Ransomware Attacks in August 2026: Monthly Report
Which ransomware groups claimed the most victims in August 2026, how half the top 10 turned over in a single month, and which countries and industries got hit hardest.
• There were 964 victims in August, up 19% from July’s 811 and the highest month of 2026 by a wide margin. The eight-month total is 6,065, on pace for roughly 9,100 by year-end, about 25% ahead of 2025.
• Qilin took sole possession of first place with 157 victims, pulling ahead of TheGentlemen’s 119-119 tie from July. TheGentlemen still climbed to 127. Five of the top 10 groups, including a returning CL0P, weren’t in July’s top 10 at all.
• Healthcare stayed the most-targeted industry and climbed to 91 victims, its second-highest month of the year. Construction, Finance, and Technology all posted double-digit gains.
• The US share of victims grew to 43% (417 of 964). Italy more than doubled its count to jump from seventh to second place, ahead of Germany.
August broke the yearly record for total victims, but the bigger surprise was in the group rankings: half the top 10 weren’t there the month before.
We compiled this data from ransomware groups’ own leak sites where they publicly list victims. The numbers reflect claimed victims, not confirmed breaches. Some claims are exaggerated or misattributed.
83 distinct ransomware groups were active in August, the most of any month this year and up from 66 in July. CL0P returned to the top five after sitting out since February.
Here’s what the August 2026 numbers tell us.
August 2026 ransomware numbers at a glance
August set a new high for the year, with more active groups than any month before it.
Ransomware leak sites are dark web pages where ransomware operators publish stolen data from victims who refuse to pay. Many groups steal data and threaten to leak it. Some also encrypt files. A growing number, like ShinyHunters and WorldLeaks, skip encryption entirely and run pure data-extortion operations.
- 964 victim companies claimed across ransomware leak sites
- 83 active ransomware groups (up from 66 in July)
- 78 countries affected (unchanged from July’s count)
- 62 industries represented (down from 65)
- 19% increase from July’s 811 victims
- 58% above the 2025 monthly average of 609 victims per month
Eight months in, the 2026 total is 6,065 victims. That puts 2026 on pace for roughly 9,100, about 25% ahead of 2025’s total of 7,307.
Most active ransomware groups: August 2026
Qilin has held at least a share of the lead in seven of the year’s eight months. August was its most dominant month yet, with a 30-victim gap over second place.
| Rank | Group | Victims | Change from July |
|---|---|---|---|
| 1 | Qilin | 157 | +38 |
| 2 | TheGentlemen | 127 | +8 |
| 3 | Orova | 41 | new to top 10 |
| 4 | DireWolf | 40 | new to top 10 |
| 5 | CL0P | 39 | new to top 10 |
| 6 | Storm | 37 | new to top 10 |
| 7 | INC_RANSOM | 36 | -4 |
| 8 | KRYBIT | 35 | +10 |
| 9 | Akira | 27 | +5 |
| 10 | DarkProject | 24 | new to top 10 |
The top 10 groups accounted for 563 victims (58.4%), almost identical to July’s 58.3% despite 17 more groups being active. The remaining 73 groups split the other 401.
Half the top 10 is new. Orova, DireWolf, CL0P, Storm, and DarkProject weren’t in July’s top 10 (more on each below). That kind of turnover hasn’t happened in a single month before this year.
Qilin pulled ahead with 157 victims, up from the 119 it split with TheGentlemen in July. That’s Qilin’s best month of the year, ahead of March’s 131. TheGentlemen kept climbing too, to 127, its own high for 2026.
INC_RANSOM slipped to 36 victims, down from July’s 40. It’s swung between 29 and 46 all year without ever taking the top spot. KRYBIT climbed to 35, up from 25, its highest count of the year. Akira rose to 27, up from July’s 22, though its count has swung with no clear direction all year: 71, 39, 84, 48, 52, 30, 22, 27.
Just outside the top 10: CoinbaseCartel (22), Play and DragonForce (17 each). DragonForce fell hard from 38 in July, and DeadLock, June’s sudden number two, dropped to just 7.
Countries most targeted by ransomware
The US pulled further ahead this month, and Italy jumped into second place.
| Rank | Country | Victims | % of Total |
|---|---|---|---|
| 1 | United States | 417 | 43.3% |
| 2 | Italy | 48 | 5.0% |
| 3 | Germany | 45 | 4.7% |
| 4 | Canada | 37 | 3.8% |
| 5 | United Kingdom | 32 | 3.3% |
| 6 | France | 23 | 2.4% |
| 7 | India | 23 | 2.4% |
| 8 | Spain | 18 | 1.9% |
| 9 | Taiwan | 18 | 1.9% |
| 10 | Australia | 17 | 1.8% |
The US grew to 43% of all victims, up from 41% in July. The count rose from 330 to 417, its highest total of the year.
Italy jumped from seventh place to second, more than doubling from 19 victims to 48. That’s the sharpest rise of any country in the top 10 besides the US.
Germany held steady with 45 victims, close to July’s 48, its third straight month in the top three.
Canada climbed slightly to 37, and the UK settled at 32, down from July’s recovery to 33.
Taiwan and Australia both entered the top 10 with 18 and 17 victims. Brazil, ninth in July with 17, fell just outside the top 10 this month.
78 countries were hit in total, the same count as July. The list of which specific countries made the cut shifted, but the overall spread held steady.
Industries hit hardest
Healthcare kept the top spot by a wide margin. Finance and Technology both jumped, while IT fell out of the top 10 entirely.
Double extortion ransomware is an attack where criminals steal your data before encrypting it. If you restore from backups and refuse to pay, they threaten to publish the stolen data on leak sites. This makes backups alone an incomplete defense.
| Rank | Industry | Victims | Change from July |
|---|---|---|---|
| 1 | Healthcare | 91 | +20 |
| 2 | Construction | 65 | +16 |
| 3 | Finance | 59 | +22 |
| 4 | Technology | 58 | +21 |
| 5 | Legal | 43 | +17 |
| 6 | Manufacturing | 41 | +8 |
| 7 | Consumer Goods | 40 | +2 |
| 8 | Machinery | 39 | new to top 10 |
| 9 | Automotive | 32 | new to top 10 |
| 10 | Government | 31 | new to top 10 |
Healthcare climbed to 91 victims, up from 71. That’s its second-highest month of the year, behind only February’s 93. Healthcare’s monthly totals this year: 40, 93, 47, 64, 54, 54, 71, 91.
Construction rose to 65 victims, up from 49, holding second place for a second straight month.
Finance and Technology both posted their biggest jumps of the year, to 59 and 58 victims. Finance was fifth in July with 37; Technology was sixth with 37. Both roughly moved up two spots.
Legal rebounded to 43 victims, well past June’s 34 and July’s 26.
Machinery and Automotive entered the top 10 for the first time in 2026, at 39 and 32 victims. Government victims returned to the top 10 at 31, after dropping out in July.
IT fell out of the top 10 entirely, down to 29 victims from 46 in July. NonProfit dropped even further, to 14 from 28.
62 industries were hit in total, down from 65 in July.
New and rising groups
Orova (41 victims) and DireWolf (40 victims): Both went straight into the top five. Neither has appeared in a Breachsense monthly report before this month.
CL0P (39 victims): Back in the top 10 for the first time since February. CL0P built its reputation on mass exploitation of a single vulnerability across many victims at once, then going quiet for months. This is very similar to its 2026 activity: third place in January, third again in February, then absent until this month.
Storm (37 victims) and DarkProject (24 victims): Two more first-time top 10 entries.
The number of active groups jumped from 66 to 83, the highest count of the year.
Month over month and YTD summary
| Metric | Jan | Feb | Mar | Apr | May | Jun | Jul | Aug | YTD Total |
|---|---|---|---|---|---|---|---|---|---|
| Total victims | 677 | 680 | 808 | 772 | 646 | 707 | 811 | 964 | 6,065 |
| Active groups | 58 | 54 | 65 | 70 | 61 | 63 | 66 | 83 | n/a |
| Countries hit | 60 | 72 | 75 | 79 | 73 | 87 | 78 | 78 | n/a |
| Industries hit | 61 | 63 | 72 | 72 | 59 | 62 | 65 | 62 | n/a |
| Top group | Qilin (107) | Qilin (104) | Qilin (131) | Qilin (103) | Qilin (101) | TheGentlemen (94) | Tie: 119 | Qilin (157) | Qilin (893) |
August’s 964 is the highest month of the year by 153 victims over July’s previous record, and well above the 2025 monthly average of 609. Every month in 2026 has come in above that average.
Qilin leads the year with 893 victims across eight months. TheGentlemen is second with 675, and DragonForce third with 332.
What security teams should do
The total number of victims hit a new high, and so did the turnover among the top-ranked groups.
Naming this month’s leader doesn’t tell you much about next month. Five of August’s top 10 groups weren’t active enough to appear in July’s list at all. A new name can reach 40 victims in its first month, and a group that led one month can nearly vanish the next. What stays constant is the entry point most of them rely on: stolen credentials.
Healthcare and construction are the top targets. Together they accounted for 156 victims in August, about 16% of the total. Healthcare has finished first or second in six of the year’s eight months, including the last three in a row. If you’re in either sector, or you supply companies that are, the pressure isn’t letting up.
Check your credential exposure. Most ransomware attacks start with stolen credentials. Groups often buy their access from initial access brokers, who get those credentials from infostealer logs. There’s a gap of days to weeks between when credentials are stolen and when they’re used to deploy ransomware. Dark web monitoring catches those credentials in that window. You need to find your leaked credentials before attackers use them.
If ransomware gets through, don’t assume paying is your only option. No More Ransom has free decryptors for many strains, plus guidance on reporting the attack. Check there before you consider paying.
Methodology
This data reflects publicly claimed victims only. The actual number of attacks is higher because:
- Many victims pay before being listed publicly
- Some groups operate private negotiation channels without public leak sites
- Not all ransomware attacks involve data theft or public claims
When multiple groups claim the same victim, we count it once for the total but list it under each claiming group in the per-group breakdown. Industry and country are based on the company’s primary business and headquarters.
