CRITICALFortiBleed is actively compromising Fortinet firewalls. Is your domain exposed?
Run free scan
CyberXtron
Ransomware Report - July 2026
Ransomware ActivityRansomware ReportThreat IntelCybersecurity

Ransomware Report - July 2026

July 2026 Ransomware Report

Executive Summary

In July 2026, ransomware activity recorded a total of 954 victims globally, marking a 34.9% increase from the 707 victims reported in June 2026 — reversing two consecutive months of decline. The rebound was driven overwhelmingly by a resurgent rivalry at the top of the ecosystem, alongside the rapid emergence of several new mid-tier operators.

The United States retained its position as the most impacted geography, accounting for 318 victims and representing approximately 33% of globally attributed incidents. Professional Services emerged as the most heavily targeted confirmed sector for a fourth consecutive month, with 175 victims, followed closely by Manufacturing (152 victims) and Technology (126 victims), both of which surged sharply from June.

TheGentlemen displaced Qilin as the most active threat group, recording 177 victims against Qilin's 127 — a dramatic escalation in what researchers describe as an intensifying rivalry between the two operators. The two groups traded the top spot repeatedly throughout the month, a dynamic some analysts attribute to direct competition between the two criminal collectives. Deadlock, a construction- and engineering-focused extortion group, emerged at scale for the first time with 85 victims, while CRPxO (36 victims) and Global Secret Group (31 victims) also debuted as significant new entrants. Victim organizations were identified across 91 confirmed countries, with an additional 39 victims recorded under an "Unknown" geographic classification.

Key Points

  • A total of 954 ransomware victims were recorded globally in July 2026.

  • Ransomware activity increased by approximately 34.9% from June to July 2026, the sharpest month-over-month rise in the year, ending two consecutive months of decline.

  • The United States accounted for 318 victims, representing approximately 33% of globally attributed incidents and remaining the dominant target geography.

  • Among confirmed sectors, Professional Services (175 victims), Manufacturing (152 victims), and Technology (126 victims) were the most targeted, with Manufacturing and Technology both more than doubling in relative terms from June.

  • TheGentlemen overtook Qilin as the most active threat group, recording 177 victims against Qilin's 127.

  • Deadlock, a group specializing in construction, engineering, and professional-services targets, emerged at scale with 85 victims, becoming the third most active operator overall.

  • CRPxO (36 victims) and Global Secret Group (31 victims) debuted as notable new entrants, reinforcing continued fragmentation at the ecosystem's edges.

  • Germany (58 victims) overtook the United Kingdom (39 victims) to remain the most impacted country outside the United States for a second consecutive month.

  • 63 distinct threat groups were active during July 2026. Victim organizations were identified across 91 confirmed countries, with 39 additional victims recorded under an unresolved "Unknown" geographic classification.

Ransomware Activity — July 2026

Ransomware activity in July 2026 was defined by an intensifying contest for dominance between the ecosystem's two largest operators, alongside the rapid scaling of several previously minor or entirely new groups.

TheGentlemen recorded 177 victims, taking the top position after trailing Qilin last month. The group operates a fully featured RaaS platform offering affiliates a 90% revenue share — among the highest in the underground market — a structure designed specifically to draw experienced operators away from competing programs. By July 2026 the group was described as fully active and among the ecosystem's front-runners, with claims spanning manufacturing, technology, healthcare, and financial services and continued scaling throughout the month. Qilin (127 victims) fell to second place after leading the ecosystem for six consecutive months, though it remained a dominant force overall; the group has continued to eclipse many of its rivals as one of the most active ransomware gangs of 2025 and 2026, with victims spanning manufacturers, financial firms, retailers, healthcare providers, government agencies, and transportation-related entities.

Deadlock represented the most structurally significant development of the month, emerging at scale for the first time with 85 victims and vaulting directly into third place. Public reporting attributes Deadlock's emergence to late 2024, with the group rapidly adopting a double-extortion model that combines encryption with data theft and public shaming, concentrating its targeting on manufacturing, engineering, and professional-services firms across Europe and North America. Its July campaigns focused heavily on Construction & Engineering and Professional Services targets, with activity spreading across the United States, Spain, Italy, and further afield.

DragonForce (42 victims) and Incransom (39 victims) held the fourth and fifth positions, both expanding from June. CRPxO (36 victims), SafePay (33 victims), and Global Secret Group (31 victims) rounded out the upper-middle tier — with CRPxO and Global Secret Group both appearing as wholly new entrants to the top ten. Krybit (25 victims) continued its steady growth, while Akira (22 victims) and Nova (21 victims) both moderated from June. Genesis (18 victims) rebounded sharply after its June pullback, and Nightspire (16 victims) eased further from its earlier peak.

Several previously prominent operators pulled back significantly. LockBit5, which had surged to 59 victims in June, fell to just 9 in July. Settra, last month's most notable new entrant, declined to 9 victims after its initial 22-victim debut. ShinyHunters' tracked leak-site listings fell to 6 victims even as the group was linked to one of the month's most consequential breaches, described later in this report — a reminder that monthly leak-site counts do not always move in step with the scale of individual incidents. ExfilSquad (15), Chaos (15), Play (15), CMDorganization (12), and newly tracked Booba Project (12) sustained the ecosystem's dense mid-tier. In total, 63 distinct groups were identified as active during July 2026.

Ransomware Activity — June 2026 vs. July 2026

Ransomware activity rose sharply from 707 victims in June 2026 to 954 in July 2026, a 34.9% month-over-month increase and the largest single-month rise recorded in the current reporting cycle. Unlike prior months, where changes were broadly distributed, July's surge was concentrated in the dramatic escalation of the two largest operators and the sudden arrival of several new groups at scale.

TheGentlemen more than doubled its output, rising from 76 victims in June to 177 in July — a 132.9% increase that pushed it past Qilin for the first time. Qilin itself grew from 78 to 127 victims (up 62.8%), meaning both leading operators expanded simultaneously even as their relative rankings flipped. DragonForce rose from 28 to 42 victims, and Incransom climbed from 30 to 39. SafePay expanded from 21 to 33 victims, and Krybit grew from 20 to 25.

Several groups moved in the opposite direction. Akira eased from 32 to 22 victims, and Nova declined from 28 to 21. Nightspire fell from 22 to 16. The most dramatic reversal belonged to LockBit5, which collapsed from 59 victims in June — its strongest month since March — to just 9 in July, while Settra fell from 22 to 9 following its scale debut the prior month.

Deadlock's emergence at 85 victims, alongside CRPxO's 36 and Global Secret Group's 31, represented entirely new contributions to the ecosystem's total volume rather than shifts from existing operators, helping explain why the month's aggregate growth outpaced the gains recorded by any single established group.

Industry Impact in July 2026 — Ransomware Continues to Target Critical Sectors

In July 2026, ransomware attacks intensified across nearly every major confirmed sector, with Professional Services, Manufacturing, and Technology all recording substantial increases from June.

Professional Services recorded the highest confirmed victim count at 175, retaining the top position for a fourth consecutive month and rising 42.3% from June's 123. This continued dominance reflects sustained attacker interest in law firms, consulting firms, managed service providers, and staffing agencies, whose client data and broad third-party access create outsized extortion leverage — a pattern reinforced this month by Deadlock's and TheGentlemen's parallel campaigns against engineering and fiduciary-services firms.

Manufacturing followed closely with 152 victims, up 83.1% from June's 83 and firmly holding second place among confirmed sectors. Technology recorded 126 victims, more than doubling from June's 56 — a 125% increase underscored qualitatively by a major supply-chain-adjacent healthcare-technology breach detailed later in this report. Healthcare recorded 85 victims, up 66.7% from June, continuing its status as a persistent high-priority target. Retail & E-Commerce, tracked as a distinct category this month, recorded 70 victims.

Financial Services (50 victims) doubled from June's 25, while Government & Defense (37 victims), Transportation (37 victims), and Agriculture and Food Production (37 victims) each recorded meaningful activity, with Government & Defense up 54.2% from the prior month's Public Sector total. Energy & Utilities nearly tripled to 35 victims from June's 12. Hospitality (27 victims) and Education (24 victims) rounded out the confirmed sector distribution, alongside a broader "Other" classification of 46 victims not mapped to the report's standard categories.

The "Not Found" classification fell sharply to 53 victims, down 61.3% from June's 137 — a marked improvement in sector attribution coverage that reverses the prior month's deterioration and suggests underground reporting channels regained clarity on victim sectors during July.

Geographical Distribution of Victims

The United States remained the most targeted country in July 2026, accounting for 318 victims and approximately 33% of globally attributed incidents — a substantial rise from June's 198 victims, though a modestly smaller share of total activity than the roughly 39% recorded in May, reflecting the month's broader geographic spread.

Germany recorded 58 victims, extending its position as the most impacted country outside the United States for a second consecutive month and rising 18.4% from June's 49. The United Kingdom rebounded to 39 victims after June's sharp decline to 21, nearly doubling (up 85.7%). An additional 39 victims were recorded under an unresolved "Unknown" geographic classification, tying the UK's confirmed total.

Canada (32 victims) held steady from June, while Italy (30 victims) recorded a notable increase. Brazil (26 victims) continued its multi-month growth trend, building on June's doubling from May. Spain (24 victims) recovered from June's sharp pullback, and India (24 victims) and France (24 victims) both posted gains, with India extending the growth pattern flagged in the June report. Türkiye (22 victims) and Argentina (19 victims) recorded meaningful increases, the latter more than doubling from June.

Mexico (18 victims), the Czech Republic (17 victims), and Australia (16 victims) sustained consistent exposure. Poland (14 victims), Switzerland (13 victims), and Taiwan (11 victims) rounded out the upper-middle tier of confirmed geographies. Portugal (10 victims), Malaysia (9 victims), China (9 victims), and Japan (9 victims) each recorded meaningful activity, while the United Arab Emirates (8 victims) and Colombia (8 victims) sustained measurable exposure. A long tail of countries across Africa, Latin America, the Middle East, and Eastern Europe each recorded between one and seven victims.

In total, victim organizations were identified across 91 confirmed countries and territories, with an additional 39 victims recorded under an unresolved "Unknown" geographic classification — a notable improvement in attribution scope compared to June's larger unattributed pool, though geographic data for the most recent reporting month should still be interpreted with some caution.

Major Ransomware Breaches Across Global Sectors — July 2026

During July 2026, ransomware and cyber-extortion activity produced several significant confirmed or claimed incidents across critical industries and regions.

Professional Services and Manufacturing — The month's defining storyline was the accelerating rivalry between TheGentlemen and Qilin, which traded the position of most active group multiple times during July amid a wave of claimed attacks against engineering, construction, and fiduciary-services firms worldwide. TheGentlemen's July campaign included claimed breaches of Premier Fiduciary, a Hong Kong-based corporate and fiduciary services provider, and CRB Group, a major U.S. engineering and construction firm, alongside dozens of mid-sized manufacturing and professional-services targets across more than a dozen countries. The group's claims by July spanned manufacturing, technology, healthcare, and financial services, with continued scaling throughout the month. Deadlock's parallel campaign concentrated on construction and engineering firms in Europe and Southeast Asia, including claimed attacks on Thailand's Tesco Engineer and Lithuania's KEMEK Engineering.

Healthcare — ShinyHunters claimed one of the year's most consequential healthcare incidents against Abbott Laboratories, targeting the company's Cancer Diagnostics business. The group told reporters it had conducted voice-phishing attacks against Abbott employees in mid-June, compromising a Microsoft Entra single sign-on account that provided access to internal systems, and claimed to have exfiltrated approximately 30 million rows of customer data including one million Social Security numbers. Abbott confirmed unauthorized access to a limited number of internal systems within its Cancer Diagnostics business, stating the incident had not disrupted patient care, manufacturing, or business operations. A separate threat actor, ShadowByt3$, independently claimed a related breach of Abbott's LabCentral customer portal using compromised customer credentials. ShinyHunters set an extortion deadline that Abbott negotiated to extend into late July.

Financial Services, Insurance, and Aviation — CRPxO conducted one of the month's most concentrated national campaigns in Turkey, listing close to 20 Turkish organizations on its leak site in the final days of July alone. The group ran an aggressive data-exfiltration campaign against Turkish critical infrastructure, publishing stolen data packages ranging from 0.8 GB to 3.1 GB and concentrating on banking, insurance, and aviation/transportation operators. Confirmed or claimed victims included banks Kuveyt Türk, Anadolubank, and Finansbank, national carrier THY, automaker Hyundai's Turkish operations, and conglomerate Doğan Holding. The Hyundai Turkey listing alone claimed 1.5 GB of recruitment and personnel data, including candidate assessment records and proctored exam footage, and reflected a broader pattern of the group actively expanding its footprint among Turkish organizations in recent days. The concentrated burst helped drive Türkiye's victim count to 22 for the month, and contributed meaningfully to CRPxO's emergence as a top-ten operator in its first month of significant activity.

Banking and Financial Services — India Bank of Baroda, India's second-largest public sector bank, confirmed a cyber incident in late July after the Triple X ransomware group claimed to have exfiltrated roughly one terabyte of customer data. The bank said an employee's email account had been compromised, allowing unauthorized access to certain data, while stating that the incident was detected and contained immediately and that its core banking systems were not accessed. Triple X, a relatively new group first observed in May 2026, published the stolen data on the dark web for free on July 24 rather than demanding payment, in an unusual departure from the standard double-extortion playbook. The published dataset reportedly included more than 92,000 files covering customer KYC records, security reports, and internal audit documents.

Manufacturing and Consumer Goods — The Anubis ransomware group claimed responsibility for an attack on fairlife, Coca-Cola's dairy subsidiary, which forced a temporary suspension of U.S. production operations. Coca-Cola disclosed in a July 16 SEC filing that fairlife had identified unauthorized third-party access to a portion of its systems, including production-related systems, in connection with a ransomware event, while stating that Canadian production was not affected. Anubis subsequently claimed to have encrypted servers and exfiltrated roughly one terabyte of confidential data, threatening to publish the files unless a ransom was paid. Coca-Cola later confirmed that data had been taken during the incident, after resuming the majority of production across its four U.S. manufacturing facilities.

These incidents collectively underscore the continued dominance of credential-based and voice-phishing initial access techniques, the growing willingness of extortion groups to target production-critical manufacturing infrastructure, and the intensifying competitive dynamics among the RaaS ecosystem's top operators.

Recommendations — July 2026 Ransomware Outlook

To mitigate the ongoing ransomware threat, organizations should continue strengthening defensive resilience through layered controls. The July 2026 incidents highlight several critical vectors requiring immediate attention, including voice-phishing (vishing) attacks against help desks and employees, legacy system exposure following mergers and acquisitions, and ransomware targeting of production and operational technology environments.

  • Train help-desk and employee populations to recognize and resist vishing attempts, and implement callback verification procedures for any identity or credential-reset request received by phone.

  • Conduct thorough security audits of legacy and inherited systems following mergers and acquisitions, ensuring newly acquired environments are brought under the parent organization's identity and access management controls promptly.

  • Enforce phishing-resistant MFA across all remote access channels, and review single sign-on configurations to limit the blast radius of any single compromised identity provider account.

  • Segment production and operational technology environments from corporate IT networks to limit the ability of ransomware to disrupt manufacturing operations, and maintain tested business continuity plans specific to production facilities.

  • Deploy advanced EDR/XDR solutions and continuously monitor for indicators of compromise across endpoint, network, and cloud telemetry, with particular attention to abnormal API and bulk data-query activity.

  • Maintain offline, encrypted, and regularly tested backup systems, and extend third-party and supply-chain risk management to cover professional-services, engineering, and construction vendors given this month's concentrated targeting of those sectors.

  • Conduct regular incident response exercises calibrated to current threat actor TTPs, with specific scenarios addressing vishing-based identity compromise, dual-actor extortion incidents, and ransomware affecting production environments.

Conclusion

The ransomware landscape in July 2026 reflected a sharp reversal of the moderation seen in May and June, with 954 globally recorded victims distributed across 91 confirmed countries and 63 active threat groups — a 34.9% month-over-month increase and the highest monthly total of the current reporting cycle.

The United States remained the most targeted country, while Germany extended its position as the leading target outside North America and the United Kingdom rebounded sharply from June's decline. Professional Services retained its position as the most targeted confirmed sector for a fourth consecutive month, while Manufacturing and Technology both recorded dramatic increases in confirmed volume.

The month's central story was the intensifying rivalry between TheGentlemen and Qilin, which traded the position of most active operator throughout July, alongside the rapid, large-scale emergence of Deadlock as a new top-three threat actor. The ShinyHunters breach of Abbott Laboratories and the Anubis attack on Coca-Cola's fairlife subsidiary further illustrate the ecosystem's continued willingness to target healthcare data at scale and disrupt physical production operations, respectively.

Ransomware remains a persistent, adaptive, and strategically driven threat. The intensifying competition among top-tier operators, the rapid scaling of new entrants, and the demonstrated willingness to target production-critical infrastructure and healthcare data alike underscore the need for sustained investment in identity security, operational technology segmentation, detection, response, and recovery capabilities across all industries and organizational sizes.

Elevate your security—get curated threat insights in your inbox.