India now tops the Asia-Pacific for ransomware attacks. Local and lesser-known groups are breaking in through years-old security holes. Organisations must rethink their defences as threats multiply.
August 2026 brought a sharp warning for India's cyber defences. Ransomware groups claimed 24 Indian victims that month. No other country in Asia-Pacific saw more. That's nearly one in six reported cases across the region. The global total hit 1,034 publicly disclosed ransomware victims in August, a new monthly record. Multiple industry threat intelligence reports confirm the spike.
Big ransomware names grab global headlines. But in India, a different set of attackers is at work. Cyble Research and Intelligence Labs (CRIL) found that regional gangs and affiliates-often ignored in global threat models-are now driving the surge. The Gentlemen, Krybit, and orova were among the busiest in Asia-Pacific. They even outpaced Qilin, the world's most prolific group in August. Thailand, Taiwan, and Japan together made up almost half of the 143 APAC victims. The threat is wide and growing.
Old flaws, new victims
Attackers aren't waiting for new zero-days. They're using old, unpatched holes. The Akira ransomware group hit CVE-2024-40766, a SonicWall SSL VPN flaw found two years ago and patched in August 2024. Gunra affiliates went after known Fortinet FortiOS bugs. SonicWall called CVE-2024-40766 a critical SonicOS SSLVPN vulnerability. The company warned it was being actively exploited. The lesson is simple. Patching isn't a one-time job. If updates aren't rolled out everywhere, old weaknesses stay open. Attackers walk right in.
This isn't just India's problem. Across Asia-Pacific, 143 ransomware victims were publicly named in August. India led, then Thailand, Taiwan, and Japan. But India's case stands out. The country's rapid digital growth has left a patchwork of old systems and uneven security. The latest CRIL report says 88 ransomware groups struck in August. That's an average of 33 new victims a day. It's a 25% jump from July's already high numbers.
NCC Group confirmed that August 2026 saw a 12% month-on-month increase in publicly disclosed ransomware attacks, reaching a new annual high with 1,073 incidents worldwide.
Ransomware changes tactics and slips past defences
Ransomware tactics are shifting fast. Detection is getting harder. CRIL points to a campaign by Cl0p affiliates using CVE-2026-12569 in PTC Windchill and FlexPLM. These tools are vital for manufacturing and engineering. Instead of locking up systems, attackers are stealing blueprints, CAD files, and supply-chain data. Over 40 organisations have been named in this campaign. The old model-locked screens and ransom notes-doesn't always apply now. Intellectual property and business secrets can be stolen quietly. Classic endpoint alarms don't always go off.
For Indian manufacturers and engineering firms, the risk is now at the core of their business. Design and supply-chain data are targets. It's not just about downtime. Silent theft of competitive advantage is a real threat. Italian regulators like ACN have stressed the need for timely patching and sector-specific threat intelligence. Ransomware groups are going after industrial and critical infrastructure more often.
The threat landscape splinters
India's ransomware crisis is growing as threats become more scattered and unpredictable. No single group runs the show. Instead, a mix of global actors, regional specialists, and affiliates are finding new ways in. This mess makes generic defences useless. Organisations need sharp, local threat intelligence. They must track the groups and tactics active in their own region, not just the ones in global news.
As reported earlier, attackers are nimble. They switch between ransomware brands and use remote access tools to break into networks. India's experience shows the danger of ignoring local threats and leaving old flaws unpatched. That's a recipe for disaster.
Complacency is the real threat
With 88 ransomware groups active worldwide in August, the threat is spread out. It's not just about a few big names. The Cyble report is clear. Indian organisations can't focus only on the next headline ransomware or the latest exploit. The real risk is complacency. Old vulnerabilities are still dangerous. Attacks can come from groups you've never heard of. The worst breach might use a door left open years ago. For Indian enterprises, the way forward is clear. Patch management must be constant. Local threat intelligence matters. Ransomware is changing faster than most defences. Only those who adapt to this fractured, region-driven threat landscape will avoid becoming the next public victim.