Ransomware Attacks in September 2026: Monthly Report

Ransomware Attacks in September 2026: Monthly Report

Which ransomware groups claimed the most victims in September 2026, what happened to the groups that joined the top 10 in August, and which countries and industries got hit hardest.

• There were 789 victims in September, down 18% from August’s 964, the highest month of 2026. That’s still 30% above the 2025 monthly average of 609. The nine-month total is 6,854, on pace for roughly 9,100 by year-end.
• TheGentlemen had the most victims with 98. Qilin’s count fell by more than half, from 157 to 75. Even so, its 2026 total of 968 already tops its full-year 2025 total of 958.
• The US share of victims fell to 41% (321 of 789). The UK had 12 victims, its lowest month of the year. Victims came from 88 countries, more than any month in 2026.
• Healthcare had the most victims for the fourth month in a row, with 89. IT tied Manufacturing for second with 53, IT’s highest count of the year.

Three of the five groups that entered the top 10 in August listed five victims or fewer in September. Orova went from 41 to 3, and CL0P from 39 to 3.

We compiled this data from ransomware groups’ own leak sites where they publicly list victims. The numbers reflect claimed victims, not confirmed breaches. Some claims are exaggerated or misattributed.

September 2026 ransomware numbers at a glance

  • 789 victim companies claimed across ransomware leak sites
  • 79 active ransomware groups (down from 83 in August)
  • 88 countries affected (up from 78, the most of any month this year)
  • 59 industries represented (down from 62)
  • 18% decrease from August’s 964 victims
  • 30% above the 2025 monthly average of 609 victims per month

Nine months in, the 2026 total is 6,854 victims. That puts 2026 on pace for roughly 9,100, about 25% ahead of 2025’s total of 7,307.

Most active ransomware groups: September 2026

RankGroupVictimsChange from August
1TheGentlemen98-29
2Qilin75-82
3INC_RANSOM40+4
4Akira39+12
5KRYBIT350
6Storm33-4
7SETTRA26new to top 10
7SafePay26new to top 10
9LockBit25new to top 10
10BrainCipher18new to top 10
10DireWolf18-22
10Panzer18new to top 10
10EMPERADOR18new to top 10

Of the 175-victim drop from August, 111 came from Qilin and TheGentlemen.

Qilin fell to 75 victims, down from 157. Only June, at 71, was lower this year. Even so, Qilin’s 2026 total of 968 has already passed the 958 victims it claimed in all of 2025.

TheGentlemen dropped from 127 to 98 and still had the most victims. It has 773 victims this year, more than ten times its 2025 total of 72.

INC_RANSOM had 40, up from 36. It has stayed between 29 and 46 victims all year. Akira rose to 39 from 27, its highest count since May’s 52.

KRYBIT matched August’s 35. It has been in the top 10 in five of the last six months.

BrainCipher, Panzer and EMPERADOR had 18 victims each, and Wallstreet and Vexy had 17. None of the five made our top 10 earlier this year.

Countries most targeted by ransomware

RankCountryVictims% of Total
1United States32140.7%
2Canada303.8%
3India273.4%
4Germany253.2%
5Spain243.0%
6Brazil222.8%
7France212.7%
7Italy212.7%
9Argentina131.6%
10United Kingdom121.5%
10Switzerland121.5%
10South Africa121.5%

The US share fell to 41%, down from 43% in August. The count dropped from 417 to 321.

Canada placed second for the first time this year with 30 victims, down from 37.

India rose to 27 victims, up from 23 and one short of its June high of 28. Spain had 24, its most in 2026.

Italy fell from 48 to 21. Germany dropped from 45 to 25.

The UK had 12 victims, its lowest of 2026. It was second in both January and February, with 43 and 44.

Brazil and Argentina both returned to the top 10, with 22 and 13 victims. Taiwan and Australia, new to the top 10 in August, both dropped out.

Industries hit hardest

RankIndustryVictimsChange from August
1Healthcare89-2
2IT53+24
2Manufacturing53+12
4Finance36-23
5Consumer Goods35-5
5Education35new to top 10
7Legal34-9
8Construction33-32
9Technology32-26
10Transportation25new to top 10

Healthcare had 89 victims, close to August’s 91, and ranked first for the fourth month in a row. Its 2026 total is now 603, more than the 538 it had in all of 2025.

IT had 53 victims, its highest count of 2026, up from 29 in August.

Education had 35 victims, its most this year, and entered the top 10.

Construction fell from 65 to 33, its lowest month of 2026. Finance fell from 59 to 36 and Technology from 58 to 32.

Machinery and Government dropped out of the top 10 with 24 victims each. Automotive dropped out with 22.

What happened to the groups that joined the top 10 in August?

Five groups that weren’t in July’s top 10 made it in August. In September only Storm (33) and DireWolf (18) are still there.

Orova fell from 41 to 3, CL0P from 39 to 3 and DarkProject from 24 to 5. August was Orova’s first month in our reports, and CL0P’s first top 10 month since February.

Month over month and YTD summary

MetricJanFebMarAprMayJunJulAugSepYTD Total
Total victims6776808087726467078119647896,854
Active groups585465706163668379n/a
Countries hit607275797387787888n/a
Industries hit616372725962656259n/a
Top groupQilin (107)Qilin (104)Qilin (131)Qilin (103)Qilin (101)TheGentlemen (94)Tie: 119Qilin (157)TheGentlemen (98)Qilin (968)

Akira is third for the year with 412 victims, behind Qilin and TheGentlemen.

What security teams should do

When a company is hit with ransomware, the leaked files often include its clients’ data as well. The threat actor’s leak post doesn’t name those clients. Searching the text from the leaked files themselves for your data is the only reliable way to know whether (and how) you were affected by a vendor’s breach. Breachsense indexes the full text of those files so you can manage your third-party cyber risk.

Methodology

This data reflects publicly claimed victims only. The actual number of attacks is higher because:

  • Many victims pay before being listed publicly
  • Some groups operate private negotiation channels without public leak sites
  • Not all ransomware attacks involve data theft or public claims

When multiple groups claim the same victim, we count it once for the total but list it under each claiming group in the per-group breakdown. Industry and country are based on the company’s primary business and headquarters.

This is part of a monthly threat brief series from Breachsense. See our August 2026 report for the previous month’s numbers. For the credentials stolen from infected machines and fake login pages, see our infostealer reports and phishing reports.

Breachsense is a dark web monitoring API for security teams and MSSPs who need to know when their own data, or a vendor’s, has already been stolen. Alongside stolen credentials and session tokens, it indexes the files ransomware groups leak, so teams can search them for their own company’s data. When a new leak matches a monitored term, such as a domain, Breachsense sends an email or webhook alert. Book a demo.

September 2026 Ransomware FAQ

Breachsense tracked 789 companies listed on ransomware leak sites in September 2026, down from 964 in August. They were claimed by 79 distinct groups and came from 88 countries. The actual number of attacks is higher since many victims pay before being publicly listed.
TheGentlemen led with 98 victims, down from 127 in August. Qilin placed second with 75, less than half its August count of 157. INC_RANSOM was third with 40.
The US accounted for 41% of all ransomware victims in September 2026 with 321 claims. Canada followed with 30 victims, India with 27, Germany with 25 and Spain with 24.
Healthcare was the most targeted sector in September 2026 with 89 victims, its fourth month in a row in first place. IT and Manufacturing tied for second with 53 each.
Yes. At 6,854 victims after nine months, 2026 is on pace for roughly 9,100, about 25% more than 2025’s 7,307. Every month this year has topped the 2025 monthly average of 609.
Many ransomware groups buy access from initial access brokers instead of breaking in themselves. Those brokers get many of the logins they sell from infostealer malware logs. The same logs often hold session tokens, so when you reset a leaked password, also terminate that user’s sessions.