State of Ransomware: July 2026
Published 1 August 2026 · ThreatVectr Intelligence
Ransomware groups claimed 895 attacks on organisations worldwide in July 2026, up 29% on the previous month's 696. 61 distinct groups posted at least one victim during the month, across 88 countries. The busiest single day was 10 July, with 103 victims listed.
The Gentlemen was the most active operation of the month, claiming 137 victims — 15% of all listings. Qilin (127) and DeadLock (84) followed. 7 groups appeared for the first time, including Crpxo, Global secret group, Section9, Exfilsquad.
Manufacturing bore the heaviest targeting, with 120 claimed victims, ahead of Technology (102) and Business Services (93). By geography, United States accounted for 301 claims — 34% of the month — with Germany (52) and United Kingdom (35) next.
Claims per day — July 2026
Most active groups
- 1The Gentlemen·13715%
- 2Qilin·12714%
- 3DeadLock20849%
- 4DragonForce3425%
- 5INC Ransom·374%
- 6CrpxoNew364%
- 7SafePay2324%
- 8Global secret groupNew313%
- 9Krybit2253%
- 10Akira6233%
First seen this month:Crpxo, Global secret group, Section9, Exfilsquad, Blackout, D1r, Gammax
Most-targeted sectors
- 1Manufacturing120
- 2Technology102
- 3Business Services93
- 4Healthcare77
- 5Financial Services53
- 6Professional Services52
- 7Agriculture and Food Production37
- 8Consumer Services30
- 9Other30
- 10Retail & E-Commerce29
Most-affected countries
- 1United States301
- 2Germany52
- 3United Kingdom35
- 4Brazil31
- 5Canada30
- 6Italy24
- 7Spain21
- 8India21
- 9France20
- 10Argentina19
Every figure in this report counts a claim posted to a criminal leak site, observed via the monitoring service ransomware.live. A listing is an extortion tactic, not a confirmed breach: some claims are exaggerated, some are duplicates under new branding, and a few are outright false. Companies named in listings have not necessarily confirmed any incident, and ThreatVectr does not publish victim names from this dataset.
Cite this report
This report is free to cite and reproduce with attribution. Suggested citation:
ThreatVectr, “State of Ransomware: July 2026”, https://threatvectr.com/ransomware-tracker/reports/july-2026
Journalists and researchers: for questions about the data or methodology, contact the newsdesk.
Most ransomware starts with one email
The groups in this report overwhelmingly get in through phishing. Train2Secure runs realistic phishing simulations and short training that teach your team to spot the lure.