August tops 2026 ransomware record, rising 12% month-on-month
- Total ransomware levels hit 2026 high with 1073 attacks in August, a 12% increase from 960 in July
- Qilin overtakes The Gentlemen as the most dominant threat group responsible for 15% of all attacks
- North America was the most targeted region again, with almost half (44%) of all attacks, followed by Europe with over a quarter (26%)
- Industrials is still most targeted sector with almost a third (31%) of ransomware attacks
Manchester, September 2026 – Monthly ransomware levels have reached a new high for 2026, with 1073 attacks recorded in August. This is up by 12% month-on-month from July which saw the highest monthly figures this year to date. The findings are according to NCC Group’s monthly Threat Intelligence Report for August 2026.
AI’s influence on cyber landscape continues to evolve
As ransomware levels have risen, concerns have grown about how rapidly evolving developments in AI are changing the nature of cyber threats and prevention methods against them.
The recent Hugging Face incident demonstrated the capability of OpenAI models escaping containment and conducting autonomous attacks. Meta and Anthropic are also demonstrating similar capabilities, prompting significant debate about global AI policy and how to regulate developments moving forward.
North America and Europe experience majority of attacks
In line with previous months, Western regions were the most targeted for ransomware attacks in August. North America experienced nearly half (44%) of all attacks and over a quarter (26%) happened in Europe.
Significant attacks in August had large knock-on effects on day-to-day operations. Manchester Airports Group suffered a customer data leak across its car park, lounge, fast track bookings and in-airport WiFi systems at Manchester, Stansted and East Midlands Airport. Boston Scientific, the US-based medical technology giant, also experienced an intrusion into multiple IT systems which led to global disruption of its manufacturing, shipping and customer order processing.
Industrials remains most targeted sector
The industrials sector experienced almost a third (31%) of all attacks in August, in line with consistently ranking as the most targeted. The proportion of attacks rose from 28% in July – a signal of the growing target on critical infrastructure organisations as threat actors look to cause mass disruption.
VPN exploitation by RaaS actor Aurora
Having first emerged in 2026, Aurora continues to establish itself in the threat landscape and has now targeted organisations across the manufacturing, legal, research and development sectors. The group has conducted successful attacks by exploiting VPNs, a technique already common.
Aurora was observed by NCC Group’s Digital Forensics and Incident Response team on a case that affected an organisation in the transportation sector in August. It left a short ransom note on the encrypted hypervisor stating they had encrypted confidential information files, and to contact them via the Tor browser using the provided .onion link, along with the organisation’s access key. These techniques are nothing new, but data extortion is now also a priority end goal, alongside encryption and, in some cases, destruction.
Matt Hull, Vice President of Cyber Intelligence and Response at NCC Group said: “August was the second consecutive month of highest ransomware levels for the year, indicating a steady rise in global activity. A combination of factors is driving this increase including rapid advancements in AI and ongoing geopolitical volatility which are fuelling state-sponsored threats. As the threat landscape evolves, organisations must ensure their resilience and response capabilities keep pace.
“AI is becoming a powerful tool for defenders and attackers. As these technologies continue to advance, the most effective approach to protecting against cyber threats will be combining AI’s speed and scale with human expertise and experience. Keeping people at the centre of cyber defence, whilst using technology responsibly, will be key for identifying and responding to cyber risk.”
Matt Hull biography
Matt Hull is Vice President of Cyber Intelligence and Response at NCC Group, leading the global Cyber Response and Intelligence (CRI) capability.
A former Detective Constable specialising in cybercrime, Matt brings deep operational experience across investigation, response, and intelligence-led operations. He leads multidisciplinary teams supporting organisations through complex incidents, advanced threat activity, and the development of mature detection and response capabilities.
Matt is recognised across the industry for his authenticity and clear communication, speaking at major conferences and featuring in media including BBC News, the Financial Times and Channel 4’s Hunted. He also serves as Chair of the Threat Intelligence Focus Group and sits on the CREST International Council.