Ransomware attacks increased 3% (2,165 to 2,229) between Q1 and Q2 2026
- 665 global ransomware attacks recorded in June
- Industrials continue to be most targeted sector accounting for 30% of attacks in Q2 and 183 (28%) in June
- North America remains most targeted region in Q2 with 980 attacks (44%) and 275 (41%) in June, followed by Europe which had (26%) all of attacks in the quarter (579) and 23% (153) in June
- Qilin was most active threat group, responsible for 14% of attacks in Q2 and 12% (79) in June
Manchester, July 2026 - Global ransomware activity rose by 3% in Q2 2026 compared with the previous quarter, according to NCC Group’s latest Quarterly Cyber Threat Intelligence Report. The report’s analysis also shows that supply chain attacks continue to increase in scale and sophistication, reinforcing the need for stronger organisational resilience.
Supply chains remain vulnerable
In the last quarter, global threat groups have continued to target trusted software development ecosystems.
Rather than attacking organisations directly, threat actors are increasingly compromising trusted software and development tools that thousands of businesses rely on. This allows a single attack to cascade across multiple organisations, making supply chain attacks one of the most effective methods of large-scale compromise.
TeamPCP has emerged as one of the most prominent groups associated with this activity, with campaigns demonstrating how compromised software dependencies and development workflows can enable downstream compromise before attacks are detected.
Most targeted regions and sectors stay consistent
Industrials remained the most targeted sector, accounting for almost a third (30 %) of all ransomware attacks globally in Q2, followed by Consumer Discretionary and Information Technology (23%). These three sectors were also the most targeted in June, with Industrials ranking top with 183 (28%) attacks, followed by Consumer Discretionary with 166 (25%) and Information Technology at 63 (9%).
In Q2, North America was the most targeted region, accounting for almost half of all global attacks (44%). The region again was also the most targeted in June with 275 (41%) attacks, followed by 153 (23%) in Europe and 133 (20%) in Asia.
Same threat groups continue to dominate at the top
Qilin remained the most active threat group for the fifth consecutive quarter, responsible for 14% (301) of all attacks. The Gentlemen group followed, with 238 victims, and DragonForce ranked third with 145. In the last three months, KryBit emerged as a new entrant to the top 10 most active ransomware groups.
VPNs under spotlight
In Q2, corporate VPNs and internet-facing edge devices continued to be prioritised by attackers. This ranged from opportunistic hackers to ransomware-as-a-service operators and nation-state sponsored APT groups exploiting software vulnerabilities to gain unauthorised entry and deepen network compromise.
Vulnerabilities affecting specific VPNs or their manufacturers accounted for some of the most common threat intelligence alerts issued by NCC Group in the first half of 2026 with many of them rated either high or critical severity.
Matt Hull, VP and Head of Cyber Intelligence and Response at NCC Group, said: “Supply chain attacks continue to be one of the most attractive routes for threat actors to cause significant operational, financial and reputational damage to organisations. We have seen these attacks continue to rise in scale and sophistication, and businesses should therefore ensure monitoring and resilience is continuous, rather than ad hoc.
“Although there has not been a material rise in ransomware volume in the last quarter, the trajectory of attacks continues upwards, and VPNs remain an increasingly attractive target. Alongside ongoing geopolitical tensions, rapidly evolving AI capabilities and increasingly sophisticated attack methods, organisations must remain resilient and proactive in their approach to cyber security, treating it as the board-level issue it is.”
Incident figures may change slightly over time as cyber attacks are often disclosed after they occur. The statistics presented represent the best available estimate at the time of publication and may be updated as further information becomes publicly available.