Ransomware Attacks in August 2026: Monthly Report

Ransomware Attacks in August 2026: Monthly Report

Which ransomware groups claimed the most victims in August 2026, how half the top 10 turned over in a single month, and which countries and industries got hit hardest.

• There were 964 victims in August, up 19% from July’s 811 and the highest month of 2026 by a wide margin. The eight-month total is 6,065, on pace for roughly 9,100 by year-end, about 25% ahead of 2025.
• Qilin took sole possession of first place with 157 victims, pulling ahead of TheGentlemen’s 119-119 tie from July. TheGentlemen still climbed to 127. Five of the top 10 groups, including a returning CL0P, weren’t in July’s top 10 at all.
• Healthcare stayed the most-targeted industry and climbed to 91 victims, its second-highest month of the year. Construction, Finance, and Technology all posted double-digit gains.
• The US share of victims grew to 43% (417 of 964). Italy more than doubled its count to jump from seventh to second place, ahead of Germany.

August broke the yearly record for total victims, but the bigger surprise was in the group rankings: half the top 10 weren’t there the month before.

We compiled this data from ransomware groups’ own leak sites where they publicly list victims. The numbers reflect claimed victims, not confirmed breaches. Some claims are exaggerated or misattributed.

83 distinct ransomware groups were active in August, the most of any month this year and up from 66 in July. CL0P returned to the top five after sitting out since February.

Here’s what the August 2026 numbers tell us.

August 2026 ransomware numbers at a glance

August set a new high for the year, with more active groups than any month before it.

Ransomware leak sites are dark web pages where ransomware operators publish stolen data from victims who refuse to pay. Many groups steal data and threaten to leak it. Some also encrypt files. A growing number, like ShinyHunters and WorldLeaks, skip encryption entirely and run pure data-extortion operations.

  • 964 victim companies claimed across ransomware leak sites
  • 83 active ransomware groups (up from 66 in July)
  • 78 countries affected (unchanged from July’s count)
  • 62 industries represented (down from 65)
  • 19% increase from July’s 811 victims
  • 58% above the 2025 monthly average of 609 victims per month

Eight months in, the 2026 total is 6,065 victims. That puts 2026 on pace for roughly 9,100, about 25% ahead of 2025’s total of 7,307.

Most active ransomware groups: August 2026

Qilin has held at least a share of the lead in seven of the year’s eight months. August was its most dominant month yet, with a 30-victim gap over second place.

RankGroupVictimsChange from July
1Qilin157+38
2TheGentlemen127+8
3Orova41new to top 10
4DireWolf40new to top 10
5CL0P39new to top 10
6Storm37new to top 10
7INC_RANSOM36-4
8KRYBIT35+10
9Akira27+5
10DarkProject24new to top 10

The top 10 groups accounted for 563 victims (58.4%), almost identical to July’s 58.3% despite 17 more groups being active. The remaining 73 groups split the other 401.

Half the top 10 is new. Orova, DireWolf, CL0P, Storm, and DarkProject weren’t in July’s top 10 (more on each below). That kind of turnover hasn’t happened in a single month before this year.

Qilin pulled ahead with 157 victims, up from the 119 it split with TheGentlemen in July. That’s Qilin’s best month of the year, ahead of March’s 131. TheGentlemen kept climbing too, to 127, its own high for 2026.

INC_RANSOM slipped to 36 victims, down from July’s 40. It’s swung between 29 and 46 all year without ever taking the top spot. KRYBIT climbed to 35, up from 25, its highest count of the year. Akira rose to 27, up from July’s 22, though its count has swung with no clear direction all year: 71, 39, 84, 48, 52, 30, 22, 27.

Just outside the top 10: CoinbaseCartel (22), Play and DragonForce (17 each). DragonForce fell hard from 38 in July, and DeadLock, June’s sudden number two, dropped to just 7.

Countries most targeted by ransomware

The US pulled further ahead this month, and Italy jumped into second place.

RankCountryVictims% of Total
1United States41743.3%
2Italy485.0%
3Germany454.7%
4Canada373.8%
5United Kingdom323.3%
6France232.4%
7India232.4%
8Spain181.9%
9Taiwan181.9%
10Australia171.8%

The US grew to 43% of all victims, up from 41% in July. The count rose from 330 to 417, its highest total of the year.

Italy jumped from seventh place to second, more than doubling from 19 victims to 48. That’s the sharpest rise of any country in the top 10 besides the US.

Germany held steady with 45 victims, close to July’s 48, its third straight month in the top three.

Canada climbed slightly to 37, and the UK settled at 32, down from July’s recovery to 33.

Taiwan and Australia both entered the top 10 with 18 and 17 victims. Brazil, ninth in July with 17, fell just outside the top 10 this month.

78 countries were hit in total, the same count as July. The list of which specific countries made the cut shifted, but the overall spread held steady.

Industries hit hardest

Healthcare kept the top spot by a wide margin. Finance and Technology both jumped, while IT fell out of the top 10 entirely.

Double extortion ransomware is an attack where criminals steal your data before encrypting it. If you restore from backups and refuse to pay, they threaten to publish the stolen data on leak sites. This makes backups alone an incomplete defense.

RankIndustryVictimsChange from July
1Healthcare91+20
2Construction65+16
3Finance59+22
4Technology58+21
5Legal43+17
6Manufacturing41+8
7Consumer Goods40+2
8Machinery39new to top 10
9Automotive32new to top 10
10Government31new to top 10

Healthcare climbed to 91 victims, up from 71. That’s its second-highest month of the year, behind only February’s 93. Healthcare’s monthly totals this year: 40, 93, 47, 64, 54, 54, 71, 91.

Construction rose to 65 victims, up from 49, holding second place for a second straight month.

Finance and Technology both posted their biggest jumps of the year, to 59 and 58 victims. Finance was fifth in July with 37; Technology was sixth with 37. Both roughly moved up two spots.

Legal rebounded to 43 victims, well past June’s 34 and July’s 26.

Machinery and Automotive entered the top 10 for the first time in 2026, at 39 and 32 victims. Government victims returned to the top 10 at 31, after dropping out in July.

IT fell out of the top 10 entirely, down to 29 victims from 46 in July. NonProfit dropped even further, to 14 from 28.

62 industries were hit in total, down from 65 in July.

New and rising groups

Orova (41 victims) and DireWolf (40 victims): Both went straight into the top five. Neither has appeared in a Breachsense monthly report before this month.

CL0P (39 victims): Back in the top 10 for the first time since February. CL0P built its reputation on mass exploitation of a single vulnerability across many victims at once, then going quiet for months. This is very similar to its 2026 activity: third place in January, third again in February, then absent until this month.

Storm (37 victims) and DarkProject (24 victims): Two more first-time top 10 entries.

The number of active groups jumped from 66 to 83, the highest count of the year.

Month over month and YTD summary

MetricJanFebMarAprMayJunJulAugYTD Total
Total victims6776808087726467078119646,065
Active groups5854657061636683n/a
Countries hit6072757973877878n/a
Industries hit6163727259626562n/a
Top groupQilin (107)Qilin (104)Qilin (131)Qilin (103)Qilin (101)TheGentlemen (94)Tie: 119Qilin (157)Qilin (893)

August’s 964 is the highest month of the year by 153 victims over July’s previous record, and well above the 2025 monthly average of 609. Every month in 2026 has come in above that average.

Qilin leads the year with 893 victims across eight months. TheGentlemen is second with 675, and DragonForce third with 332.

What security teams should do

The total number of victims hit a new high, and so did the turnover among the top-ranked groups.

Naming this month’s leader doesn’t tell you much about next month. Five of August’s top 10 groups weren’t active enough to appear in July’s list at all. A new name can reach 40 victims in its first month, and a group that led one month can nearly vanish the next. What stays constant is the entry point most of them rely on: stolen credentials.

Healthcare and construction are the top targets. Together they accounted for 156 victims in August, about 16% of the total. Healthcare has finished first or second in six of the year’s eight months, including the last three in a row. If you’re in either sector, or you supply companies that are, the pressure isn’t letting up.

Check your credential exposure. Most ransomware attacks start with stolen credentials. Groups often buy their access from initial access brokers, who get those credentials from infostealer logs. There’s a gap of days to weeks between when credentials are stolen and when they’re used to deploy ransomware. Dark web monitoring catches those credentials in that window. You need to find your leaked credentials before attackers use them.

If ransomware gets through, don’t assume paying is your only option. No More Ransom has free decryptors for many strains, plus guidance on reporting the attack. Check there before you consider paying.

Methodology

This data reflects publicly claimed victims only. The actual number of attacks is higher because:

  • Many victims pay before being listed publicly
  • Some groups operate private negotiation channels without public leak sites
  • Not all ransomware attacks involve data theft or public claims

When multiple groups claim the same victim, we count it once for the total but list it under each claiming group in the per-group breakdown. Industry and country are based on the company’s primary business and headquarters.

August 2026 Ransomware FAQ

Breachsense tracked 964 companies listed on ransomware leak sites in August 2026, from 83 distinct groups across 78 countries. That’s the most of any month this year. The actual number of attacks is higher since many victims pay before being publicly listed.
Qilin led with 157 victims, breaking its July tie with TheGentlemen, which climbed to 127. Orova placed third with 41 victims in its first month appearing in the top 10.
The US accounted for 43% of all ransomware victims in August 2026 with 417 claims. Italy followed with 48 victims, Germany with 45, Canada with 37, and the UK with 32.
Healthcare was the most targeted sector in August 2026 with 91 victims, its second-highest month of the year. Construction followed with 65 victims and Finance with 59.
Year to date, the eight-month total of 6,065 victims puts 2026 on pace for roughly 9,100 by year-end, up about 25% from 2025’s total of 7,307. August was the busiest month yet and ran 58% ahead of the 2025 monthly average of 609.
Many ransomware groups buy their way in from initial access brokers rather than breaking in themselves. Those brokers often get the credentials from infostealer malware logs. There’s usually a gap of days to weeks between when credentials are stolen and when ransomware gets deployed. Monitoring for leaked credentials can help you catch and reset them before attackers use them.