ITSecurityGuru

Global cyber attacks up 48% as ransomware and phishing climb, Check Point finds


Organisations worldwide faced an average of 2,803 cyber attacks per week in September 2026, up 16% on August and 48% on the same month last year, according to new data from Check Point Research.

The figures point to sustained growth rather than a one-off spike. Weekly attacks per organisation have climbed 36% in five months, from 2,055 in May.

UK organisations faced an average of 1,920 attacks per week, a 50% increase year on year. Europe recorded the fastest growth of any region, with attacks up 61%, while Latin America faced the highest volume at 3,813 weekly attacks per organisation, followed by Africa (3,701) and APAC (3,593).

“September’s data shows cyber risk increasing in both volume and breadth,” said Barnaby Nickels, regional manager for exposure management (UKI & North EU) at Check Point.

Education hit hardest as term begins

Education was again the most targeted sector, averaging 6,656 weekly attacks per organisation. That is up 59% year on year and 24% on August, the second-highest monthly rise of any industry, as students, staff and parents reconnected to institutional networks at the start of the academic year. Telecommunications ranked second globally with 3,483 weekly attacks (up 29%), followed by Government with 3,443 (up 37%).

The picture was similar in the UK, where Education and Government were the two most targeted sectors, followed by Media & Entertainment, Energy & Utilities and Software.

The Gentlemen tops ransomware rankings

A total of 824 ransomware attacks were published on double-extortion groups’ leak sites in September, 53% more than in September 2025. The Gentlemen was the most prolific group, responsible for 13% of published attacks, ahead of Qilin (9%) and Akira (5%). A further 80 extortion groups also posted victims during the month.

The Gentlemen is a fast-growing ransomware-as-a-service (RaaS) operation founded in mid-2025. It operates as both a RaaS provider and an initial access broker, and supports Windows, Linux and ESXi environments.

Business Services accounted for 31.3% of reported victims, followed by Consumer Goods & Services (15.2%) and Industrial Manufacturing (11.0%). Because business services providers often hold data or system access on behalf of multiple clients, a single incident can spread well beyond the organisation first hit. North America accounted for 46% of reported incidents, Europe 25% and APAC 17%.

Phishing more frequent, and mostly link-based

One in every 91 emails (1.1%) was classified as phishing in September, up from 1 in 112 (0.89%) in August. Malicious links remained the main delivery method, appearing in 81% of phishing emails, while 11% carried attachments and the rest relied on social engineering alone.

Associations & Nonprofits saw the highest phishing rate at 2.17%, or 1 in 46 emails, roughly double the global average. Construction & Engineering followed at 2.05% (1 in 49) and Real Estate, Rentals & Leasing at 1.38% (1 in 72). North America was the most affected region, with 1 in 79 emails classified as malicious.

GenAI prompts exposing infrastructure details

Enterprise GenAI use continued to expand, with the average user generating 131 prompts in September and each organisation using an average of eight tools. One in every 39 prompts posed a high risk of sensitive data leakage, affecting 89% of organisations that regularly use GenAI. A further 14% of prompts contained potentially sensitive information.

Network and IT infrastructure data was the most commonly exposed category, observed in prompts at 71% of organisations. This includes hardware and network configurations and IP addresses, details that could give attackers valuable insight into an internal environment. It was followed by financial data (70%), legal and regulatory data (68%), employee and HR data (62%) and personally identifiable information (60%).

By industry, Business Services had the highest high-risk prompt rate at 1 in 20, followed by Financial Services (1 in 25) and Healthcare & Medical (1 in 29).

“With attacks rising across every region, phishing becoming more frequent, ransomware remaining elevated and GenAI use expanding alongside sensitive-data exposure, security teams cannot rely on fragmented defences. They need prevention-first protection that combines visibility, control and automation across network, cloud, endpoint, email and AI usage to stop threats before they disrupt operations or expose sensitive information,” concludes Nickels.

The full September 2026 report is available here: https://blog.checkpoint.com/research/september-2026-cyber-threat-landscape-global-attacks-jump-48-as-phishing-and-genai-data-exposure-rise/



Source link