A total of 799 ransomware attacks were recorded in July 2026 — averaging 26 per day — representing a 19 per cent increase from June and the second-highest monthly figure of the year, according to a Comparitech ransomware roundup. Ransomware groups show no sign of slowing, operating at high volume across multiple sectors including finance, healthcare, education, and critical infrastructure.
Which sectors are most targeted by ransomware in 2026?
Businesses remained the primary target in July 2026, accounting for 688 of the 799 recorded attacks. Finance companies saw a 71 per cent increase in ransomware attacks month-over-month, while tech companies experienced a 62 per cent rise. The education and healthcare sectors also recorded significant increases, underscoring that no industry is off-limits.
Ransomware is causing real-world physical disruption
Ransomware attackers are no longer limiting themselves to data theft — they are increasingly targeting organizations where stolen data or operational downtime creates maximum physical disruption and financial pressure.
Comparitech reports attacks against transport companies including Hahn Airport in Germany, Nihon Kotsu in Japan, and Stadler Rail in Switzerland. Stadler Rail confirmed the attack by ransomware group Everest but said it did not meet the group's $12.3 million ransom demand.
US dairy manufacturer Fairlife was also struck, with threat actor group Anubis allegedly causing "widespread disruption" and stealing 1 terabyte of data. The attack left Fairlife unable to resume operations for 10 days.
Third-party supply chain exposure remains a major attack vector. Healthcare billing software provider The Craneware Group confirmed a recent attack in which threat actor Anubis claims to have viewed and exfiltrated a "significant volume" of files — including 960 GB of data — potentially exposing not only Craneware's own data but that of its healthcare customers.
The Gentlemen: July 2026's most prolific ransomware gang
The most prolific ransomware gang of July 2026 was The Gentlemen — a group that ransomware research firm Halcyon describes as having "scaled faster than nearly any modern ransomware operation on record." Active since late 2025, The Gentlemen has already claimed nearly 300 victim organizations across more than 66 countries and 20 industries.
The group's growth rate is striking: in their first five months, The Gentlemen claimed the same number of victims it took top ransomware gang Qilin eighteen months to accumulate. The gang has compromised over 14,700 Fortigate devices worldwide and brute-forced nearly 1,000 VPN credentials — an "exceptionally large" stockpile that allows them to conduct sustained attacks without establishing new footholds each time.
Why is The Gentlemen ransomware group growing so fast?
The Gentlemen's rapid expansion is largely driven by a 90 per cent affiliate payout model — far above the industry norm — which attracts experienced operators and accelerates recruitment. The group actively recruits ransomware affiliates, penetration testers, and initial access brokers, pointing to a structured criminal ecosystem rather than an ad hoc operation.
How to defend against ransomware in 2026
To mitigate ransomware risk, cybersecurity firm Hyacin recommends that organizations take the following steps:
- Patch internet-facing systems promptly, particularly network appliances such as Fortigate devices
- Strengthen multi-factor authentication (MFA) enforcement and harden Active Directory security
- Assess the security posture of third-party providers with access to internal systems or sensitive data
With ransomware volumes at near-record highs and groups like The Gentlemen rapidly professionalizing their operations, organizations across all sectors face mounting pressure to close the gaps that attackers are actively exploiting.
