State of Ransomware: July 2026

Published 1 August 2026 · ThreatVectr Intelligence

895+29%
Claimed attacks
vs 696 the month before
61
Groups active
88
Countries affected
103
Busiest day
10 July

Ransomware groups claimed 895 attacks on organisations worldwide in July 2026, up 29% on the previous month's 696. 61 distinct groups posted at least one victim during the month, across 88 countries. The busiest single day was 10 July, with 103 victims listed.

The Gentlemen was the most active operation of the month, claiming 137 victims — 15% of all listings. Qilin (127) and DeadLock (84) followed. 7 groups appeared for the first time, including Crpxo, Global secret group, Section9, Exfilsquad.

Manufacturing bore the heaviest targeting, with 120 claimed victims, ahead of Technology (102) and Business Services (93). By geography, United States accounted for 301 claims — 34% of the month — with Germany (52) and United Kingdom (35) next.

Claims per day — July 2026

Most active groups

  1. 1The Gentlemen·137
  2. 2Qilin·127
  3. 3DeadLock2084
  4. 4DragonForce342
  5. 5INC Ransom·37
  6. 6CrpxoNew36
  7. 7SafePay232
  8. 8Global secret groupNew31
  9. 9Krybit225
  10. 10Akira623

First seen this month:Crpxo, Global secret group, Section9, Exfilsquad, Blackout, D1r, Gammax

Most-targeted sectors

  1. 1Manufacturing120
  2. 2Technology102
  3. 3Business Services93
  4. 4Healthcare77
  5. 5Financial Services53
  6. 6Professional Services52
  7. 7Agriculture and Food Production37
  8. 8Consumer Services30
  9. 9Other30
  10. 10Retail & E-Commerce29

Most-affected countries

  1. 1United States301
  2. 2Germany52
  3. 3United Kingdom35
  4. 4Brazil31
  5. 5Canada30
  6. 6Italy24
  7. 7Spain21
  8. 8India21
  9. 9France20
  10. 10Argentina19

Every figure in this report counts a claim posted to a criminal leak site, observed via the monitoring service ransomware.live. A listing is an extortion tactic, not a confirmed breach: some claims are exaggerated, some are duplicates under new branding, and a few are outright false. Companies named in listings have not necessarily confirmed any incident, and ThreatVectr does not publish victim names from this dataset.

Cite this report

This report is free to cite and reproduce with attribution. Suggested citation:

ThreatVectr, “State of Ransomware: July 2026”, https://threatvectr.com/ransomware-tracker/reports/july-2026

Journalists and researchers: for questions about the data or methodology, contact the newsdesk.

Most ransomware starts with one email

The groups in this report overwhelmingly get in through phishing. Train2Secure runs realistic phishing simulations and short training that teach your team to spot the lure.

Start free — no card required
© 2026 Threat Vectr