Ransomware Attacks in September 2026: Monthly Report
Which ransomware groups claimed the most victims in September 2026, what happened to the groups that joined the top 10 in August, and which countries and industries got hit hardest.
• There were 789 victims in September, down 18% from August’s 964, the highest month of 2026. That’s still 30% above the 2025 monthly average of 609. The nine-month total is 6,854, on pace for roughly 9,100 by year-end.
• TheGentlemen had the most victims with 98. Qilin’s count fell by more than half, from 157 to 75. Even so, its 2026 total of 968 already tops its full-year 2025 total of 958.
• The US share of victims fell to 41% (321 of 789). The UK had 12 victims, its lowest month of the year. Victims came from 88 countries, more than any month in 2026.
• Healthcare had the most victims for the fourth month in a row, with 89. IT tied Manufacturing for second with 53, IT’s highest count of the year.
Three of the five groups that entered the top 10 in August listed five victims or fewer in September. Orova went from 41 to 3, and CL0P from 39 to 3.
We compiled this data from ransomware groups’ own leak sites where they publicly list victims. The numbers reflect claimed victims, not confirmed breaches. Some claims are exaggerated or misattributed.
September 2026 ransomware numbers at a glance
- 789 victim companies claimed across ransomware leak sites
- 79 active ransomware groups (down from 83 in August)
- 88 countries affected (up from 78, the most of any month this year)
- 59 industries represented (down from 62)
- 18% decrease from August’s 964 victims
- 30% above the 2025 monthly average of 609 victims per month
Nine months in, the 2026 total is 6,854 victims. That puts 2026 on pace for roughly 9,100, about 25% ahead of 2025’s total of 7,307.
Most active ransomware groups: September 2026
| Rank | Group | Victims | Change from August |
|---|---|---|---|
| 1 | TheGentlemen | 98 | -29 |
| 2 | Qilin | 75 | -82 |
| 3 | INC_RANSOM | 40 | +4 |
| 4 | Akira | 39 | +12 |
| 5 | KRYBIT | 35 | 0 |
| 6 | Storm | 33 | -4 |
| 7 | SETTRA | 26 | new to top 10 |
| 7 | SafePay | 26 | new to top 10 |
| 9 | LockBit | 25 | new to top 10 |
| 10 | BrainCipher | 18 | new to top 10 |
| 10 | DireWolf | 18 | -22 |
| 10 | Panzer | 18 | new to top 10 |
| 10 | EMPERADOR | 18 | new to top 10 |
Of the 175-victim drop from August, 111 came from Qilin and TheGentlemen.
Qilin fell to 75 victims, down from 157. Only June, at 71, was lower this year. Even so, Qilin’s 2026 total of 968 has already passed the 958 victims it claimed in all of 2025.
TheGentlemen dropped from 127 to 98 and still had the most victims. It has 773 victims this year, more than ten times its 2025 total of 72.
INC_RANSOM had 40, up from 36. It has stayed between 29 and 46 victims all year. Akira rose to 39 from 27, its highest count since May’s 52.
KRYBIT matched August’s 35. It has been in the top 10 in five of the last six months.
BrainCipher, Panzer and EMPERADOR had 18 victims each, and Wallstreet and Vexy had 17. None of the five made our top 10 earlier this year.
Countries most targeted by ransomware
| Rank | Country | Victims | % of Total |
|---|---|---|---|
| 1 | United States | 321 | 40.7% |
| 2 | Canada | 30 | 3.8% |
| 3 | India | 27 | 3.4% |
| 4 | Germany | 25 | 3.2% |
| 5 | Spain | 24 | 3.0% |
| 6 | Brazil | 22 | 2.8% |
| 7 | France | 21 | 2.7% |
| 7 | Italy | 21 | 2.7% |
| 9 | Argentina | 13 | 1.6% |
| 10 | United Kingdom | 12 | 1.5% |
| 10 | Switzerland | 12 | 1.5% |
| 10 | South Africa | 12 | 1.5% |
The US share fell to 41%, down from 43% in August. The count dropped from 417 to 321.
Canada placed second for the first time this year with 30 victims, down from 37.
India rose to 27 victims, up from 23 and one short of its June high of 28. Spain had 24, its most in 2026.
Italy fell from 48 to 21. Germany dropped from 45 to 25.
The UK had 12 victims, its lowest of 2026. It was second in both January and February, with 43 and 44.
Brazil and Argentina both returned to the top 10, with 22 and 13 victims. Taiwan and Australia, new to the top 10 in August, both dropped out.
Industries hit hardest
| Rank | Industry | Victims | Change from August |
|---|---|---|---|
| 1 | Healthcare | 89 | -2 |
| 2 | IT | 53 | +24 |
| 2 | Manufacturing | 53 | +12 |
| 4 | Finance | 36 | -23 |
| 5 | Consumer Goods | 35 | -5 |
| 5 | Education | 35 | new to top 10 |
| 7 | Legal | 34 | -9 |
| 8 | Construction | 33 | -32 |
| 9 | Technology | 32 | -26 |
| 10 | Transportation | 25 | new to top 10 |
Healthcare had 89 victims, close to August’s 91, and ranked first for the fourth month in a row. Its 2026 total is now 603, more than the 538 it had in all of 2025.
IT had 53 victims, its highest count of 2026, up from 29 in August.
Education had 35 victims, its most this year, and entered the top 10.
Construction fell from 65 to 33, its lowest month of 2026. Finance fell from 59 to 36 and Technology from 58 to 32.
Machinery and Government dropped out of the top 10 with 24 victims each. Automotive dropped out with 22.
What happened to the groups that joined the top 10 in August?
Five groups that weren’t in July’s top 10 made it in August. In September only Storm (33) and DireWolf (18) are still there.
Orova fell from 41 to 3, CL0P from 39 to 3 and DarkProject from 24 to 5. August was Orova’s first month in our reports, and CL0P’s first top 10 month since February.
Month over month and YTD summary
| Metric | Jan | Feb | Mar | Apr | May | Jun | Jul | Aug | Sep | YTD Total |
|---|---|---|---|---|---|---|---|---|---|---|
| Total victims | 677 | 680 | 808 | 772 | 646 | 707 | 811 | 964 | 789 | 6,854 |
| Active groups | 58 | 54 | 65 | 70 | 61 | 63 | 66 | 83 | 79 | n/a |
| Countries hit | 60 | 72 | 75 | 79 | 73 | 87 | 78 | 78 | 88 | n/a |
| Industries hit | 61 | 63 | 72 | 72 | 59 | 62 | 65 | 62 | 59 | n/a |
| Top group | Qilin (107) | Qilin (104) | Qilin (131) | Qilin (103) | Qilin (101) | TheGentlemen (94) | Tie: 119 | Qilin (157) | TheGentlemen (98) | Qilin (968) |
Akira is third for the year with 412 victims, behind Qilin and TheGentlemen.
What security teams should do
When a company is hit with ransomware, the leaked files often include its clients’ data as well. The threat actor’s leak post doesn’t name those clients. Searching the text from the leaked files themselves for your data is the only reliable way to know whether (and how) you were affected by a vendor’s breach. Breachsense indexes the full text of those files so you can manage your third-party cyber risk.
Methodology
This data reflects publicly claimed victims only. The actual number of attacks is higher because:
- Many victims pay before being listed publicly
- Some groups operate private negotiation channels without public leak sites
- Not all ransomware attacks involve data theft or public claims
When multiple groups claim the same victim, we count it once for the total but list it under each claiming group in the per-group breakdown. Industry and country are based on the company’s primary business and headquarters.
This is part of a monthly threat brief series from Breachsense. See our August 2026 report for the previous month’s numbers. For the credentials stolen from infected machines and fake login pages, see our infostealer reports and phishing reports.
Breachsense is a dark web monitoring API for security teams and MSSPs who need to know when their own data, or a vendor’s, has already been stolen. Alongside stolen credentials and session tokens, it indexes the files ransomware groups leak, so teams can search them for their own company’s data. When a new leak matches a monitored term, such as a domain, Breachsense sends an email or webhook alert. Book a demo.
