Cybersecurity

Ransomware attacks rose nearly 20% in July, researchers say

Comparitech recorded 799 ransomware incidents in July, making it the second-busiest month of the year, with finance, technology, pharmaceutical and education organisations seeing sharp increases.

By Jack Douglas | 8 August 2026
Close-up of a laptop displaying cybersecurity text, emphasizing digital security themes.

Ransomware attacks rose by nearly 20% in July, according to new figures from cybersecurity firm Comparitech, which recorded 799 incidents during the month.

The total was up from 668 incidents in June and made July the second-busiest month of the year for ransomware activity in Comparitech’s tracking. March remains slightly higher, with 805 attacks recorded.

Comparitech said 51 of July’s incidents had been confirmed by victims. The broader total includes attacks identified through other sources, including claims made by ransomware groups, which means some incidents may not yet have been publicly verified by affected organisations.

The figures point to continued pressure from established ransomware operators at a time when much of the wider technology and security debate has been focused on artificial intelligence. While AI-related risks have attracted growing attention from governments, companies and security teams, Comparitech’s data suggests more familiar cybercrime methods remain highly active.

The sector breakdown also shows a shift in targeting. Recent cyber headlines have included attacks on water infrastructure in the United States, but Comparitech said ransomware incidents affecting utility companies fell by 44% in July.

Legal firms and government agencies also saw fewer ransomware attacks, with incidents down 31% and 11% respectively, according to the company.

By contrast, attacks rose sharply against finance companies, technology firms, pharmaceutical companies and medical billers, and the education sector. Comparitech said attacks on finance companies increased by 71%, while technology firms saw a 62% rise. Incidents affecting pharmaceutical companies and medical billers were up 46%, and attacks on education organisations rose by 44%.

The pattern broadly matches findings from penetration testing firm DeepStrike, which has reported that manufacturing, education, healthcare and financial sector organisations are among the most likely to pay ransoms. DeepStrike said even finance, which it described as the least likely payer among those sectors, still paid in 51% of cases.

Ransomware groups often focus on organisations where disruption can be costly, urgent or difficult to absorb. Schools, healthcare-linked businesses and financial services firms may face operational pressure to restore access quickly, while technology providers can present opportunities for wider disruption if their systems or customers are affected.

The United States remained by far the most-targeted country in July, accounting for 322 of the 799 attacks recorded by Comparitech. Germany was second with 40 incidents, underlining the scale of the gap between the US and other affected countries in the firm’s monthly data.

Two ransomware groups accounted for a large share of activity. Comparitech said The Gentlemen, a relatively new operation, claimed 135 victims in July. Qilin, a better-known ransomware gang, claimed 125 victims.

Together, the two groups were linked to almost a third of the ransomware attacks logged during the month.

Qilin is known in the UK for the 2024 attack on pathology provider Synnovis, which disrupted NHS services. The incident affected blood testing and other pathology services used by hospitals and GP practices in parts of London.

The Gentlemen has also been linked to UK targets. Earlier this year, the group claimed responsibility for an attack on Adaptavist Group, a UK software consultancy.

Comparitech did not provide details on how attackers gained access to victims’ networks in the July incidents. In previous reporting on ransomware groups, common entry methods have included stolen credentials, phishing, exploitation of unpatched systems and abuse of previously unknown software vulnerabilities.

Trend Micro has previously said The Gentlemen used stolen credentials as part of its methodology. Qilin has previously told The Register that it exploited zero-day vulnerabilities in the Synnovis attack in June 2024.

Security specialists commonly advise organisations to reduce ransomware exposure by enforcing multi-factor authentication, limiting unnecessary access privileges, applying software updates promptly and maintaining tested offline or otherwise protected backups.

Backups are especially important because they can allow organisations to restore systems without paying a ransom, although attackers increasingly combine encryption with data theft and extortion. In such cases, victims may face threats that stolen information will be leaked even if systems can be recovered.

The latest figures indicate that ransomware remains a persistent global threat despite changing priorities in cybersecurity. AI may be reshaping parts of the security landscape, but July’s activity suggests criminal groups continue to rely on established tactics against organisations that cannot easily tolerate disruption.