Organizations hit by ransomware in August 2026: 1,073 (Source: NCC Group Cyber Threat Intelligence Report, published September 23, 2026)
A Record Month for Cyber Extortion
Ransomware attacks hit 1,073 organizations worldwide in August 2026, the highest monthly total recorded so far this year, according to NCC Group's Cyber Threat Intelligence Report, published September 23. That total is up 12% from the 973 organizations hit in July, making it the second straight month of record activity for 2026. NCC Group's VP of cyber intelligence and response, Matt Hull, described the trend as a 'steady rise in global activity.'
For budget-signers, the trend line matters more than any single incident. Two consecutive record months suggest attackers now have more capacity to run campaigns, not that one novel exploit is responsible. Hull pointed to two drivers behind that capacity: faster-moving AI tools available to attackers and ongoing geopolitical instability that he said is fueling state-sponsored activity. Neither driver points to a specific software flaw — both describe a broader increase in the volume and speed of attacks industry-wide.
Which Sectors and Regions Took the Hit
North America accounted for 44% of August's ransomware incidents, Europe for 26% and Asia for 13%, with South America, Africa and Oceania making up the remaining 10% between them, per NCC Group's regional breakdown. Industrial companies made up roughly 31% of August's reported incidents, the largest share of any sector for the month, with consumer goods and services next at 18%, followed by healthcare (12%), information technology (11%) and financial services (6%). NCC Group presents this as a snapshot of August's incident mix rather than a change from prior months.
The Extortion Playbook Is Shifting
NCC Group singled out two August incidents as illustrative: an attack on robotics firm Boston Dynamics and a data breach affecting Manchester Airport Group. The airport group case fits a broader move by some ransomware crews away from file encryption toward straight data theft and extortion — a separate development from the monthly volume increase, but one that matters operationally, since restoring from backup does nothing to stop a threat to publish stolen data.
Attribution data shows a small number of groups still drive most named incidents. Qilin was linked to 164 August attacks and The Gentlemen to 116; the two have traded the top spot for most active operator through 2026. Clop (89), Dire Wolf (43) and INC Ransom (43) followed.
What to Ask Your Team
NCC Group's own recommendation is unglamorous but specific: a written ransomware defense plan, tested through tabletop exercises rather than left as an untested document. Budget-signers can use the sector and tactic breakdown as a checklist — ask whether your organization's sector tracks against NCC Group's August concentration, whether your incident-response plan already covers a data-theft-only scenario like Manchester Airport Group's rather than assuming encryption is the only threat, and when your last tabletop exercise ran and what gaps it exposed.
Produced by the WebPulse Newsroom with AI assistance from the original reporting credited below, and checked against that source by our editorial review. How we use AI.
Original reporting: Infosecurity Magazine.





