Ransomware Attacks Rebound in July After Slow Q2

▼ Summary
– July 2026 saw 799 claimed ransomware attacks, a 19% increase from June and the second highest month of the year, with finance, tech, and healthcare hit hardest.
– Finance attacks rose 71% month-over-month, followed by technology (62%), healthcare (46%), and education (44%), while US-targeted attacks increased 31%.
– Major incidents included an attack on US healthcare provider AnMad, forcing facility closures, and one on Romania’s land registry agency that wiped its entire database, disrupting the real estate market.
– The Gentlemen and Qilin ransomware groups accounted for 33% of all July attacks, with 135 and 125 claims respectively, continuing their rivalry for dominance.
– Other active groups included DragonForce (41 attacks), INC (36), CRPx0 (33), and SafePay (30), with Comparitech urging regular backups to mitigate impacts.
Ransomware activity rebounded sharply in July 2026, with a 19% month-over-month surge that marked the second-highest total of the year, according to fresh data from Comparitech. The consumer research firm logged 799 claimed attacks during the month, a figure that also ranks as the third-largest monthly total in the past 17 months.
The rebound follows a comparatively quiet stretch from April through June, when attack volumes had tapered off. Finance emerged as the hardest-hit sector, experiencing a 71% jump in incidents compared to June. Technology followed with a 62% increase, while healthcare and education saw respective rises of 46% and 44%. Attacks against US-based organizations also climbed 31% month-over-month.
Comparitech’s July report highlighted several major confirmed incidents due to their severity. A cyberattack on US healthcare provider AnMad forced the closure of multiple facilities. Meanwhile, an intrusion at Romania’s land registry agency resulted in the complete deletion of its database, causing widespread disruption across the country’s real estate sector.
Rebecca Moody, head of data research at Comparitech, stressed the varied tactics employed by criminal groups. “These attacks highlight how ransomware groups hit organizations in various different ways, taking down key systems, stealing troves of data, and even deleting massive datasets,” she said. “Never has it been more important for organisations to ensure they’re carrying out regular backups (and backups of their backups!) so they can reset systems and restore data as quickly as possible if the worst does happen.”
The analysis, published on August 5, revealed that The Gentlemen and Qilin continue to dominate the threat landscape. Together, the two groups accounted for 33% of all July attacks, with The Gentlemen claiming 135 incidents and Qilin 125. This marks an ongoing rivalry for supremacy between the two ransomware strains.
Earlier analysis from ReliaQuest indicated that The Gentlemen had already overtaken Qilin as the most prolific cyber extortion actor between March and May 2026. In July, the gap widened further. The next most active groups trailed significantly: DragonForce accounted for 41 attacks, followed by INC (36), CRPx0 (33), and SafePay (30).
(Source: Infosecurity Magazine)