Get DeafLetter
A weekly selection of signals, vulnerabilities and guides. Critical alerts remain optional.
You can unsubscribe at any time. Privacy policy.
August 2026 was the bloodiest month of the year for global ransomware: 1,073 organizations hit, according to NCC Group's Threat Intelligence report. It marks the second consecutive month at peak levels, following 973 attacks in July, a 12% increase confirming a steady upward trajectory. Behind the numbers, however, lies a profound mutation of the criminal market: payments stalled at 23% in Q2 2026, a multi-year low, while those who do pay face median demands up 368% in a year.
- 1,073 organizations hit by ransomware in August 2026, annual record with +12% over previous month
- Payment rate crashed to 23% in Q2 2026, lowest level in six years
- Median payment jumped from approx. $12,700 (2024) to approx. $59,600 (2025), +368% YoY per Chainalysis
- Industrial sector absorbed 31% of August attacks, North America accounted for 44% of global total
August's Record and the Geography of Risk
The geographic distribution of August 2026 attacks leaves little room for ambiguity. North America accounted for 44% of incidents, Europe 26%, Asia 13%. The data is unsurprising: developed economies offer richer targets and more complex infrastructures to defend. The industrial sector was the most targeted at 31% of victims, followed by healthcare, education, and professional services.
Matt Hull, VP of cyber intelligence and response at NCC Group, commented: August was the second consecutive month of highest ransomware levels for the year, indicating a steady rise in global activity
. The same source had already recorded 3% growth in Q2 2026, with 2,229 global attacks. August's figure is no outlier: it is the acceleration of a trend.
Japan offers an instructive case study. The National Police Agency confirmed 123 ransomware cases in H1 2026, a record since 2020. Suspicious activity increased 50% year-over-year, with 13,687 anomalous communications detected daily. Despite the impressive growth, Japan ranks 14th globally in Forescout's ranking: up from a previous 28th place, but far from the peaks of cybercrime.
"Although there has not been a material rise in ransomware volume in the last quarter, the trajectory of attacks continues upwards" — Matt Hull, VP NCC Group
The Economic Paradox: More Attacks, Less Revenue
Ransomware is suffering a business-model crisis. Total on-chain revenue settled at approx. $820 million in 2025, down 8% from the prior year per Check Point Research. Criminals are hitting more targets but collecting less. The reason is twofold: victims have entrenched in non-payment positions, while operators have responded by raising the bar.
The median payment has exploded. Chainalysis, in its February 2026 Crypto Crime Report, recorded a jump from approx. $12,738 in 2024 to approx. $59,556 in 2025: +368% year-over-year. Sophos detected an even higher median in its 2026 sample: approx. $769,000 for victims suffering full encryption. The discrepancy between the two figures reflects different methodologies — Chainalysis tracks aggregate on-chain transactions, Sophos surveys victims with documented incidents — but the direction is identical: those who pay, pay far more.
The calculus is cynical. With 23% of victims paying versus 85% in 2019, groups must extract a higher multiple from the few remaining. Target selection becomes surgical. Hospitals, critical infrastructure, supply chains: targets that cannot afford downtime and that public perception renders more vulnerable to pressure.
Dominant Groups and Their Tactics
Qilin retained the crown of most active group for the fifth consecutive quarter, with 301 victims in Q2 2026 (14% of total) and 164 incidents in August alone. The Gentlemen logged 116 victims in the same month. Both operate on the RaaS (Ransomware-as-a-Service) model, with affiliates deploying the payload and operators managing negotiation and leak infrastructure.
Professionalization is total. Cisco Talos documented Qilin's use of EDR killer tools capable of terminating over 300 endpoint security drivers. Distribution to affiliates occurs through structured packages, with operational manuals and technical support. The privileged initial access vector in 2026 was VPNs and edge devices: NCC Group detected 15% of over 150 alerts on VPN vulnerabilities, with groups like Akira, Qilin, and The Gentlemen observed in action.
The Gentlemen introduced a touch of institutional sophistication: structured negotiations, professional communications, curated leak portals serving as showreels of damage. This is no longer the cybercrime of the early 2010s. It is an industry with division of labor, performance metrics, and continuous adaptation to countermeasures.
What to Do Now
- Verify security posture on VPNs and edge devices: 15% of NCC Group alerts in 2026 concerned vulnerabilities on this surface, with active groups observed in exploitation
- Review EDR detection capabilities in light of tools documented by Talos, capable of terminating over 300 security drivers
- Conduct tabletop exercises specific to ransomware scenarios with full encryption and data leak, as recommended in NCC guidelines
- Assess supply chain resilience: Q2 2026 data shows escalation in cascading compromises, with multi-organization impacts
The Criminal Market Adapts Faster Than Defenses
August 2026's record is no passing storm. It is the crystallization of a market that has learned to coexist with victim resistance, transforming payment scarcity into leverage for more brutal demands. The month's 1,073 attacks are distributed across a global industrial fabric increasingly dependent on digitized supply chains and increasingly unable to isolate damage.
The technical lesson is that asymmetry persists and amplifies. Defenders must protect every surface, every time. Attackers need find only one entry point, once. Be it an unpatched VPN, an outdated EDR driver, a compromised supply-chain credential. The 23% payment rate is a cultural victory, but the +368% on the median is the price the criminal market extracted for that victory.
FAQ
Why have payments fallen if attacks have increased?
The payment rate dropped to 23% in Q2 2026 because more organizations refuse to negotiate, backed by regulations, insurance, and preparedness. Groups responded by selecting high-value targets and exponentially raising demands for those who yield.
What is the difference between Chainalysis and Sophos payment data?
Chainalysis tracks aggregate on-chain transactions on public blockchains, reporting a median of approx. $59,600 for 2025. Sophos surveys victims with documented incidents and full encryption, detecting approx. $769,000 in 2026. Different methodologies explain the discrepancy.
Has Japan become a primary target for ransomware?
Not according to global rankings. Japan rose from 28th to 14th in Forescout's ranking, with significant growth but from a previously low base. The 123 H1 2026 cases represent a national record, not a top international position.
Sources
- https://www.infosecurity-magazine.com/news/ransomware-attacks-reach-record/
- https://www.itsecurityguru.org/2026/07/22/ransomware-attacks-rise-3-in-q2-as-supply-chain-compromises-escalate-ncc-group-warns/
- https://tech-insider.org/ransomware-2026-data-trends-group-ib/
- https://www.csoonline.com/article/4201372/ransomware-report.html
- https://www.japantimes.co.jp/news/2026/09/10/japan/crime-legal/ransomware-attack-record/
- https://tech-insider.org/japan-ransomware-cases-record-high-h1-2026/
- https://www.hipaajournal.com/healthcare-data-breach-statistics/
- https://www.securityweek.com/massachusetts-hospital-diverts-ambulances-as-cyberattack-causes-disruption/
- https://blog.talosintelligence.com/qilin-edr-killer/
Information verified against cited sources and current as of publication.
Sources
Get DeafLetter
A weekly selection of signals, vulnerabilities and guides. Critical alerts remain optional.
You can unsubscribe at any time. Privacy policy.