State of Ransomware: August 2026
Published 1 September 2026 · ThreatVectr Intelligence
Ransomware groups claimed 1,072 attacks on organisations worldwide in August 2026, up 10% on the previous month's 972. 83 distinct groups posted at least one victim during the month, across 80 countries. The busiest single day was 5 August, with 99 victims listed.
Qilin was the most active operation of the month, claiming 165 victims — 15% of all listings. The Gentlemen (113) and Cl0p (88) followed. 12 groups appeared for the first time, including Storm, Zawoo, Panzer, Emperador.
Manufacturing bore the heaviest targeting, with 165 claimed victims, ahead of Technology (138) and Professional Services (122). By geography, United States accounted for 360 claims — 34% of the month — with Germany (61) and United Kingdom (48) next.
Claims per day — August 2026
Most active groups
- 1Qilin116515%
- 2The Gentlemen111311%
- 3Cl0p60888%
- 4DirewolfNew434%
- 5INC Ransom·434%
- 6StormNew414%
- 7Krybit2363%
- 8Akira2303%
- 9Orova22262%
- 10Coinbasecartel29242%
First seen this month:Storm, Zawoo, Panzer, Emperador, Barracuda, Helix, Dysphor1a, Iah6477 and 4 more
Most-targeted sectors
- 1Manufacturing165
- 2Technology138
- 3Professional Services122
- 4Healthcare105
- 5Other100
- 6Financial Services65
- 7Retail & E-Commerce61
- 8Transportation37
- 9Agriculture and Food Production35
- 10Energy & Utilities28
Most-affected countries
- 1United States360
- 2Germany61
- 3United Kingdom48
- 4Italy48
- 5Canada26
- 6Brazil23
- 7Mexico23
- 8France20
- 9India19
- 10Australia17
Every figure in this report counts a claim posted to a criminal leak site, observed via the monitoring service ransomware.live. A listing is an extortion tactic, not a confirmed breach: some claims are exaggerated, some are duplicates under new branding, and a few are outright false. Companies named in listings have not necessarily confirmed any incident, and ThreatVectr does not publish victim names from this dataset.
Cite this report
This report is free to cite and reproduce with attribution. Suggested citation:
ThreatVectr, “State of Ransomware: August 2026”, https://threatvectr.com/ransomware-tracker/reports/august-2026
Journalists and researchers: for questions about the data or methodology, contact the newsdesk.
Most ransomware starts with one email
The groups in this report overwhelmingly get in through phishing. Train2Secure runs realistic phishing simulations and short training that teach your team to spot the lure.