The latest data reveals a sharp rise in ransomware incidents globally in July, with organised gangs like The Gentlemen and Qilin dominating the scene as targeting shifts towards financial, tech, and healthcare sectors, amid evolving cyber threats.
Ransomware activity rose sharply in July, with Comparitech counting 799 incidents worldwide, up from 668 in June and just below March’s year-to-date high of 805. The UK security research firm said 51 of last month’s cases were confirmed by victims, underscoring how much of the market still relies on public leak sites and other indirect reporting rather than direct disclosure.
The pattern of targeting also shifted. Comparitech said attacks on utility companies fell 44% even as headlines focused on other forms of disruption to critical infrastructure, while legal firms and government agencies saw declines of 31% and 11% respectively. By contrast, finance companies, technology firms, pharmaceutical businesses, medical billers and education providers absorbed the largest increases, with attacks up 71%, 62%, 46% and 44% in those sectors. Comparitech’s half-year data, which recorded 4,217 ransomware incidents in the first six months of 2026, suggests the pressure on business targets has remained elevated across the year.
The United States remained the most heavily affected country, accounting for 322 of July’s 799 recorded attacks, while Germany followed with 40. That concentration reflects a broader trend identified by Comparitech and other security researchers: ransomware groups continue to focus on organisations that are more likely to pay or that cannot tolerate prolonged downtime. DeepStrike has said manufacturing, education, healthcare and financial services are among the most likely sectors to pay ransoms, even when the payment rate is below 100%.
Two groups dominated the month’s attack counts. Comparitech said The Gentlemen claimed 135 victims in July, narrowly ahead of Qilin on 125, together accounting for almost a third of the incidents it logged. Qilin, which was linked to the 2024 attack on pathology provider Synnovis that disrupted NHS services, and The Gentlemen, a newer operation that has rapidly scaled up, illustrate how ransomware remains a highly organised criminal market rather than a fading threat. Analysts cited by other security publications say the wider ecosystem is being reinforced by stolen credentials, proxy services and access brokers, making basic controls such as multi-factor authentication, patching and reliable backups more important, not less, even as attention shifts to AI-driven threats.
Disclaimer: This content is intended for informational purposes only. Readers are advised to exercise their own judgement, conduct due diligence, or consult a qualified expert before acting on any information provided.





