State of Ransomware: July 2026
Published 1 August 2026 · ThreatVectr Intelligence
Ransomware groups claimed 976 attacks on organisations worldwide in July 2026, up 37% on the previous month's 712. 68 distinct groups posted at least one victim during the month, across 88 countries. The busiest single day was 10 July, with 104 victims listed.
The Gentlemen was the most active operation of the month, claiming 137 victims — 14% of all listings. Qilin (127) and DeadLock (84) followed. 10 groups appeared for the first time, including Global secret group, Crpxo, Majinahanashi, Section9.
Manufacturing bore the heaviest targeting, with 138 claimed victims, ahead of Technology (115) and Business Services (93). By geography, United States accounted for 333 claims — 34% of the month — with Germany (57) and United Kingdom (36) next.
Claims per day — July 2026
Most active groups
- 1The Gentlemen·13714%
- 2Qilin·12713%
- 3DeadLock20849%
- 4DragonForce4434%
- 5INC Ransom·374%
- 6CrpxoNew364%
- 7SafePay2323%
- 8Global secret groupNew313%
- 9Akira5253%
- 10Krybit1253%
First seen this month:Global secret group, Crpxo, Majinahanashi, Section9, Zawoo, Exfilsquad, Gammax, Blackout and 2 more
Most-targeted sectors
- 1Manufacturing138
- 2Technology115
- 3Business Services93
- 4Healthcare84
- 5Professional Services59
- 6Financial Services55
- 7Other40
- 8Agriculture and Food Production38
- 9Retail & E-Commerce37
- 10Consumer Services30
Most-affected countries
- 1United States333
- 2Germany57
- 3United Kingdom36
- 4Brazil33
- 5Canada32
- 6India27
- 7Italy27
- 8France22
- 9Spain21
- 10Argentina20
Every figure in this report counts a claim posted to a criminal leak site, observed via the monitoring service ransomware.live. A listing is an extortion tactic, not a confirmed breach: some claims are exaggerated, some are duplicates under new branding, and a few are outright false. Companies named in listings have not necessarily confirmed any incident, and ThreatVectr does not publish victim names from this dataset.
Cite this report
This report is free to cite and reproduce with attribution. Suggested citation:
ThreatVectr, “State of Ransomware: July 2026”, https://threatvectr.com/ransomware-tracker/reports/july-2026
Journalists and researchers: for questions about the data or methodology, contact the newsdesk.
Most ransomware starts with one email
The groups in this report overwhelmingly get in through phishing. Train2Secure runs realistic phishing simulations and short training that teach your team to spot the lure.