Aug 7, 2026
Policy

Ransomware attacks in July 2026 rose in Comparitech’s incident tally

Comparitech counted 799 ransomware incidents in July, but just 51 were victim-confirmed and the data does not tie the rise to AI.

Renata Fuchs

By Renata Fuchs · Policy Reporter

· 3 min read

Ransomware attacks in July 2026 rose in Comparitech’s incident tally
Photo: The Register

Ransomware attacks in July 2026 rose to 799 in Comparitech’s tally, from 668 in June, an increase of about 19.6%. The count puts July narrowly behind March, when the UK research firm recorded 805 incidents, but it is not a verified global total: only 51 of July’s entries had been confirmed by victims, according to reporting on the data.

That limitation is material for operators assessing exposure. Ransomware statistics can combine confirmed disclosures, claims by criminal groups and other public signals. They indicate reported activity, but they do not establish the full number of successful intrusions or prove each listed victim was hit.

The reported rise also does not show that attention on AI, or AI use by attackers, caused the July increase. Separate first-quarter research from cyber insurer Travelers says criminal groups are using AI to support social-engineering and business-email-compromise campaigns, but neither dataset links that use to Comparitech’s July result.

Which sectors saw more ransomware attacks in July 2026?

Finance had the largest reported month-over-month increase, up 71%, followed by technology at 62%. Pharmaceutical companies and medical billers rose 46%, while education increased 44%, Comparitech’s data showed.

Several sectors moved in the other direction. Reported attacks on utilities fell 44%, legal firms dropped 31%, and government agencies declined 11%. Cyberattacks recently affecting US water infrastructure were not ransomware incidents, according to the report.

The United States accounted for 322 of the 799 July incidents in Comparitech’s count. Germany, the second-most-targeted country in that tally, had 40.

What do the ransomware figures say about the groups behind them?

Two groups accounted for a sizable share of the month’s publicly claimed activity. The Gentlemen claimed 135 victims in July and Qilin claimed 125, a combined 260, or roughly one-third of Comparitech’s 799-incident tally. Those are group claims, not independently verified victim totals.

Comparitech did not identify the initial-access routes for the incidents it counted. That leaves no basis to assign the July increase to stolen credentials, unpatched software, phishing or any other single method. For companies, the practical response remains broader than a single control: enterprise security is a program involving access controls, monitoring, staff processes and recovery planning.

Travelers’ first-quarter 2026 report supplies a wider, though differently measured, signal. It found 84 criminal groups had posted more than 2,400 victim companies on ransomware leak sites, its highest quarterly level since it began the study in 2020. Leak-site postings, like gang claims, should not be treated as confirmed incidents without qualification. The insurer said 20 groups became inactive during the quarter while 19 new groups appeared, suggesting churn alongside sustained activity.

For security leaders, July’s count is a reason to check basic resilience rather than evidence that ransomware has become an AI-only problem. The data supports elevated reported activity in selected sectors; it does not establish the cause of the one-month jump.

This story draws on original reporting from The Register.

More from Policy

All Policy →