Ransomware attacks hit a record-breaking high in August 2026 with 32 attacks per day, up from 26 per day in July.
In August, we recorded 997 ransomware attacks, a 23 percent increase from July (809). It exceeds the record in February 2025 when we logged 988 attacks.
The healthcare sector saw a 30 percent increase in attacks, but utility companies saw the biggest spike. Here, attacks doubled, rising from five in July to 10 in August. Law firms (up 52%), tech companies (up 42%), and finance companies (up 40%) also saw significant increases.
Education (down 4%) and the food and beverage sector (down 5%) were the only areas to see ransomware attacks decrease.
Qilin and The Gentlemen once again dominated, accounting for over 26 percent of all the attacks. Qilin did, however, far exceed The Gentlemen’s total for the first time in a few months with 157 attacks compared to 107.
Key findings for August 2026
997 attacks in total — 77 confirmed attacks ( confirmed by the entity involved )
Of the 77 confirmed attacks: 49 were on businesses 18 were on government entities 8 were on healthcare companies 2 were on educational institutions
49 were on businesses
18 were on government entities
8 were on healthcare companies
2 were on educational institutions
Of the 920 unconfirmed attacks*: 812 were on businesses 21 were on government entities 61 were on healthcare companies 22 were on educational institutions
812 were on businesses
21 were on government entities
61 were on healthcare companies
22 were on educational institutions
The most prolific ransomware gangs were Qilin (157) and The Gentlemen (107)
Qilin took credit for the most confirmed attacks (12), followed by The Gentlemen (8)
The US saw the most attacks (417), followed by Germany and Italy (48 each), the UK (36), and Canada (35)
*Four attacks were on entities that couldn’t be identified.
Ransomware attacks by sector
Three of the confirmed attacks took place in the US:
Nutex Health Inc. – noted unauthorized activity on its systems in a SEC filing on August 24, 2026. The Gentlemen claimed the attack
Cedar County Memorial Hospital – the hospital’s IT networks were disrupted on the afternoon of August 14, 2026. Operations had returned to normal on the morning of August 28. Wallstreet claimed the attack
Windrose Health Network – hackers were able to exploit a vulnerability in the network’s remote-management tool in early August, which led to a data breach. Storm claimed the attack
Elsewhere, an attack on Canada’s Health Science Centre in Winnipeg impacted certain facility maintenance systems, including door access, heating, ventilation, and air-conditioning. No hackers have claimed the attack. The group involved in an attack on Hvidovre Hospital in Denmark also remains unknown.
Rhysida issued SIA Medical Centre in Australia with a 6 bitcoin ($376,000) ransom demand, while the Instituto Nacional de Cancerología (INCAN) in Guatemala confirmed it hadn’t met its hackers’ (KRYBIT) demands. INC also claimed an attack on Policlinico Triestino in Italy.
During the first eight months of 2026, we’ve recorded 378 attacks on the healthcare sector. This is a 32 percent increase from the same period of 2025 (287). 85 attacks throughout 2026 have been confirmed.
Nine of the confirmed attacks took place in the US. The City of Coweta in Oklahoma and the City of Circleville in Ohio both confirmed they hadn’t met their hackers’ (unknown) demands. Both the City of Fort Scott in Kansas (unknown hackers) and the City of Mitchell in South Dakota (claimed by Storm) noted nearly a week of disruptions due to their attacks.
The groups responsible also remain unknown in the attacks against Suisun City in California, the Town of Lincoln in Maine, and the City of Norcross in Georgia. Wallstreet claimed an attack on the Town of Andover , which disrupted schools in the area. And Qilin claimed an attack on the Bureau of Alcohol, Tobacco, Firearms and Explosives (ATF) .
Spain and Germany had two attacks each. In Spain, attacks on Gobierno de Castilla-La Mancha and Ayuntamiento de Velilla San Antonio were claimed by Panzer and Kairos, respectively. In Germany, unknown hackers targeted a memorial foundation ( Stiftung Brandenburgische Gedenkstätten ), while Rhysida issued the government of Berlin with a 30 bitcoin ($2.3 million) ransom demand for the deletion of 5.79 TB of data. Berlin refused the demand.
Attacks on the Commission de la construction du Québec in Canada, Ministerio de Justicia y del Derecho in Colombia, Municipality of Sithonia & Municipal Port Fund of Sithonia in Greece, Corte de Constitucionalidad in Guatemala, and Magyar Államkincstár Mezőgazdasági és Vidékfejlesztési (Nemzeti Kifizető Ügynökség) in Hungary were also confirmed. The ransomware groups are unknown in all cases bar the Commission de la construction du Québec, for which Qilin claimed responsibility.
From January to August 2026, we’ve noted 270 attacks on government entities – a similar figure to that noted within the same period of 2025 (267). 124 attacks have been confirmed in 2026 so far.
Both of August’s confirmed attacks on the education sector were claimed by Qilin. Brazosport College in the US confirmed a cybersecurity incident had significantly impacted its systems on August 10, 2026. Most campus internet and WiFi services had been restored by August 20. Uşak Üniversitesi in Turkey also noted system disruptions due to its attack.
2026 so far (up to the end of August) has seen 154 attacks on the education sector – a drop of 12 percent (from 175) in the same period of 2025. Throughout 2026, 48 attacks have been confirmed.
As we’ve noted, attack claims on utility companies doubled in August with one attack confirmed to date. Italy’s Alto Calore Servizi S.p.A. confirmed an attack, which was later claimed by Titan. This wasn’t the first confirmed attack on the Italian water company. In August 2023, Medusa hit Alto Calore Servizi with a $100,000 ransom demand after breaching its systems.
Legal firms, finance companies, and technology organizations also saw significant increases in attacks, rising by 52, 40, and 42 percent, respectively. None of the attacks on legal firms have been confirmed yet but five attacks each were confirmed by finance and tech companies.
The confirmed attacks on finance companies were:
TechVentures Bank SA , Romania – claimed by RansomHouse
Sawyer Savings Bank , US – claimed by Storm
Dodo Payments , India – claimed by Dire Wolf
DC Partner , South Africa – claimed by KRYBIT
Partners HoldCo, a.s. , Czech Republic – unknown hackers
The five confirmed attacks on tech companies were:
CEC Co., Ltd. , Japan – hackers unknown
Ambition DX Holdings Co., Ltd. , Japan – claimed by SETTRA with 437 GB stolen
The AME Group , US – hackers unknown
HostDzire , India – hackers unknown
Cartrack , South Africa – claimed by Dire Wolf with 100 GB stolen
Attacks on retailers increased by 30 percent and manufacturers saw a 23 percent increase. These two sectors also saw the most confirmed attacks in August 2026 with eight and 12, respectively.
From January to August of this year, we’ve noted 5,260 attacks on businesses worldwide, an increase of 32 percent from the same period in 2025 (4,000).
The most prolific ransomware groups in August 2026
Qilin and The Gentlemen may remained at the top again last month but it was Qilin that upped the ante. Qilin’s attacks increased 22 percent in August, while The Gentlemen’s declined 21 percent.
12 of Qilin’s attacks were confirmed last month. Among these was the Belgian retailer WEBA , which refused to meet the hackers’ demands. Qilin said it stole 1.224 TB of data.
Seven of The Gentlemen’s attacks were also confirmed. Manufacturers were a key focus. Akatake Engineering Co., Ltd. in Japan, GEB SAS in France, and healthcare manufacturer PharmaEssentia (Panco Healthcare) in Taiwan all confirmed attacks. The Austrian Chamber of Labour (Arbeiterkammer) confirmed an attack by The Gentlemen, stating 270,000 members were potentially involved in the data breach.
The biggest increase in attack claims last month came from Clop. It added 45 victims to its site (up from just one in July 2026). These attacks form part of its PTC Windchill vulnerability exploit with Shell in the UK and Philips in the Netherlands confirming breaches as a result.
August 2026 ransomware attacks by country
Attacks in the US increased by 28 percent last month, which is likely due to the increase in attacks by Qilin. 34 percent of its claims were on US companies.
Italy and Taiwan saw the biggest increase in attacks. In Italy attacks jumped by 200 percent from 16 in July 2026 to 48 in August 2026. A 200 percent increase was also seen in Taiwan (up from 7 in July to 21 in August).
Germany saw a 14 percent rise in attacks, while the UK saw a 44 percent increase. Attacks remained level in France. They declined by three percent in Canada and 20 percent in India.
Confirmed vs unconfirmed attacks
We label a ransomware attack as “confirmed” when a) the targeted organization publicly discloses an attack that involved ransomware, or b) the targeted organization publicly acknowledges a cyber attack that coincides with a claim made by a ransomware group. If a ransomware group claims that it successfully attacked an organization, but the organization never acknowledged an attack, then we label the attack as “unconfirmed”.
An attack might be unconfirmed because the ransomware group making the claim is lying, or because the targeted organization chose not to disclose the attack to the public. Ransomware groups post their attack claims on their respective websites, where the data is auctioned or released when organizations don’t meet their ransom demands.
Organizations in the US are required to disclose data breaches, which often result from ransomware attacks, to state officials when they meet certain thresholds. Not all countries have breach disclosure laws.
When an attack is confirmed, it is removed from our list of unconfirmed attacks. Therefore, we must allow for some changes in figures when comparing monthly figures, especially when using unconfirmed attacks. This is due to claims from ransomware groups often coming a month later than the attack was carried out–if not longer. For example, if a ransomware gang claims an attack in January 2026, it may later be confirmed as an attack in December 2025 and will, therefore, be attributed to a different month.
You can view all attacks, from 2018 to present via our worldwide ransomware tracker here .
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
