Ransomware attacks saw a significant increase in July, with 799 incidents recorded, marking a nearly 20 percent rise from June's 668 incidents. This surge made July the second busiest month of the year for ransomware, closely trailing March, which saw 805 attacks. Of the July incidents, 51 were confirmed by the affected organizations.
The distribution of targets shifted notably in July. While attacks on utility companies, legal firms, and government agencies decreased by 44 percent, 31 percent, and 11 percent respectively, other sectors experienced substantial increases. Financial companies saw a 71 percent rise in attacks, tech firms 62 percent, pharmaceutical companies and medical billers 46 percent, and the education sector 44 percent. This trend aligns with observations that manufacturing, education, healthcare, and financial sector firms are among the most likely to pay ransoms, with even the least likely among these, finance, paying out in 51 percent of cases.
The United States was the most frequently targeted country, accounting for 322 of the 799 attacks in July. Germany followed distantly with 40 incidents.
Two prominent ransomware gangs were particularly active in July. "The Gentlemen," a relatively new but highly prolific operation, claimed responsibility for 135 victims. This group was previously linked to an attack on UK software consultancy Adaptavist Group earlier in the year. Qilin, known for its 2024 attack on UK pathology provider Synnovis that disrupted NHS services, claimed 125 victims. Together, these two groups were responsible for nearly a third of all ransomware attacks logged in July.
The methods of initial access for these attacks were not detailed for July's incidents. However, previous analysis of "The Gentlemen" suggests the use of stolen credentials, while Qilin has claimed to exploit zero-day vulnerabilities, as it did in the Synnovis breach in June 2024.
The overall increase in ransomware activity underscores the ongoing threat posed by these attacks, even as attention in the cybersecurity landscape may be drawn to emerging areas like artificial intelligence. Organizations are advised to maintain robust security practices, including multi-factor authentication, regular system updates, and consistent data backups.






