
AI-generated editorial illustration by CyberShitty. Not a photograph or a document from the organisations named.
Trackers counted between 997 and 1,168 claimed victims in August, a 2026 high, with Qilin and The Gentlemen far ahead. Only a small share of those claims had been confirmed by victims.
01 / The numbers
August 2026 was the busiest month of the year so far for ransomware leak-site claims, according to several trackers, but they do not agree on how busy. According to Comparitech, 997 attacks were recorded in August, 23% more than the 809 it logged for July and above its previous monthly record of 988 set in February 2025. ThreatVectr counted 1,114 claimed victims, up 14% on its July figure of 976, spread across 83 groups and 80 countries. NCC Group recorded 1,073 attacks, a 12% month-on-month rise and its highest monthly total of 2026.
The live statistics page at ransomware.live showed 1,168 victims for August against 954 for July when we checked on 29 September, the highest month on its 2026 chart; that page updates continuously and its figures can change as late posts are indexed. The spread between the lowest and highest count is 171 victims, which is a reminder that each tracker collects, de-duplicates and dates listings differently.
02 / Claims are not confirmed victims
Most of these numbers come from posts on criminal leak sites, where gangs name organisations to pressure them into paying. A listing is a threat, not proof. Groups recycle old data, re-list victims of other gangs, inflate what they took, or name organisations they never breached. ThreatVectr says plainly that a listing is an extortion tactic rather than a confirmed breach.
A thousand leak-site posts is a measure of extortion pressure, not a count of verified breaches.
Comparitech separates the two. Of its 997 August attacks, only 77 had been confirmed by the affected organisation at the time of publication; the other 920 rested on the gang's word alone. Of the confirmed attacks, 49 hit businesses, 18 government bodies, eight healthcare providers and two education institutions, according to Comparitech.
03 / Who was most active
Every tracker put Qilin first and The Gentlemen second. Comparitech attributed 157 attacks to Qilin and 107 to The Gentlemen, together more than a quarter of the month's total. NCC Group counted 164 and 116, ThreatVectr 165 and 116, and AhnLab's ASEC 167 and 112. Qilin's lead follows June, when Comparitech's half-year report noted that The Gentlemen briefly overtook it.
Behind them the rankings diverge. ThreatVectr and NCC Group both placed Cl0p third, with 88 and 89 listings respectively, largely from its data-theft campaign against PTC Windchill and FlexPLM servers. ASEC instead listed Orova, Dark_Project and Akira next, while NCC Group named Dire Wolf and INC Ransom with 43 incidents each. ThreatVectr counted 11 groups posting for the first time.
04 / Notable attacks
- ATF. Qilin listed the US Bureau of Alcohol, Tobacco, Firearms and Explosives on its leak site. The agency confirmed a breach of a standalone system holding information on investigation targets and declared a major incident, The Record reported. Our coverage.
- Cl0p and Windchill. By 19 August, Cl0p had named more than 40 organisations it said it breached through CVE-2026-12569, including Shell, Philips and Fiserv, SecurityWeek reported. Several said they were investigating; none had confirmed a significant breach at that point.
- Boston Scientific. The medical device maker detected an attack on 25 August that disrupted manufacturing and shipping and later said it is unlikely to meet 2026 guidance. HIPAA Journal reported that no group had claimed it and ransomware had not been confirmed. Our coverage.
- CEVA Logistics. An intrusion notified to clients on 1 August affected eight European warehouses and exposed shipping data for retailers and Steam customers. The Record said it was unclear whether ransomware was deployed. Our coverage.
- Manchester Airports Group. The operator disclosed on 27 August that customer booking data had been accessed from a third-party-hosted database; the FulcrumSec extortion group claimed the theft, according to SecurityWeek.
05 / Sectors, countries and law enforcement
Manufacturing led ThreatVectr's sector ranking with 172 claims, followed by technology (141), professional services (127) and healthcare (113). NCC Group said the industrial sector accounted for 31% of attacks. Comparitech recorded a 30% rise in healthcare attacks to 69, and a doubling of attacks on utilities from five to ten.
The United States remained the main target: 417 attacks according to Comparitech and 373 according to ThreatVectr, while NCC Group put North America at 44% and Europe at 26%. Germany, Italy and the UK followed in both Comparitech's and ThreatVectr's country lists.
On the enforcement side, the US Justice Department announced on 5 August that Maksim Silnikau, the Belarusian creator of the Ransom Cartel ransomware service, had been sentenced to 16 years in prison. Prosecutors said the operation attacked at least 18 companies between 2021 and 2023.
06 / What defenders should prioritise
- Patch internet-facing enterprise applications first. The Windchill campaign shows data-theft crews targeting business software, not just VPNs and firewalls.
- Audit customer data held in third-party-hosted databases; MAG said the data taken sat in a database hosted by a third party.
- Treat a leak-site listing as a lead to investigate, not a verdict, and verify claims against your own logs before responding.
- Keep offline backups and tested restores, and plan for extortion that involves theft alone, with no encryption.
- Map which suppliers hold your customer data; CEVA showed one provider's breach becoming many clients' notification problem.
Source log / 2026-0929-RR
- Comparitech — Ransomware roundup: August 2026 (8 Sep 2026) Primary
- ThreatVectr — State of ransomware: August 2026 (1 Sep 2026) Primary
- NCC Group — Monthly Threat Pulse: review of August (23 Sep 2026) Primary
- Ransomware.live — 2026 statistics (accessed 29 Sep 2026) Primary
- AhnLab ASEC — August 2026 threat trend report on ransomware (23 Sep 2026) Primary
- Comparitech — Ransomware roundup: H1 2026 (2 Jul 2026) Secondary
- SecurityWeek — Cl0p ransomware group names over 40 victims of PTC Windchill campaign (19 Aug 2026) Secondary
- The Record — DOJ firearms agency says hackers breached system containing investigation targets (27 Aug 2026) Secondary
- HIPAA Journal — Boston Scientific unlikely to meet 2026 sales and profit forecast due to cyberattack (Sep 2026) Secondary
- The Record — Cyberattack on logistics giant Ceva hits retailers and Steam customers across Europe (Aug 2026) Secondary
- SecurityWeek — Extortion group claims Manchester Airports Group data breach (31 Aug 2026) Secondary
- US DOJ (EDVA) — Belarusian leader of 'Ransom Cartel' sentenced to 16 years in prison (5 Aug 2026) Primary