// ZDNET — CYBERSECURITY
July was the worst month for ransomware victim claims in 2026 - or was it?
Follow ZDNET: Add us as a preferred source on Google.
New NCC Group research says that July 2026 saw a spike in ransomware activity, with a year-to-date record of 894 victim listings recorded in the month alone. But what's actually behind it?
Also: Why this fully agentic ransomware attack is giving researchers nightmares
According to NCC Group's July threat advisory report, published on Wednesday, global ransomware attacks increased by 22% in July 2026, compared to June 2026. This was also when the first incident of a fully agentic AI ransomware attack chain was also recorded.
Almost a third of attacks were launched against the industrial sector. Other popular targets were consumer services and technology, critical services, finance, and healthcare. In total, 41% of recorded incidents occurred in the US; 29% in Europe, 14% in Asia, and 9% in South America.
NCC Group data reveals that 10 cybercriminal groups were attributed to most of these ransomware attacks against businesses, ranked as follows:
Also: What is ransomware? Everything you need to know and how to reduce your risk
Numbers are one thing, but high rates don't automatically mean severe attacks or even successful extortion. However, there were some notable incidents in July.
The reputation of a cybercriminal group, especially one that has just emerged, is based not just on the ransomware it uses or the service it offers -- known as Ransomware-as-a-Service (RaaS) -- but also on how many victims it has claimed and which organizations they are.
Also: A low-tech solution from the past may be your best defense against AI deepfakes