August 2026 set a new record for ransomware attacks, with more than 1,000 organizations worldwide hit. Factories, hospitals, and IT companies took the brunt as groups like Qilin and The Gentlemen stepped up their campaigns.
Ransomware broke all records in 2026. In August alone, 1,073 organizations worldwide were hit by digital extortion. This number comes from NCC Group's Cyber Threat Intelligence Report. The surge marks a new phase in cyber risk. No sector or region is safe. Comparitech-linked coverage found 997 ransomware attacks in August, averaging 32 incidents a day. That's more than any previous month, beating the old record from February 2025. The pace keeps climbing.
North America took the biggest hit, with 44% of known attacks. Europe saw 26%, and Asia 13%. South America, Africa, and Oceania were also targeted, but less often. Factories and industrial firms were the main targets, making up nearly a third of all cases. Consumer goods, healthcare, IT, and financial services followed. The range and scale of these attacks show how exposed both critical infrastructure and everyday businesses have become.
Manufacturing has been the top ransomware target for four years running. The Black Kite 2026 Manufacturing & Distribution Ransomware Report says 1,183 manufacturing victims were made public in just the first seven months of 2026. That's a 39.7% jump from last year, already topping the full-year total for 2024. Across all sectors, Black Kite counted 7,551 ransomware victims in its wider dataset. This shows how exposed the sector is to digital extortion and supply chain threats. Italian authorities, including the Agenzia per la Cybersicurezza Nazionale (ACN), have warned that industrial and critical infrastructure operators must follow the latest EU NIS2 Directive and sector-specific cybersecurity rules to reduce these risks.
Qilin and The Gentlemen led the pack among ransomware groups, with 164 and 116 attacks each. Their campaigns have made them the most feared groups of 2026. Clop, Dire Wolf, and INC Ransom followed behind. Notable cases included a cyber-attack on Boston Dynamics and a data breach at Manchester Airport Group. The Manchester breach showed how some gangs are moving from encrypting data to stealing it outright and demanding payment.
The manufacturing sector has now seen four consecutive years as the top ransomware target, with 1,183 victims in just the first seven months of 2026-a 39.7% year-over-year increase that signals a critical need for enhanced cyber resilience across European industry.
Matt Hull, VP of cyber intelligence and response at NCC Group, links this spike to fast advances in AI and ongoing geopolitical tension. Both are driving more complex and state-backed threats. The report calls on organizations to build strong defense plans and run tabletop exercises to spot and fix gaps before attackers find them.
This surge is not happening in isolation. As reported earlier, the ransomware world is splitting apart. Rival gangs are sabotaging each other even as they step up attacks on real businesses. The result is chaos. The rules keep changing, and the risks keep growing.
August was the second month in a row with record ransomware activity. The warning for organizations is clear: there's no room for complacency. Factories, hospitals, and IT firms are all in the crosshairs. Data theft is rising as gangs move beyond simple encryption. The threat is changing faster than most defenses can keep up. Only those who invest in resilience, plan ahead, and adapt quickly will have a shot at stopping the next wave of digital extortion. For more help, organizations can use the ACN's official NIS2 cybersecurity resources for compliance and best practices.