Software

Ransomware Claims Hit a High in July 2026, But Was It Truly the Year’s Peak?

Ransomware Attacks Hit Annual High as Cybercriminal Groups Ramp Up Operations

Global cyber extortion reached a record peak in July 2026, with security researchers tracking 894 public victim listings—the highest monthly total recorded so far this year. Detailed in a recent threat report from NCC Group, the sharp 22% increase compared to June highlights an accelerating wave of extortion schemes driven by established syndicates, newly formed syndicates, and advancing attack techniques.

Key Target Sectors and Global Distribution

Cybercriminals continued to focus their efforts heavily on critical economic drivers. Nearly one-third of all recorded attacks in July targeted the industrial sector. Consumer services and technology providers were also heavily hit, alongside organizations in finance, healthcare, and critical infrastructure.

Geographically, North America remained the primary target:

  • United States: 41% of all recorded incidents
  • Europe: 29%
  • Asia: 14%
  • South America: 9%

Top Threat Actors Driving the Surge

A small collection of prominent extortion cartels accounted for a significant portion of the month’s activity. NCC Group’s tracking identified ten syndicates responsible for the highest volume of reported victim compromises:

  1. The Gentlemen – 138 victims
  2. Quilin – 127 victims
  3. Deadlock – 84 victims
  4. DragonForce – 43 victims
  5. INC Ransom – 38 victims
  6. CRPxO – 36 victims
  7. SafePay – 33 victims
  8. Global Secret Group – 31 victims
  9. KryBit – 25 victims
  10. Akira – 22 victims

Major Corporate Incidents Highlight Growing Risks

Beyond raw numbers, several high-profile attacks demonstrated the real-world impact of these operational surges during July:

  • Ernst & Young (EY): The professional services firm suffered a breach that exposed tax records and sensitive client information. The attack was publicly claimed by the extortion group ShinyHunters.
  • Fairlife: The Coca-Cola dairy subsidiary was hit by a breach linked to the Anubis ransomware group, which alleged it had exfiltrated more than 1 terabyte of corporate data.
  • Analog Devices: The extortion group ExfilSquad claimed to have compromised 570,000 files from the semiconductor company, though that claim has not been independently verified.

Exaggerated Claims and the Illusion of Explosive Growth

While the volume of listed victims broke records, security analysts caution that published numbers do not always equate to successful intrusions or paid ransoms. In the competitive Ransomware-as-a-Service (RaaS) market, emerging groups often attempt to build leverage and attract affiliates by exaggerating their success.

A prime example is CRPxO, a newcomer that surfaced in July and almost immediately listed 36 victimized organizations, including unconfirmed high-profile targets such as Turkish Airlines and Johnson & Johnson. Operating on a low-barrier affiliate model charging just $333 to join while promising a 70% share of proceeds, CRPxO heavily marketed its launch via synthetic media videos, dedicated Telegram channels, and Tor-hosted leak sites.

Due to a lack of published proof, missing data leaks, and inconsistent evidence, analysts at NCC Group assigned CRPxO’s claims a “low to moderate” credibility rating. Similar patterns have occurred in past quarters, such as when massive single-actor operations by groups like ClOP temporarily distorted overall industry metrics. While low entry fees may help groups like CRPxO recruit short-term affiliates, long-term operational survival ultimately depends on verifiable access and reliable extortion capabilities.

The Changing Landscape of Autonomous Cyber Threats

Despite skepticism around certain padded victim lists, the financial viability of extortion ensures that the threat landscape remains formidable. A particularly significant development in July was the documentation of JadePuffer, marked as the first known occurrence of an automated, fully agentic attack chain executed end-to-end without direct human intervention.

As threat groups increasingly experiment with autonomous execution frameworks, cybersecurity defenses are entering a new phase. Future tracking may soon need to distinguish between traditional human-managed operations and fully automated machine-driven compromises.

Related Articles

Leave a Reply

Your email address will not be published. Required fields are marked *

Back to top button