Back www.comparitech.com Ransomware Roundup Q3 2026 Stats On Attacks Ransoms And Active Gangs
Q3 2026 saw the highest quarterly figures to date with 2,627 ransomware attacks in total – an average of nearly 29 per day.
This is a 29 percent increase on Q2 2026 when we logged 2,030 attacks in total, and a 61 percent increase on the same period last year (Q3 2025), when 1,636 attacks took place.
All four key sectors saw significantly more attacks in Q3 2026 compared to Q2 2026. Education saw the biggest uptick with an increase of 50 percent, followed by healthcare (up 39 percent), government (up 36 percent), and businesses (up 27 percent).
Within the business sector, all sub-industries saw a rise in attacks from Q2 to Q3 2026, bar two. Legal firms saw a 26 percent decrease in attacks, while the construction sector saw a minor two percent decline.
The industries with the biggest increases were finance (up 72 percent), technology (up 70 percent), businesses operating in the healthcare sector* (up 35 percent), and utilities (up 32 percent).
*but not providing direct care, e.g. pharmaceutical and medical device manufacturers.
Key findings for Q3 2026:
2,627 attacks in total — 247 confirmed attacks (confirmed by the entity involved)
Of the 247 confirmed attacks: 138 were on businesses 53 were on government entities 36 were on healthcare companies 20 were on educational institutions
138 were on businesses
53 were on government entities
36 were on healthcare companies
20 were on educational institutions
Of the 2,380 unconfirmed attacks*: 2,096 were on businesses 71 were on government entities 152 were on healthcare companies 55 were on educational institutions
2,096 were on businesses
71 were on government entities
152 were on healthcare companies
55 were on educational institutions
1,611,971 records compromised in the confirmed attacks
Median ransom demand: $150,000 (average: $602,400)
The most prolific ransomware gangs were Qilin (357 attack claims) and The Gentlemen (342)
Qilin and The Gentlemen also had the most confirmed attacks out of these claims with 27 and 26, respectively
Over 641 TB of data has been stolen across all these attacks
The US saw the most attacks (1,066), followed by Germany (121) and Canada (103)
Attacks in the US increased by 34 percent (when compared to Q2) but some of the largest increases were seen in India (up 116 percent) and Argentina (up 150 percent)
*6 unconfirmed attacks couldn’t be attributed to a sector due to limited company information.
Ransomware attacks by sector
124 attacks in total (confirmed and unconfirmed)
71 unconfirmed attacks
Median ransom demand was $60,000 (average = $358,000)
12 entities confirmed they hadn’t paid a ransom (none confirmed to have paid)
188 attacks in total (confirmed and unconfirmed)
152 unconfirmed attacks
Median ransom demanded = $300,000 (average = $528,000)
5 entities confirmed they hadn’t paid a ransom (none confirmed to have paid)
75 attacks in total (confirmed and unconfirmed)
55 unconfirmed attacks
Median ransom demanded = $510,000 (average = $645,100)
5 entities confirmed they hadn’t paid a ransom (none confirmed to have paid)
2,234 attacks in total (confirmed and unconfirmed)
138 confirmed attacks
2,096 unconfirmed attacks
Median ransom demanded = $100,000 (average = $651,500)
11 entities confirmed they hadn’t paid a ransom (one, Nick Scali in Australia, is rumored to have negotiated with its hackers)
As we’ve already noted, all but two sub-industries (construction and legal) saw an increase in attacks from Q2 2026 to Q3 2026.
Finance and tech companies saw the biggest increases.
A total of 262 tech companies were targeted in Q3 2026, which was a 70 percent increase from Q2 2026 (154 attacks). Finance organizations saw a similar increase of 72 percent, with attacks rising from 116 in Q2 2026 to 199 in Q3 2026.
Manufacturers were the most targeted overall with 478 attacks in Q3 2026. This was a 22 percent increase from Q2 2026 (391).
Businesses operating in the healthcare sector (up 35 percent) and utility companies (up 32 percent) were also a favored target for hackers.
When comparing Q3 2025 with Q3 2026, tech companies recorded the biggest increase. Attacks climbed 132 percent from 113 in Q3 2025 to 262 in Q3 2026. Transportation companies saw the second-highest increase. Here, attacks jumped by 118 percent from 34 to 74.
Healthcare businesses (up 95 percent), retailers (up 97 percent), and manufacturers (up 52 percent) also saw marked increases.
The top 5 biggest ransom demands in Q3 2026
According to our data, the following organizations saw the biggest ransom demands (across confirmed attacks) throughout Q3 2026. Note that most companies and ransomware groups do not disclose their ransom demands, so data is limited.
Stadler Rail, Switzerland – $12.3 million: In July 2026, Everest issued Stadler with a hefty ransom after accessing a platform shared between the Swiss manufacturer and one of its suppliers. Stadler refused to pay and Everest proceeded to leak 201 GB of data.
Government of Berlin, Germany – $2.3 million: Rhysida tried to blackmail the German city in August 2026 after allegedly stealing 5.79 TB of data. Berlin refused to meet the hackers’ demands.
Kreishandwerkerschaft Borken, Germany – $674,000: Rhysida also claimed this attack on Germany’s Borken District Craftsmen’s Association in September 2026.
SAD’S Intérim, France – $630,000: The French employment agency was targeted in September 2026 with Rhysida issuing it an 8-bitcoin demand.
General Santos Doctors Hospital, the Philippines – $617,400: After Rhysida claimed the attack in September 2026 and issued the hospital with a ransom for 2.44 TB of alleged stolen data, GSDH said there was no evidence of a breach. It later retracted the statement and confirmed the attack.
Please note: while Rhysida features heavily in this list, this doesn’t mean it’s necessarily issuing the biggest ransom demands. Rather, Rhysida is one of only a few groups to disclose a ransom demand figure in its public attack claims.
The top 5 biggest data breaches via ransomware in Q3 2026
While most data breach reports come through months after an attack has taken place, 28 companies disclosed the number of people impacted in ransomware attacks throughout Q3 2026. In total, over 1.6 million are confirmed to have been impacted so far.
The largest of these were:
Saber Healthcare Group, US – 427,084 people affected: In July 2026, Saber was targeted in an attack by unknown hackers. It is now issuing data breach notifications to over 427,000 people with medical information, Social Security numbers, and financial data affected.
Arbeiterkammer (Austrian Chamber of Labour) – 270,000 people affected: The Gentlemen breached the chamber’s systems in August 2026. Approximately 270,000 members are thought to have been affected with their names and addresses, as well as their employer and social security number, being involved.
Greenberg Traurig, LLP, US – 150,000 people affected: The legal firm started notifying 150,000 people of a breach from August 2026, which was claimed by Silent Ransom Group (also known as LeakedData).
Ryomo Systems Co., Ltd., Japan – 127,789 people affected: Following the attack on the Japanese tech company, two of its clients, Daito Gas (124,000 people) and Isesaki City (3,789 people), have issued breach notifications. SafePay claimed the attack.
AngMar Management Services, US – 126,196 people affected: Interlock targeted the US company in July 2026 and said it had stolen 710 GB of data. AngMar has issued notifications to those affected, warning that Social Security numbers and medical and health insurance details were among the records affected.
The most prolific ransomware strains in Q3 2026
Qilin continued to dominate in Q3 2026 with 357 attacks in total, but was closely followed by The Gentlemen with 342 attacks. Both groups increased their attacks by similar amounts. Qilin attacks rose 24 percent compared last quarter, and The Gentlemen attacks rose 29 percent.
Bigger increases were seen by Clop (up 4,700 percent from one attack in Q2 2026 to 48 attacks in Q3 2026). DireWolf upped its attacks by 1,450 percent and Rhysida by 200 percent. In contrast, Akira’s attacks declined by 23 percent and LockBit’s by 51 percent.
Qilin and The Gentlemen had the most confirmed attacks with 27 and 26, respectively.
Q3 2026 ransomware attacks by country
1,066 (or 41 percent) of attacks were carried out on US entities. This was a 34 percent increase from Q2 2026. Germany saw the second-highest number of attacks with 121 in total – a 22 percent increase from Q2 2026 (99).
Canada (103) and Italy (86) followed and both saw increases compared to Q2 2026 (four and 32 percent, respectively). But it was fifth-place India that saw one of the biggest increases in attacks, rising by 116 percent from 37 in Q2 2026 to 80 in Q3 2026.
Argentina also saw a significant rise in attacks with 45 noted in Q3 2026, compared to 18 in Q2 2026 (a 150 percent increase).
Confirmed vs unconfirmed attacks
We label a ransomware attack as “confirmed” when a) the targeted organization publicly discloses an attack that involved ransomware, or b) the targeted organization publicly acknowledges a cyber attack that coincides with a claim made by a ransomware group. If a ransomware group claims that it successfully attacked an organization, but the organization never acknowledged an attack, then we label the attack as “unconfirmed”.
An attack might be unconfirmed because the ransomware group making the claim is lying, or because the targeted organization chose not to disclose the attack to the public. Ransomware groups post their attack claims on their respective websites, where the data is auctioned or released when organizations don’t meet their ransom demands.
Organizations in the US are required to disclose data breaches, which often result from ransomware attacks, to state officials when they meet certain thresholds. Not all countries have breach disclosure laws.
When an attack is confirmed, it is removed from our list of unconfirmed attacks. Therefore, we must allow for some changes in figures when comparing monthly figures, especially when using unconfirmed attacks. This is due to claims from ransomware groups often coming a month later than the attack was carried out–if not longer. For example, if a ransomware gang claims an attack in January 2026, it may later be confirmed as an attack in December 2025 and will, therefore, be attributed to a different quarter.
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
