Ransomware attacks saw a significant increase in July, rising by 19% compared to June, according to an analysis published on August 5. This surge followed a period of relative calm in April, May, and June, making July the second most active month for ransomware in 2026 and the third highest in the past 17 months. A total of 799 claimed ransomware attacks were observed during July.
Industries most affected by this rise included finance, which saw a 71% increase in attacks, followed by technology (62%), healthcare (46%), and education (44%). Organizations based in the United States also experienced a notable uptick, with attacks increasing by 31% from June.
Among the confirmed incidents highlighted in the analysis was an attack on AnMad, a US healthcare provider, which led to the closure of some of its facilities. Another significant event involved Romania's government land registry agency, where an attack reportedly wiped an entire database, causing considerable disruption to the country's real estate market.
The ransomware groups "The Gentlemen" and "Qilin" continued to be the most dominant threats in July, together accounting for 33% of all attacks. The Gentlemen claimed 135 attacks, while Qilin claimed 125, indicating an ongoing competition for supremacy between the two strains. Earlier analysis from March to May 2026 had already identified The Gentlemen as the leading actor in cyber extortion, surpassing Qilin.
Other active ransomware groups in July included DragonForce with 41 attacks, INC with 36, CRPx0 with 33, and SafePay with 30. These figures underscore the continued and evolving threat landscape posed by various ransomware operations.






