Ransomware incidents surged nearly 20 percent in July, climbing to 799 cases from 668 the month before, according to data published by UK cybersecurity firm Comparitech. The July count made it the second-busiest month of the year for ransomware, trailing March's 805 attacks by just six incidents. Of the 799 July attacks, 51 had been verified by the victims themselves.

The most striking pattern in the data wasn't the volume alone but where attackers focused their energy. While attacks on utility companies dropped 44 percent last month, incidents targeting finance companies jumped 71 percent, tech firms saw a 62 percent increase, pharmaceutical companies and medical billers faced 46 percent more attacks, and the education sector experienced a 44 percent climb. Legal firms and government agencies also saw declines, with attacks falling 31 percent and 11 percent respectively. The United States absorbed the bulk of the damage, accounting for 322 of the 799 recorded incidents, while Germany came in second with just 40 attacks.

Two ransomware gangs dominated the threat landscape in July, together claiming nearly 33 percent of all logged attacks. The Gentlemen, a relative newcomer that has rapidly grown into one of the most active ransomware operations, led the month with 135 claimed victims and earlier this year took credit for breaching UK software consultancy Adaptavist Group. Qilin, the gang responsible for the 2024 attack on pathology provider Synnovis that disrupted NHS services in the United Kingdom, claimed 125 victims in July. Between them, the two groups accounted for 260 of the month's incidents.

The shift in targets makes sense when viewed through the lens of who actually pays. Comparitech cited findings from pentesting firm DeepStrike showing that manufacturing, education, healthcare, and financial sector companies are the most likely to hand over ransom payments, with even finance firms—the least likely of the four—still paying ransoms 51 percent of the time. That pattern helps explain why attackers increasingly focused on finance, tech, pharmaceuticals, and education while pulling back from utilities and government agencies. As for how the criminals keep breaking in, Comparitech pointed to stolen credentials, which Trend Micro identified as The Gentlemen's preferred method, and exploitation of zero-day vulnerabilities, which Qilin told The Register it used to compromise Synnovis in June 2024.

The report's recommendations are straightforward: require employees to use a second secure factor when logging in, keep systems updated, and maintain regular backups. The takeaway, according to Comparitech, is clear: "All eyes may be on what AI is doing to the security landscape, but old-school threats aren't going away." Organizations that assume traditional attack vectors have been eclipsed by emerging threats may find themselves blindsided by the same criminals who've been operating for years. The shift toward sectors with proven willingness to pay suggests ransomware operators are becoming more selective and strategic, targeting companies where the path from breach to payment is well-worn and reliable.