Skip to content
Cyble Threat Report: August 2026 Hits Record High with 1,034 Global Ransomware Victims

Cyble Threat Report: August 2026 Hits Record High with 1,034 Global Ransomware Victims

Cxotoday • September 28, 2026

With an average of 33 victims a day, more than one every hour, August records the highest ransomware count of 2026

August recorded as the most active month for ransomware so far in 2026, with 1,034 organisations publicly named as victims worldwide by 88 ransomware gangs, according to The Ransomware Brief released by Cyble Research and Intelligence Labs (CRIL), the research arm of global AI-native cybersecurity company Cyble. India was the most targeted country in Asia-Pacific with 24 claimed victims, ranking seventh worldwide and ahead of every other country in the region.

The surge reverses a three-month decline from March to June, with volume rising 60% in July before climbing a further 25% in August. CRIL reads this as a new baseline rather than a seasonal spike: security planning built on first-half 2026 volumes now runs 41% below actual activity.

India – 24 victims, one in six of all claims in Asia-Pacific and 50% more than the most targeted countries, Taiwan and Thailand (16 each)

India – 24 victims, one in six of all claims in Asia-Pacific and 50% more than the most targeted countries, Taiwan and Thailand (16 each)

Sectors hit – Manufacturing (151), Professional Services (147), IT and ITES (126) and Healthcare (98) were the most targeted: industries where downtime is intolerable or where client data raises the pressure to pay. India’s IT services and manufacturing base sits in both categories

Sectors hit – Manufacturing (151), Professional Services (147), IT and ITES (126) and Healthcare (98) were the most targeted: industries where downtime is intolerable or where client data raises the pressure to pay. India’s IT services and manufacturing base sits in both categories

Asia-Pacific – 143 victims, 13% of the global total, third behind the Americas (603) and Europe (270). India, Thailand, Taiwan and Japan (11) accounted for 68 victims, nearly half the region. Australia and New Zealand, tracked separately, recorded 22

Asia-Pacific – 143 victims, 13% of the global total, third behind the Americas (603) and Europe (270). India, Thailand, Taiwan and Japan (11) accounted for 68 victims, nearly half the region. Australia and New Zealand, tracked separately, recorded 22

United States – 484 victims, 48% of the global total and nearly as many as every other country combined; almost ten times Italy (50), the second most targeted country

United States – 484 victims, 48% of the global total and nearly as many as every other country combined; almost ten times Italy (50), the second most targeted country

A different leader – Asia-Pacific was the only region where Qilin, the world’s most active gang, did not lead. The Gentlemen claimed 20 victims in the region against Qilin’s 16

A different leader – Asia-Pacific was the only region where Qilin, the world’s most active gang, did not lead. The Gentlemen claimed 20 victims in the region against Qilin’s 16

Regional ransomware gangs – Krybit (13) and orova (12) together claimed more Asia-Pacific victims than Qilin, yet neither ranks in the global top five

Regional ransomware gangs – Krybit (13) and orova (12) together claimed more Asia-Pacific victims than Qilin, yet neither ranks in the global top five

Ninety-six gangs posted claims in August, with the top five accounting for 38% of activity. Qilin (145) and The Gentlemen (110) together claimed a quarter of all victims. CRIL attributes the surge to affiliate recruitment and exploitation of internet-facing infrastructure, not new encryption capability.Gangs are also extorting victims through data theft alone, as in Cl0p’s PTC Windchill campaign, which used no encryption, and are using AI to speed up intrusions.

“The quieter first half of the year was never a sign that ransomware was fading. Gangs were regrouping, and August shows what they regrouped into,” said Daksh Nakra, Senior Manager of Research and Intelligence at Cyble. “For Indian organisations, the lesson is to stop planning against the names in the headlines. The groups most active in this region often have little global profile, and the defences that hold against them are the fundamentals: knowing what is exposed to the internet, who can reach it, and whether you can recover without paying.”

What organisations should do

The brief calls for discipline in existing controls rather than new ones: risk-prioritised patching of internet-facing systems, phishing-resistant MFA extended to third parties, network segmentation to limit data theft, tested offline backups, and monitoring for exposure in leak and access markets.