More than 1,000 organizations worldwide were struck by ransomware attacks in August, marking a new peak for cyber extortion campaigns in 2026, according to NCC Group's Cyber Threat Intelligence Report for August 2026, released on September 23. The analysis found that 1,073 companies became victims of ransomware during the month, representing a 12% jump from the 973 organizations hit in July. The findings signal a steady climb in global ransomware activity throughout the year.

North America bore the brunt of the attacks, accounting for 44% of all incidents documented in August, while European organizations represented 26% of known victims and Asian targets made up 13% of cases. Organizations in South America, Africa, and Oceania accounted for 6%, 2%, and 2% of ransomware victims, respectively. The industrial sector faced the heaviest assault, comprising nearly a third—31%—of all reported incidents during the month. Other sectors experiencing significant disruption included consumer goods and services at 18%, healthcare at 12%, information technology at 11%, and financial services at 6%. High-profile incidents referenced in the analysis included a cyber-attack targeting Boston Dynamics and a data breach affecting Manchester Airport Group, with the latter highlighting a shift by some criminal groups away from encryption toward direct data theft and extortion.

Among attacks traced to identified threat actors, the report attributed 164 ransomware incidents to Qilin and 116 to The Gentlemen, two groups that have consistently ranked as the most prolific ransomware attackers throughout 2026. Other active groups during August included Clop with 89 attributed attacks, Dire Wolf with 43, and INC Ransom with 43. "August was the second consecutive month of highest ransomware levels for the year, indicating a steady rise in global activity," said Matt Hull, VP of cyber intelligence and response at NCC Group, who pointed to "rapid advancements in AI and ongoing geopolitical volatility which are fuelling state-sponsored threats" as key drivers.

The escalation in ransomware activity stems from a combination of factors that are accelerating the threat landscape, according to the analysis. Artificial intelligence advancements are enabling attackers to refine their methods and scale operations more effectively, while geopolitical instability continues to fuel state-sponsored cyber threats that amplify overall attack volumes. The report emphasizes that as these dynamics evolve, organizations must ensure their defensive and response capabilities advance at the same pace to avoid falling behind emerging threats.

To counter the rising tide of attacks, the report recommends organizations establish a defense plan that includes a strategic playbook ready to deploy the moment a ransomware incident occurs, designed to minimize damage and contain the breach quickly. NCC Group also advocates for tabletop exercises that prepare teams for real-world scenarios while simultaneously identifying and closing gaps in cybersecurity strategies before attackers can exploit them. The message is clear: with ransomware showing no signs of slowing down, preparation and rapid response are no longer optional for organizations of any size. The persistence of groups like Qilin and The Gentlemen suggests that without stronger defenses, the record set in August may not hold for long.