July 2026 saw nearly 26 ransomware attacks per day, up from 22 per day in the previous month.
Last month, the number of ransomware attacks jumped 19 percent from 668 in June to 799 in July. This is the second-highest figure of the year so far, being just behind March’s total of 805 attacks.
The education sector saw a significant increase (up 44%), as did finance companies (up 71%), tech firms (up 62%), and businesses operating within the healthcare sector, e.g. pharmaceutical manufacturers and medical billing providers (up 46%).
Attacks on utility companies, legal firms, and government agencies declined by 44, 34, and 11 percent, respectively.
The battle between the two most dominant ransomware strains, The Gentlemen and Qilin, continued. The two groups accounted for nearly 33 percent of all attacks in July. The Gentlemen came out on top with 135 attacks, closely followed by Qilin with 125.
Key findings for July 2026
- 799 attacks in total — 51 confirmed attacks (confirmed by the entity involved)
- Of the 51 confirmed attacks:
- 31 were on businesses
- 10 were on government entities
- 3 were on healthcare companies
- 7 were on educational institutions
- Of the 748 unconfirmed attacks*:
- 657 were on businesses
- 24 were on government entities
- 50 were on healthcare companies
- 16 were on educational institutions
- The most prolific ransomware gangs were The Gentlemen (135) and Qilin (125)
- The Gentlemen had the most confirmed attacks (9), followed by Qilin (6)
- The US saw the most attacks (322), followed by Germany (40), Canada (36), India (30), the UK (25), and France (23)
*One attack was on an unknown entity.
Ransomware attacks by sector
Healthcare
Attacks on healthcare providers increased by 18 percent from June 2026 to July 2026, rising from 45 to 53. Three attacks were confirmed in July.
AnMed in the US announced its systems had been impacted by an attack on July 26. Patients described how hospital computer screens went blue and displayed a message demanding a ransom payment within 72 hours. At the time of writing, the hackers remain unknown and AnMed continues to work to restore its systems. By August 3, a patient phone line had been set up.
Stiftung Wagerenhof in Switzerland was targeted by unknown hackers in July 2026. The disability foundation said it did not meet its hackers’ demands. Altunizade Sağlık Hizmetleri San. Tic. A.Ş. in Turkey was also targeted by unknown hackers.
During the first seven months of 2026, we’ve recorded 306 attacks on the healthcare sector. This is a 20 percent increase from the same period of 2025 (256). 66 attacks throughout 2026 have been confirmed.
Government
Attacks on government entities declined in July 2026, falling from 38 in June to 34 in July (down 11%). 10 attacks in July have been confirmed to date.
Two government entities in Romania confirmed attacks on their systems – Agenția Națională de Cadastru și Publicitate Imobiliară (ANCPI) and Administrația Națională a Penitenciarelor (ANP). The attack on ANCPI caused widespread disruption to Romania’s real estate market. ByteToBreach claimed the attack. ANP’s attack has been linked to Babuk.
Two attacks were also confirmed in the US. Greene County was targeted by INC, and the Kenaitze Indian Tribe was targeted by The Gentlemen.
The other attacks were:
- Unitel, Angola – The state-owned telecom company was targeted in an attack just 24 hours before it was due to sell a 15 percent stake through the local stock exchange as part of its privatization program. There have been rumors of a $326.8 million ransom demand, but Unitel denied knowledge of it.
- Mato Grosso do Sul State Gas Company (MSGÁS), Brazil – Blackwater targeted the state-owned gas company. A data breach is likely.
- Ville de Drancy, France – The French town confirmed it hadn’t met its hackers’ demands. Qilin later added it to its data leak site.
- Stadtverwaltung Wriezen, Germany – On July 18, the city administration said it detected a cyberattack. The hackers are unknown.
- Bank of Baroda, India – Triple X claimed the attack on the public sector bank, saying it stole 1 TB of data.
- Metro Mondego, Portugal – On July 6, the public transport company’s systems were targeted in an attack claimed by The Gentlemen.
From January to July 2026, we’ve noted 225 attacks on government entities – a seven percent decrease from the same period of 2025 (242). 102 attacks have been confirmed in 2026 so far.
Education
Attacks on the education sector rose by 44 percent in July 2026, jumping from 16 in June to 23 in July. Seven attacks were confirmed in July.
Three educational institutions confirmed they hadn’t met their hackers’ demands – Universidad de Alicante in Spain, Universidade de Aveiro in Portugal, and Townsville Christian College in Australia. No hackers have claimed these attacks as of yet.
Elsewhere, NightSpire claimed an attack on Cedar Crest College in the US, Qilin claimed an attack on Universitatea de Vest “Vasile Goldiș” din Arad in Romania, and INC claimed an attack on Loyalist College in Canada.
The hackers remain unknown in the July 2026 attack on Hachioji Junior & Senior High School in Japan.
2026 so far (up to July) has seen 128 attacks on the education sector – a drop of 15 percent (from 151) in the same period of 2025. Throughout 2026, 44 attacks have been confirmed.
Businesses
Comparitech recorded 688 attacks on businesses in July 2026, a rise of 21 percent from June 2026 (568). 27 attacks were confirmed in June.
As previously noted, finance companies saw the biggest increase in attacks from June to July, rising by 71 percent. Three of these attacks were confirmed: Eurohold Bulgaria AD (Euroins AD) was claimed by KRYBIT, Gallant Finland was claimed by The Gentlemen, and PB Fiduciaire SA in Switzerland was claimed by BravoX.
Three transport companies confirmed attacks, including Hahn Airport in Germany (claimed by SafePay) and Nihon Kotsu Co., Ltd. in Japan (claimed by AiLock). Stadler Rail in Switzerland confirmed an attack but said it hadn’t met Everest’s ransom demand of 10 million Swiss francs (USD $12.3 million). This is Stadler’s second confirmed ransomware attack. It was previously targeted by Nefilim in May 2020.
Other key attacks include Fairlife in the US. The dairy manufacturer (which is part of Coca-Cola) was crippled by an attack on July 16. It caused widespread disruption with most production only being resumed around 10 days later. Anubis claimed the attack and said it had stolen 1 TB of data.
An attack on The Craneware Group also continued to highlight the impact of attacks on third-party healthcare businesses. The healthcare billing software provider confirmed there was no disruption to customer services but that a “significant volume of file names were viewed and exfiltrated.” Chaos claimed this attack and the theft of 960 GB of data.
From January to July of this year, we’ve noted 4,371 attacks on businesses worldwide, an increase of 24 percent from the same period in 2025 (3,513).
The most prolific ransomware groups in July 2026
The Gentlemen and Qilin once again claimed the most attacks. The Gentlemen claimed 135 victims in July, a 17 percent increase over June (115). Qilin claimed 125 victims – a significant increase on its 81 claims in June (up 54%).
Nine of The Gentlemen’s claims were confirmed. Alongside Gallant Finland, Metro Mondego, and the Kenaitze Indian Tribe mentioned above, The Gentlemen claimed attacks on Royal Foods Aust Pty Ltd in Australia, Spedidam in France, Ecopetrol S.A. in Colombia, Thialf BV in the Netherlands, Oldelval (Oleoductos del Valle) in Argentina, and Herbaház in Hungary.
Six of Qilin’s attacks were confirmed, including those on Ville de Drancy and Universitatea de Vest “Vasile Goldiș” din Arad. Attacks on rehaVital Gesundheitsservice GmbH in Germany, Groupe Fenwick in France, Pennant Hills Golf Club in Australia, and Asset Flooring Group Australia were also confirmed.
Attacks by DragonForce also rose significantly from 28 in June to 41 in July. One of its attacks was confirmed last month – Rectron (Pty) Ltd in South Africa.
SafePay, DeadLock, and Genesis also upped their attack claims with increases of 50, 110, and 467 percent respectively. Only one attack (the attack on Hahn Airport via SafePay) was confirmed.
July 2026 ransomware attacks by country
After H1 2026 saw an eight percent decline in the number of attacks carried out in the US, July saw a significant increase. Attacks increased by 31 percent from 246 in June to 322 in July.
Of the 322 attacks in the US in July, five were confirmed by the entity involved. All of these are mentioned above (Fairlife, Cedar Crest College, AnMed, Greene County, and the Kenaitze Indian Tribe).
Germany and Canada followed the US for the most attacks (confirmed and unconfirmed) but their figures for July were similar to June. Germany was targeted by 40 attacks (up from 38 in June) and Canada was targeted by 36 (compared to 35 in June).
The biggest increase in overall attacks was witnessed in Argentina. Here, attacks rose by 320 percent, jumping from five in June to 21 in July.
India (up 76%), the UK (up 67%), and Australia (up 56%) also saw significant increases
Confirmed vs unconfirmed attacks
We label a ransomware attack as “confirmed” when a) the targeted organization publicly discloses an attack that involved ransomware, or b) the targeted organization publicly acknowledges a cyber attack that coincides with a claim made by a ransomware group. If a ransomware group claims that it successfully attacked an organization, but the organization never acknowledged an attack, then we label the attack as “unconfirmed”.
An attack might be unconfirmed because the ransomware group making the claim is lying, or because the targeted organization chose not to disclose the attack to the public. Ransomware groups post their attack claims on their respective websites, where the data is auctioned or released when organizations don’t meet their ransom demands.
Organizations in the US are required to disclose data breaches, which often result from ransomware attacks, to state officials when they meet certain thresholds. Not all countries have breach disclosure laws.
When an attack is confirmed, it is removed from our list of unconfirmed attacks. Therefore, we must allow for some changes in figures when comparing monthly figures, especially when using unconfirmed attacks. This is due to claims from ransomware groups often coming a month later than the attack was carried out–if not longer. For example, if a ransomware gang claims an attack in January 2026, it may later be confirmed as an attack in December 2025 and will, therefore, be attributed to a different month.
You can view all attacks, from 2018 to present via our worldwide ransomware tracker here.
Note: a new ransomware gang called Section9 appeared in July 2026, adding a number of “unknown” entities to its data leak site. Experts suggest this is a fake group claiming fake attacks, so it hasn’t been included in our stats.