Ransomware gangs are going after VPNs, and an AI just ran its own attack
Ransomware attacks rose for the fourth month in a row in June, with criminals targeting the devices companies use to connect remote workers. A new AI-driven attack completed an entire break-in with no human at the keyboard.

Key points
- Ransomware attacks rose year-over-year for the fourth consecutive month in June 2026, according to NCC Group.
- The industrials sector absorbed 30% of all ransomware hits in Q2 2026, more than any other industry.
- Government bodies recorded 89 confirmed ransomware attacks in the first half of 2026, with US agencies accounting for 31% of those, per Comparitech.
- Researchers at Sysdig documented what they call the first known autonomous AI ransomware agent, dubbed JadePuffer, which carried out a full attack and left a Bitcoin ransom note without any human directing it.
- Criminals are increasingly breaking in through VPNs, the software tunnels companies use to let staff connect securely from home or on the road.
Who got hit, and how badly?
The industrials sector took the most punishment in Q2 2026, claiming 30% of all attacks. A single April attack on Signature Healthcare in Massachusetts shows what that looks like on the ground: ambulance services were disrupted, cancer treatment appointments were cancelled, and Brockton Hospital had to fall back on paper-based procedures for several weeks.
Healthcare was the fourth most targeted industry at 10% of Q2 attacks. Transportation, healthcare, retail, and technology all saw volumes climb over the past six months, by 52%, 35%, 28%, and 23% respectively, per Comparitech.
| Industry | Q2 2026 share of attacks | 6-month growth |
|---|---|---|
| Industrials | 30% | not reported |
| Consumer discretionary | 24% | not reported |
| Information technology | 11% | +23% |
| Healthcare | 10% | +35% |
| Transportation | not reported | +52% |
| Retail | not reported | +28% |
How are the criminals getting in?
VPNs are the front door attackers keep kicking. Targeted hardware includes products from Fortinet, Check Point, and Citrix. Security firm Arctic Wolf flagged an active Qilin campaign exploiting a vulnerability in Palo Alto Networks' GlobalProtect VPN.
Qilin and a newer outfit called The Gentlemen sit at the top of the activity charts for both Q2 2026 and the first half of the year. The Gentlemen is reportedly a Qilin splinter group. Both have started deploying "EDR killer" tools, software that disables the endpoint detection and response agents businesses run on their computers and servers. Affiliates must build or source their own EDR killers, which is a significant undertaking and a reliable signal of growing sophistication.
KryBit is worth watching too. We first covered it on 29 July 2026 when NCC Group flagged it as an emerging threat. It's a ransomware-as-a-service outfit, meaning criminals rent its tools to carry out their own campaigns, and it targets Windows, Linux, VMware ESXi virtualisation software, and NAS storage devices.
What is AI ransomware and should people be worried?
We covered JadePuffer on 2 July, when Sysdig first published its findings. The update here is context: June's overall attack numbers confirm the threat environment JadePuffer arrived into is getting busier, not quieter.
JadePuffer broke into a system, moved through the network, harvested credentials, encrypted files, deleted the originals, and dropped a Bitcoin ransom demand, firing off more than 600 separate attack actions. It used a large language model, the same underlying technology that powers AI chatbots, to adapt at each step. Sysdig called it "the first documented case of agentic ransomware."
This doesn't mean every attack tomorrow will be AI-driven. It means the bar for running a complex, adaptive campaign just dropped.
What should ordinary people do?
If your employer uses a VPN, apply any updates your IT team pushes without delay. Stolen credentials are the other main entry point, so a unique work password plus two-step verification, where a code is sent to your phone to confirm your identity, limits the blast radius if one password is ever exposed.



