Cybersecurity

Global Ransomware Attacks Hit Record High as August Sees 997 Incidents

0

Global ransomware activity reached a new monthly high in August 2026, with 997 publicly reported attacks worldwide, according to new research from Comparitech. The figure represents a 23% increase from July’s 809 attacks and surpasses the previous record of 988 incidents recorded in February 2025.

The latest numbers indicate that ransomware continues to expand despite years of investment in endpoint security, backup systems and incident-response capabilities.

Businesses Remain the Main Target

Businesses accounted for the overwhelming majority of reported incidents in August, with 861 attacks, up 24% from July.

That concentration reflects the economic logic behind ransomware.

Criminal groups continue to target organizations where operational disruption can quickly translate into financial pressure. Companies facing halted production, inaccessible systems or disrupted customer services may be more willing to negotiate with attackers when the cost of downtime becomes significant.

The growing number of attacks also means organizations are facing a wider range of ransomware operators rather than a small group of dominant criminal organizations.

Healthcare Attacks Also Increased

Healthcare organizations experienced a particularly notable increase.

Comparitech recorded 69 ransomware attacks against healthcare organizations in August, representing a 30% increase compared with July.

Healthcare remains an attractive target because hospitals and medical providers depend heavily on digital systems for patient records, scheduling, diagnostics, communications and administrative operations.

Even a partial outage can have immediate operational consequences.

That makes healthcare organizations especially vulnerable to extortion because attackers can create significant pressure without necessarily needing to steal enormous quantities of data.

Critical Infrastructure Faces Continued Pressure

The latest ransomware figures also highlight increasing pressure on essential services.

Utilities and other critical sectors remain attractive targets because disruption can create consequences that extend beyond a single organization.

Attackers can exploit weaknesses in exposed systems, stolen credentials or third-party software to gain initial access. Once inside, they may spend time moving through the network before encrypting systems or stealing information.

That means ransomware defense increasingly depends on detecting suspicious activity before encryption begins.

More Attacks Mean More Than More Malware

The record figure is significant, but the underlying trend is more important.

Modern ransomware operations increasingly resemble businesses. Criminal groups can specialize in initial access, malware deployment, data theft or negotiation, while affiliates provide additional access to corporate networks.

This specialization allows ransomware operations to scale without requiring every attacker to develop every part of the attack themselves.

It also means organizations cannot rely on antivirus software alone.

Strong identity controls, network segmentation, offline backups, rapid patching and continuous monitoring are becoming increasingly important components of ransomware defense.

The Record May Not Be the End of the Trend

August’s 997 reported attacks do not necessarily represent every ransomware incident worldwide. Many attacks are never publicly disclosed, while others may be resolved without appearing in incident databases.

That means the real number could be substantially higher.

Nevertheless, the latest data provides a clear warning for organizations heading into the final months of 2026: ransomware remains an expanding operational threat, and the combination of rising attack volumes and increasingly professional criminal groups continues to challenge traditional security defenses.

Critical ScreenConnect Flaw Exploited in Worm-Like Attacks

Previous article

You may also like

Comments

Comments are closed.