New data from Comparitech disclosed a record 997 ransomware attacks worldwide in August 2026, averaging 32 attacks per day and representing a 23% increase from 809 attacks in July. The total surpassed the previous monthly record of 988 attacks recorded in February 2025. Businesses accounted for 861 attacks, up 24% from July, while ransomware incidents targeting healthcare providers rose 30% to 69. Utility companies recorded the sharpest sector increase, with attacks doubling from five in July to 10 in August.
Ransomware surge was led by Qilin and The Gentlemen, which together accounted for more than 26% of August’s attacks, with Qilin claiming 157 incidents and The Gentlemen 107. Qilin’s attack claims increased 22% during the month, while The Gentlemen’s declined 21%; Qilin also had 12 confirmed attacks, compared with eight for The Gentlemen.
Comparitech recorded 23% more attacks against manufacturers in August, with 12 confirmed incidents, while attacks against retailers increased 30%. Clop recorded the largest increase in claims, adding 45 victims to its site compared with one in July, with the attacks linked to exploitation of the PTC Windchill vulnerability.
“The healthcare sector saw a 30 percent increase in attacks, but utility companies saw the biggest spike,” Rebecca Moody, head of data research at Comparitech, wrote in a company blog post. “Here, attacks doubled, rising from five in July to 10 in August. Law firms (up 52%), tech companies (up 42%), and finance companies (up 40%) also saw significant increases. Education (down 4%) and the food and beverage sector (down 5%) were the only areas to see ransomware attacks decrease.”
Attacks on healthcare providers increased by 30% from July 2026 to August 2026, rising from 53 to 69. Eight attacks were confirmed in August. Three of the confirmed attacks took place in the U.S. Nutex Health Inc. noted unauthorized activity on its systems in a SEC filing on Aug. 24, 2026, and The Gentlemen claimed the attack. Cedar County Memorial Hospital experienced disruption to its IT networks on the afternoon of Aug. 14, 2026, with operations returning to normal on the morning of Aug. 28. Wallstreet claimed the attack. At Windrose Health Network, hackers exploited a vulnerability in the network’s remote-management tool in early August, resulting in a data breach. Storm claimed the attack.
Elsewhere, an attack on Canada’s Health Science Centre in Winnipeg affected certain facility maintenance systems, including door access, heating, ventilation and air conditioning. No hackers have claimed the attack. The group involved in an attack on Hvidovre Hospital in Denmark also remains unknown.
Rhysida issued SIA Medical Centre in Australia with a 6 bitcoin ($376,000) ransom demand, while Instituto Nacional de Cancerología (INCAN) in Guatemala confirmed that it had not met its hackers’ demands. KRYBIT claimed the attack on INCAN. INC also claimed an attack on Policlinico Triestino in Italy.
Attacks on government entities remained consistent in August, with 39 recorded compared with 38 in July 2026. Eighteen attacks in August have been confirmed to date.
Nine of the confirmed attacks took place in the U.S. The City of Coweta in Oklahoma and the City of Circleville in Ohio both confirmed they had not met their hackers’ demands, with the hackers remaining unknown in both cases. The City of Fort Scott in Kansas, whose hackers are unknown, and the City of Mitchell in South Dakota, whose attack was claimed by Storm, both noted nearly a week of disruptions due to the attacks.
The groups responsible for the attacks against Suisun City in California, the Town of Lincoln in Maine, and the City of Norcross in Georgia also remain unknown. Wallstreet claimed an attack on the Town of Andover, which disrupted schools in the area. Qilin claimed an attack on the Bureau of Alcohol, Tobacco, Firearms and Explosives (ATF).
Spain and Germany had two attacks each. In Spain, attacks on Gobierno de Castilla-La Mancha and Ayuntamiento de Velilla San Antonio were claimed by Panzer and Kairos, respectively. In Germany, unknown hackers targeted a memorial foundation, Stiftung Brandenburgische Gedenkstätten, while Rhysida issued the government of Berlin with a 30 bitcoin ($2.3 million) ransom demand for the deletion of 5.79 TB of data. Berlin refused the demand.
Attacks on the Commission de la construction du Québec in Canada, Ministerio de Justicia y del Derecho in Colombia, Municipality of Sithonia & Municipal Port Fund of Sithonia in Greece, Corte de Constitucionalidad in Guatemala, and Magyar Államkincstár Mezőgazdasági és Vidékfejlesztési (Nemzeti Kifizető Ügynökség) in Hungary were also confirmed. Ransomware groups are unknown in all cases except the Commission de la construction du Québec, for which Qilin claimed responsibility. From January to August 2026, 270 attacks on government entities were recorded, a similar figure to the 267 attacks noted during the same period in 2025. A total of 124 attacks have been confirmed in 2026 so far.
Comparitech recorded 861 attacks on businesses in August 2026, a 24% increase from 692 in July 2026. Forty-nine attacks were confirmed in August. As noted, attacks on utility companies doubled in August, with one attack confirmed to date. Italy’s Alto Calore Servizi S.p.A. confirmed an attack that was later claimed by Titan. This was not the first confirmed attack on the Italian water company. In August 2023, Medusa hit Alto Calore Servizi with a $100,000 ransom demand after breaching its systems.
Legal firms, finance companies and technology organizations also recorded significant increases in attacks, rising by 52%, 40% and 42%, respectively. None of the attacks on legal firms have been confirmed, while five attacks each targeting finance and technology companies were confirmed.
Five confirmed attacks on finance companies were TechVentures Bank SA in Romania, claimed by RansomHouse; Sawyer Savings Bank in the U.S., claimed by Storm; Dodo Payments in India, claimed by Dire Wolf; DC Partner in South Africa, claimed by KRYBIT; and Partners HoldCo, a.s. in the Czech Republic, where the hackers remain unknown.
Additionally, five confirmed attacks on technology companies were CEC Co., Ltd. in Japan, where the hackers remain unknown; Ambition DX Holdings Co., Ltd. in Japan, claimed by SETTRA, with 437 GB of data stolen; The AME Group in the U.S., where the hackers remain unknown; HostDzire in India, where the hackers remain unknown; and Cartrack in South Africa, claimed by Dire Wolf, with 100 GB of data stolen.
Attacks on retailers increased by 30%, while attacks on manufacturers rose by 23%. These two sectors also recorded the highest number of confirmed attacks in August 2026, with eight targeting retailers and 12 targeting manufacturers.
“Attacks in the US increased by 28 percent last month, which is likely due to the increase in attacks by Qilin. 34 percent of its claims were on US companies,” Moody detailed. “Italy and Taiwan saw the biggest increase in attacks. In Italy attacks jumped by 200 percent from 16 in July 2026 to 48 in August 2026. A 200 percent increase was also seen in Taiwan (up from 7 in July to 21 in August).”
She also revealed that Germany saw a 14% rise in attacks, while the U.K. saw a 44% increase. Attacks remained level in France. They declined by 3% in Canada and 20% in India.


