
Ransomware activity during July 2026 underscored the continued evolution of the threat landscape. What began as isolated malware campaigns has matured into a service-driven criminal ecosystem capable of sustaining large-scale operations across multiple regions and sectors. With 883 publicly disclosed victims (+21.3% versus June’s 728), activity rose sharply after the June dip and remained significantly above most historical baselines. This reflects the enduring effectiveness of ransomware-as-a-service (RaaS) models and intense competition among leading brands. The Gentlemen led monthly activity with 162 incidents, followed closely by Qilin (128). DragonForce, Incransom, the newly visible CRPxO and Global Secret Group, SafePay, Krybit, Akira, and Nova rounded out a volatile top tier. Organizations within Professional Goods & Services, Manufacturing, Real Estate & Construction, Information Technology, Consumer Goods & Services, and Healthcare experienced the highest levels of targeting.
This demonstrates attackers’ preference for environments where operational disruption, sensitive information exposure, and business continuity pressures can be leveraged to maximize extortion outcomes. The reporting period also highlighted several developments: rapid weaponization of edge and VPN flaws, production-system disruption as extortion leverage, compressed intrusion-to-encryption timelines, and the short-cycle launch of emerging leak-site brands. At the same time, data theft and timed public disclosure continued to expand as primary monetization mechanisms, often reducing dependence on encryption alone.
Collectively, these developments show that modern ransomware operations are becoming more persistent, intelligence-driven, and data-focused. In response, organizations should strengthen cyber resilience through improved identity security, edge-device hardening, accelerated remediation, enhanced visibility, supply-chain risk management, and proactive threat intelligence capabilities.
Welcome to the July 2026 Ransomware Threat Report. This report delivers a detailed analysis of the ransomware landscape, highlighting the emergence of new ransomware groups, evolving attack techniques, and notable shifts in targeted industries. By examining key trends, tactics, and significant incidents, this report aims to support organizations and security teams in understanding the current threat environment. As ransomware campaigns continue to grow in complexity, this report serves as a vital resource for anticipating future threats and strengthening proactive cybersecurity strategies.
Throughout July 2026, there was notable activity from several ransomware groups. Here are the trends regarding the top 10:

The June-July 2026 data indicates a sharp rebound and redistribution of ransomware activity across the threat landscape. The Gentlemen became the most active ransomware group, rising from 91 incidents in June to 162 in July (+78%). Qilin expanded from 78 to 128 (+64%), leaving the two groups running neck and neck at the top of the marketplace. DragonForce increased from 28 to 42, Incransom from 31 to 38, and SafePay from 21 to 33. Newly visible operators CRPxO (35) and Global Secret Group (31) entered the top tier with no comparable June footprint, illustrating how rapidly emerging leak-site brands can scale. Krybit edged up from 20 to 24, while Akira declined from 31 to 23 and Nova from 26 to 21. Outside the comparable top ten, LockBit 5.0 contracted sharply from 53 to 14 (-74%), underscoring continued volatility among established brands.
Overall, July shows that the RaaS ecosystem remains highly resilient: operational capacity shifted among leaders and newcomers rather than signaling any sustained decline in the overall ransomware threat.

In July 2026, ransomware activity continued to focus on sectors where operational disruption and data theft are most likely to maximize financial extortion. Professional Goods & Services was the most targeted industry with 139 incidents, followed closely by Manufacturing (137) and Real Estate & Construction (98). Information Technology (90), Consumer Goods & Services (77), and Healthcare (76) also experienced heavy targeting. Government & Civic (52), Finance (49), Materials (35), and Transportation & Logistics (33) recorded notable activity. Education (27), Telecommunications & Media (27), Automotive (20), and Energy & Utilities (19) saw moderate levels, and four victims remained unidentified (obfuscated). Month-over-month, Manufacturing (+34), Information Technology (+33), and Real Estate & Construction (+26) posted the largest absolute increases versus June.
Overall, the distribution indicates that ransomware operators continue to prioritize industries where business disruption, critical service dependencies, and the potential exposure of sensitive information can increase the likelihood of successful extortion.

Ransomware activity remained at historically elevated levels through mid-2026 and accelerated again in July. Publicly disclosed incidents totaled 883 in July, up from 728 in June. This exceeded April (801), March (775), February (694), and January (682). May 2026 (833) and July 2026 (883) now represent the highest monthly totals in the 2026 dataset to date, with July also surpassing the December 2025 peak of 801. Compared with July 2025 (500), year-over-year growth remains substantial (+76.6%). Individual months continue to fluctuate with affiliate tempo, disclosure timing, and brand rotation. Even so, the multi-year trend demonstrates that ransomware-as-a-service (RaaS) operations remain highly active and adaptable, with threat actors retaining the capability to rapidly scale campaigns across multiple industries and geographic regions.

Ransomware activity in July 2026 remained geographically concentrated in the United States, which recorded 334 publicly disclosed incidents. This total far exceeded any other country and reinforced the country’s position as the primary target for ransomware operations. A second tier of affected countries included Germany (48), Canada (43), and the United Kingdom (34), followed by France (28), India (28), and Brazil (23). Beyond these leaders, activity extended across 79 identified countries in total. These included Spain (19), Italy (19), Argentina (18), Turkey (16), Australia (15), China (13), Singapore (13), and the Czech Republic (12), along with many additional markets across Europe, Asia-Pacific, Latin America, the Middle East, and Africa at lower but consistent volumes. Fifteen victims remained unidentified (obfuscated).
Overall, geographic distribution shows that ransomware operators continue to prioritize digitally mature economies while sustaining a broad international footprint across nearly every major region.
Expansion of Ransomware Leverage Through Production-System Disruption
This incident demonstrates the continued evolution of ransomware from data-centric extortion toward direct disruption of industrial production as a primary pressure mechanism. According to public reporting, the threat actor group Anubis is alleged to have targeted Fairlife, a dairy subsidiary of The Coca-Cola Company. The group reportedly gained unauthorized access to systems that included production-related infrastructure, forcing a temporary suspension of manufacturing operations across Fairlife’s United States facilities. Rather than relying solely on encryption to coerce payment, the operators combined operational downtime with the alleged theft of approximately one terabyte of data and subsequently published the stolen materials after the victim declined to negotiate.
The campaign illustrates how ransomware groups increasingly target high-value manufacturing subsidiaries within multinational enterprises. In such cases, halted production, regulatory disclosure obligations, and public data leakage collectively maximize financial, operational, and reputational impact.
ETLM Assessment:
Ransomware groups are expected to continue prioritizing organizations where operational downtime creates immediate business pressure beyond traditional data-theft extortion. Future campaigns are likely to focus on production systems, plant operations, and tightly coupled IT environments that support manufacturing continuity, particularly within subsidiaries of large multinational brands. Attackers are increasingly forcing public regulatory disclosures and following through on data publication when ransoms are unpaid. In response, organizations should strengthen segmentation between IT and operational technology, validate recovery procedures for production environments, and prepare dual incident-response tracks that cover both operational restoration and data-leak containment.
Acceleration of Vulnerability-Driven Ransomware Operations Against Edge Access Infrastructure
This activity demonstrates the evolution of ransomware operations toward near-immediate weaponization of newly disclosed vulnerabilities in enterprise remote access platforms. Following the disclosure of critical flaws in SonicWall Secure Mobile Access appliances, tracked as CVE-2026-15409 and CVE-2026-15410, threat actors chained the vulnerabilities to obtain root-level access on internet-facing VPN appliances. They then harvested credentials, session databases, and multi-factor authentication seed material, and used the compromised appliances as stealthy beachheads into internal networks. Subsequent public reporting associated active weaponization of the exploit chain with INC ransomware operations, citing observed credential theft, lateral movement originating from appliance infrastructure, and progression to ransomware deployment in affected environments.
This reflects a broader shift in which ransomware ecosystems convert perimeter appliance weaknesses into scalable initial access pipelines. By compromising trusted remote access gateways, operators and affiliates can bypass traditional endpoint-focused defenses.
ETLM Assessment:
Ransomware operators are likely to further accelerate vulnerability-to-exploitation timelines against VPN appliances, firewalls, remote access gateways, and other internet-facing management platforms, where a single compromise can expose privileged authentication paths. Future campaigns may increasingly combine zero-day and n-day edge-device exploitation with credential harvesting, session theft, and rapid lateral movement to shorten the window between access and ransomware deployment. Organizations should treat edge appliances as crown-jewel assets.
That means continuous external monitoring, aggressive patching, credential and session rotation after suspected compromise, and detection of anomalous authentication originating directly from appliance infrastructure.
Industrialization of Emerging Extortion Brands Through Rapid Leak-Site Expansion
This activity highlights the continued evolution of the ransomware ecosystem toward rapid brand formation and concentrated leak-site victimization. Multiple newly observed operators, including CRPxO, Global Secret Group, D1R, DOOMMAGEDDON, ExfilSquad, GAMMAX, and Wallstreet, appeared on public data-leak platforms during the month. This reflects an increasingly fluid marketplace in which new extortion brands can generate visibility within days of emerging. CRPxO exemplifies the shift: it initially concentrated claims against United States dental and healthcare-related targets before expanding into IT providers, professional services, financial firms, and aviation-linked organizations through batch victim disclosures.
Rather than gradually building reputation over extended periods, emerging groups increasingly rely on niche-to-broad targeting pivots and high-tempo leak-site campaigns to establish presence alongside mature Ransomware-as-a-Service brands.
ETLM Assessment:
The ransomware ecosystem is expected to continue producing short-cycle brand launches, whose apparent significance may be driven as much by concentrated disclosure campaigns as by sustained operational maturity. Emerging groups that begin in a narrow sector niche and quickly pivot into IT, professional services, and other high-value verticals are likely to remain a recurring pattern. Defenders should prioritize detection of shared intrusion behaviors over brand names alone, while continuously monitoring leak sites for newly appearing operators. Groups that maintain multi-week activity and cross-sector reach after their debut are expected to warrant closer scrutiny as potentially durable threats rather than one-time disclosure spikes.
Competitive Dual Leadership Within a High-Volume Ransomware Marketplace
This development highlights the continued maturation of ransomware into a highly competitive service marketplace, in which multiple established brands can simultaneously sustain large-scale victimization. Dashboard telemetry for July recorded 883 publicly disclosed incidents. The Gentlemen led at 162 victims, and Qilin followed closely at 128, while mid-tier and newly visible operators, including DragonForce, Incransom, CRPxO, SafePay, and Global Secret Group, further distributed activity across the broader ecosystem. Professional Goods & Services and Manufacturing remained the most targeted industries, and the United States accounted for the largest share of victims.
This combination of elevated volume, two brands leading in close competition, and fragmented participation underscores that aggregate ransomware risk continues to rise even as individual brand rankings remain volatile.
ETLM Assessment:
Overall ransomware and extortion volume is expected to remain elevated. It is driven by abundant initial access opportunities, rapid brand formation, and continued competition among mature Ransomware-as-a-Service platforms. Organizations should plan for sustained exposure rather than interpreting any single brand’s monthly position as a reliable predictor of near-term risk. Strategic defenses should emphasize identity security, edge-device hardening, rapid response to credential exposure, and resilience measures that assume both encryption-driven disruption and pure data-leak extortion outcomes.
Compression of Ransomware Execution Timelines Across Enterprise Environments
This incident demonstrates the continued evolution of ransomware operations toward highly compressed intrusion timelines, in which attackers progress from initial foothold to enterprise-wide encryption with minimal delay. According to public incident reporting, threat actors used a single compromised Microsoft IIS web server as an initial beachhead and deployed a previously unseen ransomware payload across the victim network in under 24 hours. Rather than depending on prolonged dwell time alone, the intrusion followed a rapid multi-stage path of internet-facing application compromise, persistence, lateral movement, and detonation. This reflects a broader shift in which modern ransomware campaigns increasingly optimize for speed, reducing the window available for detection and containment before encryption or operational disruption occurs.
ETLM Assessment:
Ransomware operators are expected to further compress attack timelines by combining automated discovery, commodity post-exploitation tooling, and pre-validated access paths that minimize hands-on delay between foothold and encryption. Organizations whose detection and response processes operate on multi-day investigation cycles will face increasing difficulty interrupting these intrusions. Defenders should prioritize continuous exposure management for internet-facing applications, rapid containment of beachhead systems, and behavioral detection tuned for early lateral movement, rather than waiting for ransomware execution indicators alone.
Amplification of Healthcare Extortion Through Service-Provider and Clinic Targeting
This activity highlights the continued evolution of ransomware campaigns against healthcare ecosystems, where attacks on clinics, dental practices, and healthcare-adjacent service providers amplify impact beyond any single care-delivery organization. Healthcare remained a heavily claimed ransomware target sector during the month. Emerging operators such as CRPxO concentrated early activity against United States dental offices and later expanded claims across additional healthcare and professional services entities. By compromising environments that aggregate patient records, billing data, and operational information, attackers increase regulatory exposure, notification obligations, and extortion leverage across multiple downstream organizations at once. This reflects a matured targeting model in which healthcare intermediaries and clinic networks are valued not only for their sensitive data density but also for their ability to propagate impact across interconnected care ecosystems.
ETLM Assessment:
Healthcare and healthcare-adjacent service providers are expected to remain priority targets, because a single compromise can expose patient data, disrupt care delivery, and create multi-organization notification obligations. Future campaigns are likely to continue blending direct hospital and clinic targeting with attacks on billing firms, dental networks, and other intermediaries that aggregate records across multiple covered entities. Sector defenses should emphasize identity protection, segmented clinical systems, vendor risk management, immutable backups, and rapid detection of data-staging activity within environments that hold multi-tenant patient information.
Continued Law Enforcement Pressure Against Social-Engineering Extortion Ecosystems
This development highlights the continued evolution of ransomware-adjacent extortion ecosystems under sustained law enforcement pressure, which targets operators who rely on social engineering and identity abuse rather than novel malware alone. According to public reporting, individuals linked to Scattered Spider activity were sentenced in the United Kingdom in connection with the Transport for London cyberattack, an intrusion characterized by helpdesk manipulation, credential abuse, and large-scale operational disruption. While prosecutions remove specific operators from the ecosystem, the underlying techniques remain transferable to replacement actors and continue to complement financially motivated ransomware and extortion campaigns. This reflects a broader dynamic in which judicial disruption of high-profile social-engineering crews coexists with persistent reuse of the same identity-centric intrusion methods across the cybercriminal marketplace.
ETLM Assessment:
Law enforcement actions are expected to continue removing individual operators from social-engineering and ransomware-adjacent ecosystems. However, technique-level risk will persist as new actors reuse helpdesk fraud, multi-factor authentication fatigue, and credential abuse methods. Organizations should treat high-profile prosecutions as confirmation of enduring tradecraft rather than evidence of reduced near-term threat. Hardened identity verification for helpdesk resets, phishing-resistant authentication, and monitoring for anomalous privileged access remain essential controls against the same intrusion patterns associated with Scattered Spider-style operations.
Evolution of Multi-Layered Extortion Through Timed Data Publication
This activity demonstrates the continued evolution of ransomware from encryption-focused disruption toward sequenced, multi-layered extortion designed to sustain leverage across the full incident lifecycle. In the Fairlife campaign, Anubis combined production outages and ransom demands with the timed public release of allegedly stolen materials after the victim declined to negotiate, converting an operational incident into a prolonged data-exposure event. Newly active groups similarly used leak-site claims of exfiltrated healthcare and enterprise datasets to establish credibility and intensify pressure on victims. By sequencing encryption, operational downtime, regulatory disclosure pressure, and public data dumps, ransomware operators are increasingly treating stolen information as a durable monetization asset, independent of whether systems can be restored from backups.
ETLM Assessment:
Ransomware groups are likely to continue expanding extortion models beyond conventional encryption, combining operational disruption with timed data publication, selective disclosure, and reputational pressure tailored to each victim. Future campaigns may increasingly assume that refusal to pay will still result in public data exposure, prolonging legal, regulatory, and reputational consequences after technical recovery. Organizations should strengthen data governance, limit bulk access to sensitive repositories, and detect unusual exfiltration. They should also prepare communications and regulatory response plans that address leak-driven extortion, even when encryption is successfully mitigated.
Based on available public reports, approximately 31% of enterprises are compelled to halt their operations, either temporarily or permanently, in the aftermath of a ransomware attack. The ripple effects extend beyond operational disruption. The additional metrics below are drawn from available public and industry reporting and are indicative rather than precise:
Ransomware remains a major threat to both organizations and individuals, locking critical data and demanding payment for its release. The consequences extend well beyond the ransom, often leading to costly recovery efforts, extended downtime, reputational harm, and potential regulatory fines. Such disruptions can destabilize operations and erode stakeholder trust. Addressing this growing risk demands a proactive cybersecurity posture and stronger collaboration between public and private sectors to build resilience against future attacks.
Cybercriminals are increasingly targeting industries that manage vast amounts of sensitive data, ranging from personal and financial information to proprietary assets. Sectors such as professional services, manufacturing, real estate and construction, healthcare, information technology, consumer services, finance, and government remain high on the threat radar, owing to their complex and extensive digital infrastructures. Adversaries strategically exploit vulnerabilities in economically advanced regions, especially the United States. Their well-planned attacks are designed to encrypt critical systems, disrupt production, and extract significant ransom payments, and are calculated to yield maximum financial returns.
Ransomware in July 2026 is no longer a discrete cyber incident. It has become an enduring, multi-stage business threat that blends cybercrime, industrial disruption, and economic coercion. The month’s 883 publicly disclosed incidents, the closely matched leadership of The Gentlemen and Qilin, and the rapid appearance of emerging brands such as CRPxO and Global Secret Group confirm that operational capacity continues to redistribute without reducing overall risk.
The continued separation of access, execution, and extortion, combined with edge-appliance exploitation, compressed attack timelines, production-system leverage, and timed data publication, has significantly eroded the effectiveness of exploit-centric and signature-driven defenses alone. For organizations, resilience in this environment will depend less on preventing every individual intrusion and more on identity and edge hardening, governance readiness, third-party risk management, early lateral-movement detection, and executive decision preparedness for both encryption and leak-driven outcomes. As ransomware groups continue to evolve toward stealth, speed, and psychological leverage, proactive external threat landscape management and cross-functional response planning will be critical to reducing both operational impact and long-term business risk.
The assessments and recommendations in this report are based on the intelligence available at the time of writing and on publicly disclosed victim data, which may be incomplete or subject to revision. Their effectiveness will depend on each organization’s own security controls, monitoring, and operating environment.