www.comparitech.com Record Ransomware Attacks Surge to 997 in August 2026
Article Content
- •Ransomware attacks hit a record 997 in August 2026, a 23% increase from July.
- •Healthcare and utility sectors saw significant increases in attacks, with healthcare up 30%.
- •Qilin and The Gentlemen were the most active ransomware groups, accounting for over 26% of attacks.
In August 2026, ransomware attacks reached a record high of 997, averaging 32 attacks per day, a 23% increase from July's 809 attacks. The healthcare sector experienced a 30% rise, while utility companies saw attacks double from five to ten. Businesses accounted for 861 of the attacks, with significant increases in law firms (up 52%), tech companies (up 42%), and finance companies (up 40%). The most active ransomware groups were Qilin and The Gentlemen, responsible for over 26% of the total attacks. Qilin led with 157 attacks, while The Gentlemen had 107. Confirmed attacks included incidents at Nutex Health Inc., Cedar County Memorial Hospital, and Windrose Health Network. The U.S. was the most targeted country, with 417 attacks. The overall trend indicates a growing threat landscape, particularly for critical sectors like healthcare and utilities.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (2)
Following this threat?
Track Clop, Storm and ATF in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
China-Linked QTFY Group Targets Critical Infrastructure with Advanced Exploits The Joint Cybersecurity Advisory JCSA-20260826-01, released on August 26, 2026, details ongoing activities by the China-linked hacking group QTFY, attributed to Nanjing Xinjiuwei Network Technology Co. Active since 2018, QTFY employs platforms like QScan and QTRouter to exploit vulnerabilities in critical…
PaperCut NG/MF Vulnerability Under Active Exploitation On August 27, 2026, PaperCut issued an urgent advisory regarding a zero-day vulnerability affecting its NG and MF print management software. This flaw allows unauthenticated attackers to execute arbitrary Java code remotely, compromising server configurations. Emergency patches have been released for versions 25 and…