Record Ransomware Victims in August 2026: What the Numbers Show

Record Ransomware Victims in August 2026: What the Numbers Show

Ransomware’s Record August: What 1,034 Claimed Victims Actually Tell Us

Cyble’s research arm counted 1,034 ransomware victims on leak sites in August, the busiest month of 2026 at 33 victims a day. Every major independent tracker agrees on the direction. None agrees on the number — and that gap is where the real story sits.

The Ransomware Brief from Cyble Research and Intelligence Labs (CRIL) reported 1,034 victims across 1,078 attacks in August. It attributes the surge to affiliate recruitment and exploitation of internet-facing infrastructure rather than new encryption capability. Attacks rose 25% over July and roughly doubled June’s total. CRIL reads this as a new baseline, not a seasonal spike.

What the Numbers Say — and Who Else Says Them

The direction is easy to corroborate. Breachsense counted 964 victims across 83 groups in August, a 19% rise over July. NCC Group logged 1,073 attacks, up 12%. Comparitech recorded 997, its highest month since February 2025. Check Point’s tally reached 1,042, nearly double August 2025.

Five trackers, five methodologies, one conclusion: the busiest month of 2026 by a wide margin.

The gang rankings line up too. Qilin led everywhere — CRIL puts it at 145 victims, Breachsense and Comparitech at 157, and AhnLab’s ASEC at 167. The Gentlemen placed second in every count. Every dataset puts the United States first, and Italy’s surge appears in both Breachsense (48 victims, second worldwide) and Comparitech (a 200% jump).

The sector story splits by taxonomy. CRIL’s top targets are Manufacturing (151), Professional Services (147), IT and ITES (126) and Healthcare (98). Breachsense’s most-hit industry is Healthcare, and NCC’s is Industrials at 31% of attacks. These categories overlap heavily, so the trackers describe the same concentration from different angles: industries where downtime forces decisions.

Claims are not breaches, though — a caveat the release never states.

Claims Are Not Breaches

Leak-site listings are the gangs’ own press releases. Ransomnews, which verifies incidents against breach notifications, regulatory filings and court records, has confirmed 93 August attacks so far. Comparitech has confirmed 77 of its 997. Confirmation lags the attack by weeks or months, so these floors will rise — but they sit far below the headline counts.

Two forces inflate the gap. Gangs pad, recycle and occasionally fabricate victim listings, because a leak site is a pressure instrument, not a ledger. Payment behaviour has also shifted: Check Point reports ransom payment rates near 23% in 2025, down for a sixth straight year, even as on-chain payments topped $820 million. Volume has replaced conversion as the business model. A gang that cannot persuade a victim to pay still profits from naming them.

How the Gangs Got Here

Qilin has dominated ransomware since 2024 through absorption. The RaaS outfit, active since 2022 under its earlier name Agenda, soaked up affiliates after the disruptions of LockBit, ALPHV/BlackCat and RansomHub. Belgian government assessors count more than 1,800 claimed victims for the group overall.

The Gentlemen is the more instructive story. It formed in mid-2025 when a Qilin affiliate called ArmCorp quit over roughly $48,000 in unpaid commissions and rebuilt as its own operation. It offers affiliates a 90/10 revenue split, the most generous cut on the market. Unit 42 counts roughly 20 operators. Leaked chats analysed by Check Point suggest a core of about nine people, using AI coding tools to reach the top three within months.

CRIL’s most interesting regional finding fits this trajectory. Asia-Pacific was the only region where Qilin did not lead, with The Gentlemen claiming 20 victims against Qilin’s 16. Trend Micro flagged the group’s APAC focus as early as September 2025. Two newer groups, Krybit (13) and Orova (12), out-claimed Qilin in the region without ranking in the global top five.

The encryption-to-extortion shift completes the picture. Cl0p’s PTC Windchill campaign, which CRIL cites, exploited CVE-2026-12569 against product-lifecycle-management software and used no encryption at all. More than 40 organisations were named, including Shell, Philips, Fiserv and Mindray. ReliaQuest documented a custom web shell built specifically for Windchill’s internals. Attacks that only steal data are quieter, run longer and defeat the backup-centred playbook.

India’s Ransomware Victims in Context

CRIL ranks India seventh worldwide with 24 victims — the most in Asia-Pacific, one in six of the region’s claims, and 50% more than Taiwan or Thailand. Breachsense also places India seventh, with 23. Comparitech, however, recorded a 20% decline in Indian attacks in August. Both findings can hold: rankings by share move when other countries surge, as Italy did.

The exposure is structural either way. CRIL’s top-targeted sectors — manufacturing, professional services, IT and ITES — are exactly the industries India’s economy concentrates. The brief’s argument that regional gangs matter more than headline names applies with force here. Krybit and Orova never appear in global rankings, yet both out-claimed Qilin in the region.

What the Release Doesn’t Say

The brief carries the precision of an audit without its methods. It does not explain how victims are counted, deduplicated or attributed to gangs. It reports 88 gangs in its opening summary and 96 in its global picture. Its subhead ties Manufacturing and Professional Services at 150 victims each; its own key figures say 151 and 147. None of this changes the story, but a report marketed on precision should reconcile its arithmetic.

Context matters too. Cyble sells the threat-intelligence platform the brief promotes, and its research arm doubles as its marketing engine. The data survives independent corroboration — more than most vendor research can claim — but readers should know the commercial position of the source. CRIL’s Daksh Nakra still gets the defence right: “stop planning against the names in the headlines” and focus on exposure, access and recoverability.

Record Ransomware Victims in August 2026: What the Numbers Show

What Security Leaders Should Do

The fundamentals in the brief are not new, and that is the point. Inventory what faces the internet, and patch the KEV list ahead of anything else — the Windchill flaw has had a fix since June. Extend phishing-resistant MFA beyond employees to third parties. Segment networks so data theft hits one compartment, not the estate. Test offline backups, and assume the incident will be a leak rather than an outage: backups restore systems, not stolen files.

Beyond that, treat gang rankings as economics rather than engineering. Affiliate splits and payout reliability move attack volume faster than new malware does — The Gentlemen proved that in twelve months. Monitor leak and access markets, where the earliest signals of an intrusion surface.

Editor’s Note: This article draws on the Cyble press release and The Ransomware Brief dated September 28, 2026, including Daksh Nakra’s quoted statement. Independent corroboration came from monthly reports by Breachsense, NCC Group, Comparitech, AhnLab’s ASEC, Data Breaches Digest and Check Point. It also uses Ransomnews’ confirmed-attacks dataset, Check Point’s Q2 2026 State of Ransomware, and reporting on The Gentlemen by Unit 42, Trend Micro, Blackpoint Cyber and Halcyon.

Further sources include the Belgian Cybersecurity Centre’s analysis of Qilin, and ReliaQuest, BleepingComputer, SecurityWeek and CyberScoop reporting on the Cl0p PTC Windchill campaign. Company background came from Cyble’s own disclosures and TechCrunch reporting. All leak-site figures are attacker claims unless noted as confirmed, and CRIL’s internal inconsistencies are reported as found. TechRecast contacted no parties for comment before publication.