CRITICALStripe breach ~33GB of exposed data across 662 organizations. Is your domain exposed?
Run free scan
CyberXtron
Ransomware Report - August 2026
RansomwareRansomware ActivityThreat IntelCybersecurity

Ransomware Report - August 2026

Executive Summary 

In August 2026, ransomware activity recorded a total of 1,165 victims globally, making this the new global high and marking a 22.1% increase from the 954 victims reported in July 2026. The rebound was driven by Qilin reclaiming the top spot from TheGentlemen, alongside the simultaneous emergence of four large new operators — Clop, Orova, DireWolf, and Storm — each posting more than 40 victims in their first month of significant visibility in this dataset. 

The United States retained its position as the most impacted geography, accounting for 414 victims and representing approximately 35.5% of globally attributed incidents. Manufacturing displaced Professional Services from the top position for the first time in the current reporting cycle, recording 185 victims, followed by Technology (155 victims) and Professional Services (136 victims). 

Key Points 

  • A total of 1,165 ransomware victims were recorded globally in August 2026. 

  • Ransomware activity increased by approximately 22.1% from July to August 2026, the second consecutive monthly increase and the highest monthly total of all time. 

  • The United States accounted for 414 victims, representing approximately 35.5% of globally attributed incidents and remaining the dominant target geography. 

  • Manufacturing (185 victims) overtook Professional Services (136 victims) as the most targeted confirmed sector, with Technology (155 victims) close behind; Healthcare (118 victims) also posted a sharp increase. 

  • Qilin reclaimed the top position from TheGentlemen, recording 164 victims against TheGentlemen's 113 — a reversal of the rankings that held for the previous two months. 

  • Clop, Orova, DireWolf, and Storm together accounted for over 170 victims in August despite having little or no presence on July's leaderboard. 

  • LockBit5 more than tripled its output, rising from 9 victims in July to 31 in August, while Settra and ShinyHunters both scaled sharply. 

  • Deadlock's public leak-site postings fell from 85 victims in July to 6 in August, and CRPxO — last month's fast-growing new entrant — collapsed from 36 victims to just 1. 

  • Italy (51 victims) posted the sharpest gain among major geographies, overtaking the United Kingdom and Germany's usual runner-up positions in relative growth terms. 

  • 85 distinct threat groups were active during August 2026, up sharply from July's 63. Victim organizations were identified across 84 confirmed countries, with an additional 99 victims recorded under an unresolved "Unknown" geographic classification. 

Ransomware Activity — August 2026 

Ransomware activity in August 2026 was defined by a leadership reversal at the top of the ecosystem and an unusually large wave of new mid-tier operators reaching significant scale in the same month. 

 

Qilin recorded 164 victims, retaking the top position after trailing TheGentlemen for two consecutive months. The group's claimed victims remain concentrated in Manufacturing, Professional Services, and Technology, spanning more than 100 countries, and its resurgence has been linked by researchers to continued exploitation of a VPN authentication-bypass flaw first observed in May 2026. TheGentlemen (113 victims) fell to second place after a sharp pullback from July's 177; the group remains one of the ecosystem's highest-volume RaaS operators, with claims spanning manufacturing, technology, healthcare, and financial services, though its monthly output has moderated considerably since peaking mid-year.  

Clop and Orova tied for third place with 45 victims apiece, representing two very different growth stories. Clop's activity reflects the long tail of its mass-exploitation campaign against Oracle E-Business Suite customers, which Mandiant has traced back to initial exploitation as early as August 2025, continuing to surface new victims nearly a year after the underlying vulnerability was first weaponized. Orova, by contrast, is a genuinely new entrant: a data-extortion actor first observed in 2026 that has shown a sharp rise in activity during August, targeting opportunistically across multiple sectors rather than a narrow vertical.  

Incransom (44 victims) continued its steady multi-month climb, while DireWolf (43 victims) and Storm (41 victims) both scaled rapidly from limited prior visibility. DireWolf's claimed victims concentrate in Manufacturing and Professional Services and span roughly 30 countries, and the group is assessed as an entirely independent operation with no evidence of ties to existing ransomware families. Storm's August surge coincides with the debut of a new payload: Microsoft has attributed a previously undocumented ransomware strain, StormEncryptor, to the actor Storm-1175 beginning August 2, 2026, likely tied to rapid exploitation of a newly disclosed authentication-bypass flaw in remote-management software. 

Krybit (36 victims), Akira (31 victims), and LockBit5 (31 victims) rounded out the upper-middle tier, with LockBit5 more than tripling its July count. LockBit5 emerged in September 2025 as the group's resurgence following the February 2024 law enforcement takedown, introducing cross-platform payloads targeting Windows, Linux, and VMware ESXi, and its August scaling followed a high-profile listing of a major US regional bank. L Group (28), Everest (27), Dark Project (25), Settra (24), and CoinbaseCartel (24) all posted substantial totals; Settra's count nearly tripled from July, while CoinbaseCartel's reappearance at scale follows a reported near-total collapse in Q2 2026 that researchers had linked to a probable law enforcement disruption. 

Several previously prominent operators pulled back significantly in August. Global Secret Group, last month's fast-scaling new entrant, fell from 31 victims to 12 — notable given researchers have separately flagged the group for scrutiny over its victim claims, with self-reported datasets surpassing 100,000 records even as its confirmed leak-site postings remain far smaller. SafePay (12), Nightspire (8), Chaos (8), and Genesis (6) all moderated substantially. Deadlock's public count fell to just 6 from July's 85, though the group's cumulative leak-site total reached 101 victims by August 31, with known victims concentrated in Professional Services, Manufacturing, and Technology across 40 countries — consistent with a group that has deliberately kept a low public profile rather than one that has gone dormant. CRPxO's count collapsed from 36 to just 1, the sharpest single-group reversal of the month. Booba Project (4) also declined. In total, 85 distinct groups were identified as active during August 2026, a sharp increase from July's 63, reflecting continued fragmentation and diversification across the mid and lower tiers of the RaaS ecosystem.  

Ransomware Activity — July 2026 vs. August 2026 

Ransomware activity rose from 954 victims in July 2026 to 1,165 in August 2026, a 22.1% month-over-month increase and the second consecutive monthly rise. Unlike July's surge, which was concentrated in the rivalry between two dominant operators, August's growth was driven by a broader base: a leadership reversal at the top combined with the simultaneous, large-scale arrival of several new or previously minor operators. 

 

Qilin grew from 127 victims in July to 164 in August (up 29.1%), while TheGentlemen fell from 177 to 113 (down 36.2%) — a reversal that returned Qilin to the position it held for much of the first half of 2026. Krybit rose from 25 to 36 victims (up 44.0%), Akira grew from 22 to 31 (up 40.9%), and Incransom expanded from 39 to 44 (up 12.8%). LockBit5 posted the sharpest proportional increase among established operators, rising from 9 to 31 victims (up 244.4%), while Settra nearly tripled from 9 to 24 (up 166.7%) and ShinyHunters more than tripled from 6 to 19 (up 216.7%). 

Clop, Orova, DireWolf, Storm, L Group, Everest, Dark Project, CoinbaseCartel, Majinahanashi, SilentRansomGroup, and several other operators represented entirely new contributions to the ecosystem's total volume, together accounting for well over 300 victims that had little or no equivalent presence in July's leaderboard — helping explain why August's aggregate growth outpaced the gains recorded by any single established group. 

Against this backdrop, several previously dominant operators pulled back sharply. DragonForce fell from 42 to 15 victims (down 64.3%), SafePay declined from 33 to 12 (down 63.6%), and Global Secret Group dropped from 31 to 12 (down 61.3%). Nightspire eased from 16 to 8 (down 50.0%), Chaos fell from 15 to 8 (down 46.7%), and Genesis and Booba Project both declined by roughly two-thirds. The most dramatic reversals belonged to CRPxO, which collapsed from 36 victims to just 1 (down 97.2%), and Deadlock, whose public count fell from 85 to 6 (down 92.9%) — though as noted above, Deadlock's true operational tempo is likely understated by leak-site tracking given its blockchain-based communications infrastructure. 

Industry Impact in August 2026 — Ransomware Continues to Target Critical Sectors 

In August 2026, ransomware attacks intensified across nearly every major confirmed sector, with Manufacturing overtaking Professional Services to claim the top position for the first time in the current reporting cycle. 

 

Manufacturing recorded the highest confirmed victim count at 185, up 21.7% from July's 152, reflecting sustained attacker interest in production-critical environments where downtime pressure accelerates ransom payment. Technology followed closely with 155 victims, up 23.0% from July's 126 — a sector where Clop's ongoing enterprise-software exploitation campaign and Orova's opportunistic targeting both contributed meaningfully. Professional Services fell to third place with 136 victims, down 22.3% from July's 175, ending its four-month run at the top of the confirmed sector rankings. 

Healthcare recorded 118 victims, up 38.8% from July's 85 and reinforced by the month's largest single data-theft claim, detailed later in this report. Retail & E-Commerce (76 victims) and Financial Services (66 victims) both grew, the latter up 32.0% from June's 50 following a wave of activity including a major US banking-sector listing. Transportation (43 victims), Agriculture and Food Production (39 victims), Energy & Utilities (33 victims), Hospitality (30 victims), and Education (27 victims) each recorded meaningful activity. Government & Defense fell to 25 victims, down 32.4% from July, even as the month's most consequential public-sector incident — a confirmed breach of a US federal law enforcement agency — unfolded in this category. 

Geographical Distribution of Victims 

The United States remained the most targeted country in August 2026, accounting for 414 victims and approximately 35.5% of globally attributed incidents — a substantial rise from July's 318 victims and a larger share of total activity than the roughly 33% recorded the prior month. 

 

Germany recorded 69 victims, extending its position as the most impacted country outside the United States and rising 19.0% from July's 58. Italy surged to 51 victims, up 70.0% from July's 30 and moving into third place globally — one of the sharpest relative gains of any major geography this month. The United Kingdom rose to 50 victims, up 28.2% from July's 39. An additional 99 victims were recorded under an unresolved "Unknown" geographic classification, nearly two-and-a-half times July's total and the largest unattributed pool of the current reporting cycle. 

Canada (31 victims) held roughly steady from July, while Brazil (27 victims) and India (27 victims) both posted modest gains. France (24 victims) was unchanged from July, and Mexico (24 victims) rose 33.3%. Australia (19 victims) and Taiwan (18 victims) both increased, with Taiwan's growth linked in part to Orova's targeting of Taiwanese manufacturers and electronics firms. Argentina (16 victims) eased from July's 19, while Switzerland (14 victims) and Japan (14 victims) both grew, the latter up 55.6%. 

Hong Kong (13 victims), Spain (13 victims), the Netherlands (12 victims), Thailand (11 victims), and China (11 victims) all featured prominently among the month's confirmed geographies, alongside the United Arab Emirates (10 victims), the Philippines (10 victims), and Singapore (10 victims). A long tail of countries across Africa, Latin America, the Middle East, and Eastern Europe each recorded between one and nine victims. 

Major Ransomware Breaches Across Global Sectors — August 2026 

During August 2026, ransomware and cyber-extortion activity produced several significant confirmed or claimed incidents across critical industries and regions. 

Government and Defense United States The month's most consequential public-sector incident involved Qilin's claimed breach of the US Bureau of Alcohol, Tobacco, Firearms and Explosives (ATF). Qilin listed the federal agency on its dark web leak site on August 26, the same day the ATF confirmed to reporters that a standalone server had been breached. The Department of Justice classified the incident as a "major incident," a formal designation that triggers mandatory congressional notification. The agency stated the compromised system was not connected to its case-management, laboratory, or eForms systems, and that its investigative operations remained unaffected. 

Healthcare — United States (Global Impact) The extortion group ShinyHunters claimed one of the year's largest healthcare-sector breaches against McKesson, a major US pharmaceutical distributor. The group told researchers it compromised employee Okta single sign-on accounts through voice-phishing attacks, then pivoted into McKesson's Salesforce and Snowflake environments, exfiltrating roughly one terabyte of data over four days between August 21 and 25. ShinyHunters demanded a ransom of just over $55 million with a 72-hour deadline, which the group told BleepingComputer went unanswered. McKesson confirmed unauthorized access to third-party applications in an SEC filing and stated its investigation remains in its early stages. 

Manufacturing — United States and Germany Two separate incidents underscored continued pressure on manufacturers this month. The Falcon group claimed an 848 GB data-theft incident against Hayward Holdings, a NYSE-listed pool and spa equipment manufacturer, alleging exfiltration of Salesforce records, distributor pricing data, and privileged account credentials. Separately, the xpl0itrs group listed BMW Group, the German luxury automaker, on its leak site.  

Financial Services — United States LockBit5 continued its resurgence with a listing of a major US regional banking subsidiary, representing one of the highest-profile financial institution targets in the group's claimed victim portfolio and following a reported operational alliance announced in October 2025 between LockBit, Qilin, and DragonForce involving shared infrastructure and coordinated targeting. 

These incidents collectively underscore the continued dominance of credential-based and vishing-driven initial access techniques, the growing willingness of extortion groups to target federal law enforcement and critical healthcare infrastructure, and the persistence of mass-exploitation campaigns against widely deployed enterprise software long after initial disclosure. 

Recommendations — August 2026 Ransomware Outlook 

To mitigate the ongoing ransomware threat, organizations should continue strengthening defensive resilience through layered controls. The August 2026 incidents highlight several critical vectors requiring immediate attention, including VPN and edge-device exploitation, voice-phishing-driven cloud compromise, and the emergence of takedown-resistant infrastructure. 

  • Patch and monitor VPN and remote-access appliances aggressively, given Qilin's continued exploitation of authentication-bypass vulnerabilities in widely deployed platforms and Storm-1175's rapid weaponization of a newly disclosed flaw in remote-management software. 

  • Audit legacy and third-party enterprise software deployments — particularly ERP and business-suite platforms — for unpatched vulnerabilities, given Clop's sustained mass-exploitation campaign against Oracle E-Business Suite customers nearly a year after initial disclosure. 

  • Train help-desk and employee populations to recognize and resist vishing attempts, and implement callback verification procedures for any credential-reset request, given ShinyHunters' continued reliance on voice-phishing to compromise SSO accounts. 

  • Review OAuth and SSO token lifecycles for all connected SaaS and cloud data platforms, and limit the blast radius of any single compromised identity provider account. 

  • Extend threat-hunting and monitoring practices to account for blockchain-hosted and decentralized command-and-control infrastructure, which is increasingly resistant to conventional takedown techniques. 

  • Maintain offline, encrypted, and regularly tested backup systems, and segment production and operational technology environments from corporate IT networks to limit ransomware's ability to disrupt manufacturing operations. 

  • Deploy advanced EDR/XDR solutions with tamper protection enabled, and monitor for abnormal API and bulk data-query activity across endpoint, network, and cloud telemetry. 

  • Conduct regular incident response exercises calibrated to current threat actor TTPs, with specific scenarios addressing federal/public-sector breach protocols, dual-actor extortion incidents, and cloud-platform data exfiltration. 

Conclusion 

The ransomware landscape in August 2026 reflected a sharp continuation of July's rebound, with 1,165 globally recorded victims distributed across 84 confirmed countries and 85 active threat groups — a 22.1% month-over-month increase and the highest monthly total ever. 

The United States remained the most targeted country by a wide margin, while Germany extended its position as the leading target outside North America and Italy posted the sharpest relative gain among major geographies. Manufacturing displaced Professional Services as the most targeted confirmed sector for the first time in this reporting cycle, while Technology and Healthcare both recorded substantial increases in confirmed volume. 

The month's central story was Qilin's reclamation of the top spot from TheGentlemen, set against the simultaneous, large-scale arrival of Clop, Orova, DireWolf, and Storm — four operators with very different origin stories that together illustrate the RaaS ecosystem's continued capacity for rapid diversification. The ATF breach claimed by Qilin and the McKesson breach claimed by ShinyHunters further illustrate the ecosystem's growing willingness to target federal law enforcement infrastructure and large-scale healthcare data, respectively. 

Ransomware remains a persistent, adaptive, and strategically driven threat. The rapid emergence of new operators, the resilience of established groups such as Clop and LockBit5, and the demonstrated willingness to target federal agencies, healthcare distributors, and production-critical manufacturers alike underscore the need for sustained investment in identity security, vulnerability management, detection, response, and recovery capabilities across all industries and organizational sizes. 

 

Elevate your security—get curated threat insights in your inbox.

Ransomware Report - August 2026 | CyberXTron Blog