State of Ransomware: August 2026

Published 1 September 2026 · ThreatVectr Intelligence

1,072+10%
Claimed attacks
vs 972 the month before
83
Groups active
80
Countries affected
99
Busiest day
5 August

Ransomware groups claimed 1,072 attacks on organisations worldwide in August 2026, up 10% on the previous month's 972. 83 distinct groups posted at least one victim during the month, across 80 countries. The busiest single day was 5 August, with 99 victims listed.

Qilin was the most active operation of the month, claiming 165 victims — 15% of all listings. The Gentlemen (113) and Cl0p (88) followed. 12 groups appeared for the first time, including Storm, Zawoo, Panzer, Emperador.

Manufacturing bore the heaviest targeting, with 165 claimed victims, ahead of Technology (138) and Professional Services (122). By geography, United States accounted for 360 claims — 34% of the month — with Germany (61) and United Kingdom (48) next.

Claims per day — August 2026

Most active groups

  1. 1Qilin1165
  2. 2The Gentlemen1113
  3. 3Cl0p6088
  4. 4DirewolfNew43
  5. 5INC Ransom·43
  6. 6StormNew41
  7. 7Krybit236
  8. 8Akira230
  9. 9Orova2226
  10. 10Coinbasecartel2924

First seen this month:Storm, Zawoo, Panzer, Emperador, Barracuda, Helix, Dysphor1a, Iah6477 and 4 more

Most-targeted sectors

  1. 1Manufacturing165
  2. 2Technology138
  3. 3Professional Services122
  4. 4Healthcare105
  5. 5Other100
  6. 6Financial Services65
  7. 7Retail & E-Commerce61
  8. 8Transportation37
  9. 9Agriculture and Food Production35
  10. 10Energy & Utilities28

Most-affected countries

  1. 1United States360
  2. 2Germany61
  3. 3United Kingdom48
  4. 4Italy48
  5. 5Canada26
  6. 6Brazil23
  7. 7Mexico23
  8. 8France20
  9. 9India19
  10. 10Australia17

Every figure in this report counts a claim posted to a criminal leak site, observed via the monitoring service ransomware.live. A listing is an extortion tactic, not a confirmed breach: some claims are exaggerated, some are duplicates under new branding, and a few are outright false. Companies named in listings have not necessarily confirmed any incident, and ThreatVectr does not publish victim names from this dataset.

Cite this report

This report is free to cite and reproduce with attribution. Suggested citation:

ThreatVectr, “State of Ransomware: August 2026”, https://threatvectr.com/ransomware-tracker/reports/august-2026

Journalists and researchers: for questions about the data or methodology, contact the newsdesk.

Most ransomware starts with one email

The groups in this report overwhelmingly get in through phishing. Train2Secure runs realistic phishing simulations and short training that teach your team to spot the lure.

Start free — no card required
© 2026 Threat Vectr