Skip to content
Ransomware Attacks Surge 87% as Nigeria Records 4975 Weekly Cyberattacks

Ransomware Attacks Surge 87% as Nigeria Records 4975 Weekly Cyberattacks

Techeconomy.Ng • August 13, 2026

Nigeria recorded an average of 4,975 cyberattacks per organisation each week in July, placing the country among the most targeted markets globally.

This was revealed in the latest threat intelligence report from Check Point Research, the research arm of Check Point Software Technologies.

The report found that organisations worldwide faced an average of 2,336 attacks each week in July, with the global figure rising 3% from June and 16% from July 2025. Africa recorded a higher average of 3,237 attacks per organisation each week.

Latin America had the highest regional average at 3,561 weekly attacks, followed by Asia-Pacific at 3,316. Within Africa, Angola recorded 5,714 weekly attacks, while Kenya and South Africa recorded 2,915 and 2,195 respectively.

Financial Services, Government, and Energy and Utilities were the three most attacked sectors in Africa during the month.

Check Point Regional Director for Africa, Lorna Hardie, said the figures showed that organisations were dealing with several forms of cyber risk at the same time.

“ July’s data shows that cyber risk is accumulating across multiple fronts at once,” Hardie said.

“ Attack volumes continue to rise, ransomware has accelerated sharply, and GenAI exposure is now part of daily business activity. Organisations need prevention-first, AI-driven security that protects networks, users, data and AI workflows before attacks can cause impact.”

Education was the world's most attacked industry in July, with organisations in the sector recording an average of 4,848 attacks per week.

The figure was 14% higher than the same period last year.

Government organisations followed with 3,044 weekly attacks, while Telecommunications recorded 2,927. Energy and Utilities saw attacks rise 20% to 2,759 per week.

Hospitality, Travel and Recreation completed the global top five after recording 2,614 weekly attacks, a 28% increase year on year.

The report also found that employees' use of generative AI tools is creating new opportunities for sensitive information to leave corporate systems.

One in every 36 enterprise prompts was considered high risk for sensitive data leakage. Check Point found that 88% of organisations regularly using GenAI had users submitting high-risk prompts.

22% of prompts contained potentially sensitive information.

Organisations used an average of eight GenAI tools, while users generated 95 prompts each on average.

Personal data was the most common sensitive information exposed. It appeared in 70% of organisations examined. Financial data and network or IT infrastructure information followed at 68% each.

Email provided a common route for cyberattacks. Check Point found that one in every 128 emails received by organisations in July was classified as phishing. That represents 0.78% of all emails examined.

Another 20% fell into unwanted or risky categories, including spam, graymail and suspicious messages.

Africa recorded the highest phishing rate globally, with one in every 106 emails classified as phishing. North America followed at one in every 117 emails.

These messages can be used to steal login details, deliver malware or carry out business email compromise.

Ransomware recorded the biggest increase in the July figures.

Check Point identified 964 reported ransomware victims during the month. That was 49% higher than June and 87% above the number recorded in July 2025.

The increase also marked a change from the pattern seen during the first half of 2026. Monthly ransomware activity averaged 672 reported incidents during that period.

Business Services accounted for the largest of reported ransomware victims at 32.5%. Industrial Manufacturing followed with 14.4%, while Consumer Goods and Services accounted for 13.4%.

North America recorded 45% of reported ransomware incidents worldwide. Europe followed with 28% and APAC with 17%.

The United States accounted for 39.4% of reported victims, ahead of Germany, Canada, the United Kingdom and Italy.

The ransomware market was also fragmented, with several groups continuing to target organisations.

The Gentlemen and Qilin were the most prevalent groups in July. Each accounted for 14% of published ransomware attacks.

DeadLock ranked third with 10% of reported attacks and 97 victims.

The figures point to continued changes among the groups responsible for ransomware attacks, even as the overall number of reported victims climbed sharply in July.