Ransomware Attacks in July 2026: Monthly Report

Ransomware Attacks in July 2026: Monthly Report

Which ransomware groups claimed the most victims in July 2026, how Qilin climbed back to tie for the top spot, and which countries and industries got hit hardest.

• There were 811 victims in July, up 15% from June’s 707 and the highest month of 2026 so far, just past March’s 808. The seven-month total is 5,101, on pace for roughly 8,700 by year-end, about 20% ahead of 2025.
• TheGentlemen and Qilin tied for the top spot with 119 victims each. Qilin jumped back from 71 in June, one month after losing the number one spot for the first time all year. June’s surprise, DeadLock, collapsed from 81 victims to 22.
• Healthcare stayed the most-targeted industry and climbed to 71 victims, its highest since February. Manufacturing kept sliding, down to 33 from 49. Construction and IT took the second and third spots.
• The US share of victims jumped back to 41% (330 of 811), up from 33% in June. The UK recovered from 16 victims to 33. Ransomware attacks affected only 78 countries, down from June’s 87.

July was the busiest month of 2026 so far, with 811 victims edging past March’s 808. But the real story was Qilin’s comeback.

We compiled this data from ransomware groups’ own leak sites where they publicly list victims. The numbers reflect claimed victims, not confirmed breaches. Some claims are exaggerated or misattributed.

66 distinct ransomware groups were active in July, up from 63 in June. The lineup near the top kept shifting: DeadLock, June’s surprise number two, fell almost as fast as it rose.

Here’s what the July 2026 numbers tell us.

July 2026 ransomware numbers at a glance

July set a new high for the year, with more groups active than in June.

Ransomware leak sites are dark web pages where ransomware operators publish stolen data from victims who refuse to pay. Many groups steal data and threaten to leak it. Some also encrypt files. A growing share, like ShinyHunters and WorldLeaks, skip encryption entirely and run pure data-extortion operations.

  • 811 victim companies claimed across ransomware leak sites
  • 66 active ransomware groups (up from 63 in June)
  • 78 countries affected (down from 87)
  • 65 industries represented (up from 62)
  • 15% increase from June’s 707 victims
  • 33% above the 2025 monthly average of 609

Seven months in, the 2026 total is 5,101 victims. That puts 2026 on pace for roughly 8,700, about 20% ahead of 2025’s total of 7,307.

Most active ransomware groups: July 2026

Qilin was the most active group for five straight months. It fell to third in June, then returned to first in July.

RankGroupVictimsChange from June
1TheGentlemen119+25
1Qilin119+48
3INC_RANSOM40+11
4DragonForce38+9
5CRPxO34new to top 10
6SafePay33+13
7KRYBIT25+4
8Akira22-8
8DeadLock22-59
10GlobalSecretGroup21new to top 10

The top 10 groups accounted for 473 victims (58.3%). The remaining 56 groups split the other 338. That’s a flatter spread than June’s 63.1%, even with the higher total.

TheGentlemen and Qilin tied at 119 victims each, the first tie for first place this year. TheGentlemen kept climbing, up from 94 in June and 70 in May. Qilin’s jump is the bigger one. It had 71 victims in June, its weakest month of the year, then climbed back to 119. That’s Qilin’s second-highest month of 2026, behind only March’s 131.

INC_RANSOM rose to third place with 40 victims, up from 29. It’s been in the top 10 all year without a standout month.

DragonForce climbed to 38 victims, up from 29. That’s its first gain after two straight months of decline.

CRPxO had the biggest jump of any group, to 34 victims. It was barely visible earlier in the year, then packed 29 of its 34 victims into the final week of July. Most of that came in a single week, so it might not hold.

Akira slipped again to 22 victims, down from 30. Its count keeps swinging with no clear direction.

DeadLock fell to 22 victims, down from 81. It came out of nowhere to reach second place in June. We said back then that a first month that big rarely holds, and it didn’t.

LockBit dropped back to 13 victims, down from 43. June’s rebound didn’t stick, so its recovery still looks shaky rather than steady.

Just outside the top 10: SETTRA (20), Everest (19) and Nova (18), with SETTRA doubling its June count of 10.

Countries most targeted by ransomware

June’s attacks reached more countries than any month this year. In July, more attacks happened in the US.

RankCountryVictims% of Total
1United States33040.7%
2Germany485.9%
3Canada364.4%
4United Kingdom334.1%
5France273.3%
6India243.0%
7Italy192.3%
8Spain172.1%
9Brazil172.1%
10Argentina151.8%

The US jumped back to 41% of all victims, up from 33% in June. The count rose from 234 to 330, more than any month this year.

Germany held second with 48 victims, up from 38. It’s been in the top two for months.

Canada climbed to third with 36 victims, up from 29, just ahead of the UK.

The UK recovered to 33 victims, up from 16. June’s drop to ninth place was the outlier; it’s back in its usual range now.

India slipped to 24 victims, down from 28, and Italy dropped to 19, down from 30.

78 countries were hit in total, down from 87 in June. Fewer countries, but more victims overall.

Industries hit hardest

Healthcare had the most victims again. Manufacturing kept falling. Construction and IT both rose.

Double extortion ransomware is an attack where criminals steal your data before encrypting it. If you restore from backups and refuse to pay, they threaten to publish the stolen data on leak sites. This makes backups alone an incomplete defense.

RankIndustryVictimsChange from June
1Healthcare71+17
2Construction49+5
3IT46new to top 10
4Consumer Goods38+3
5Finance37+12
6Technology37+9
7Manufacturing33-16
8Engineering31-2
9NonProfit28new to top 10
10Legal26-8

Healthcare kept the top spot and climbed to 71 victims, up from 54. That’s its highest month since February’s 93. Healthcare has been at or near number one all year. Its monthly totals this year: 40, 93, 47, 64, 54, 54, 71.

Manufacturing dropped to seventh place with 33 victims, down from 49. Its monthly totals since February: 94, 76, 50, 58, 49, 33.

Construction rose to second place with 49 victims, up from 44, and IT broke into the top three with 46 victims. Finance and Technology both climbed to 37 victims, with finance up from 25.

NonProfit reached 28 victims and broke into the top 10. Legal fell to 26 victims, down from 34. Its June rise didn’t hold.

65 industries were hit in total, up from 62 in June.

New and rising groups

CRPxO (34 victims): Barely active all year, then suddenly the month’s biggest surprise, almost all of it in the last week of July. That could mean a new crew getting started or a one-time dump. August will show which.

GlobalSecretGroup (21 victims): Another new face in the top 10, and one that stayed active right through the last week of the month. It’s worth watching to see if it holds.

SETTRA (20 victims): Up from 10 in June, its second double-digit month in a row after a quiet start to the year.

The number of active groups rose from 63 to 66. Which groups are most active still changes from month to month.

Month over month and YTD summary

MetricJanFebMarAprMayJunJulYTD Total
Total victims6776808087726467078115,101
Active groups58546570616366n/a
Countries hit60727579738778n/a
Industries hit61637272596265n/a
Top groupQilin (107)Qilin (104)Qilin (131)Qilin (103)Qilin (101)TheGentlemen (94)Tie: 119Qilin (736)

July’s 811 is the highest month of the year, ahead of March’s 808 and well above the 2025 monthly average of 609. Every month in 2026 has come in above it.

Even after June’s dip, Qilin still leads the year with 736 victims across seven months. TheGentlemen is second with 548, and DragonForce third with 315.

What security teams should do

The total number of victims hit a new high, but what you should do about it hasn’t changed.

A big month doesn’t mean a lasting threat. DeadLock jumped to 81 victims in June, then fell to 22 in July. CRPxO surged, jumping to 34 on the strength of a single week. Tracking groups by name is a losing game when a leader can vanish and a newcomer can spike in the space of a month.

Healthcare and construction are the top targets. Together they accounted for 120 victims in July, about 15% of the total. Healthcare has led or nearly led every month this year. If you’re in either sector, or you supply companies that are, the pressure isn’t letting up.

Check your credential exposure. Most ransomware attacks start with stolen credentials. Groups often buy their access from initial access brokers, who get those credentials from infostealer logs. There’s a gap of days to weeks between when credentials are stolen and when they’re used to deploy ransomware. Dark web monitoring catches those credentials in that window. You need to find your leaked credentials before attackers use them.

If ransomware gets through, don’t assume paying is your only option. No More Ransom has free decryptors for many strains, plus guidance on reporting the attack. Check there before you consider paying.

Methodology

This data reflects publicly claimed victims only. The actual number of attacks is higher because:

  • Many victims pay before being listed publicly
  • Some groups operate private negotiation channels without public leak sites
  • Not all ransomware attacks involve data theft or public claims

When multiple groups claim the same victim, we count it once for the total but list it under each claiming group in the per-group breakdown. Industry and country are based on the company’s primary business and headquarters.

July 2026 Ransomware FAQ

Breachsense tracked 811 companies listed on ransomware leak sites in July 2026, from 66 distinct groups across 78 countries. That’s the most of any month this year. The actual number of attacks is higher since many victims pay before being publicly listed.
TheGentlemen and Qilin were tied at 119 victims each. Qilin bounced back after falling to third place in June, and TheGentlemen kept climbing from 94 the month before. INC_RANSOM was a distant third with 40 victims.
The US accounted for 41% of all ransomware victims in July 2026 with 330 claims. Germany followed with 48 victims, Canada with 36, the UK with 33, and France with 27.
Healthcare was the most targeted sector in July 2026 with 71 victims, its highest since February. Construction followed with 49 victims and IT with 46. Manufacturing kept falling, down to 33.
Year to date, the seven-month total of 5,101 victims puts 2026 on pace for roughly 8,700 by year-end, up about 20% from 2025’s total of 7,307. July was the busiest month yet and ran well ahead of the 2025 monthly average of 609.
Many ransomware groups buy their way in from initial access brokers rather than breaking in themselves. Those brokers often get the credentials from infostealer malware logs. There’s usually a gap of days to weeks between when credentials are stolen and when ransomware gets deployed. Monitoring for leaked credentials can help you catch and reset them before attackers use them.