC Group's August concentration, whether your incident-response plan already covers a data-theft-only scenario like Manchester Airport Group's rather than assuming encryption is the only threat, and when your last tabletop exercise ran and what gaps it exposed.

Produced by the WebPulse Newsroom with AI assistance from the original reporting credited below, and checked against that source by our editorial review. How we use AI.
Original reporting: Infosecurity Magazine.

Share this insight