LONDON, 9 AUG 2026 — July produced 799 ransomware attacks, the second-busiest month of 2026 behind March. Victims confirmed 51 of them.

That gap is not a footnote to the figure. It is the figure. Ransomware counts are assembled from what attackers publish on their own leak sites, and 94% of July's total rests on the word of the people claiming credit.

What the month looked like

The tally comes from Comparitech: 799 attacks in July against 805 in March, the year's high. The United States absorbed 322 of them, more than the rest of the world combined in that month's data.

Two groups, The Gentlemen and Qilin, were responsible for a third of the month's claims. They listed 135 and 125 victims respectively, making up about 33% of the total. A market this concentrated is not a swarm of opportunists; it is a small number of operations running at industrial cadence.

Where the pressure moved

Change in ransomware targeting by sector, July 2026
Month-on-month movement in claimed attacks
Finance
+71%
Technology
+62%
Pharma / billing
+46%
Education
+44%
Utilities
−44%
Legal
−31%
Source: Comparitech, July 2026, as reported by The Register. Bars show magnitude of change; green is a fall in targeting. Figures are claimed attacks, not confirmed incidents.

Finance rising 71% is consistent with something other than fashion. That education is up 44% in the same month is telling. Separate research from DeepStrike finds it to be one of the sectors most likely to pay, alongside finance (which pays 51% of the time), manufacturing, and healthcare.

Attackers are moving toward the sectors that pay. That is a duller explanation than a shift in capability, and it fits the data better.

The year behind the month

July sits inside a year that was already at record volume. Comparitech logged 4,217 claimed attacks across the first half of 2026 — an average of 23 a day — before a relative lull through April, May and June that July then broke.

That shape matters for reading the 799. A month that follows a quiet quarter looks like a surge whether or not anything changed, because the comparison is against the trough. The more defensible statement is that July returned to the level the year had already established, not that ransomware suddenly accelerated.

The number nobody quotes

Fifty-one confirmations against 799 claims deserves to be the headline rather than the caveat.

A leak-site listing is an assertion by a criminal group that it breached an organisation. Groups have clear incentives to inflate their numbers. A long victim list serves as marketing to affiliates, puts pressure on the named company, and builds a reputation that encourages the next victim to pay. Listings recycled from old breaches, aggregated from other groups' data, or simply invented have all been documented.

None of that makes the dataset worthless. It is the only continuous measure the industry has, and directional movements across many groups probably do track reality. But "799 attacks in July" is not a confirmed-breach count, and it gets quoted as though it were. The figure appears in vendor marketing, board packs, and trend pieces that assemble a year from twelve such data points.

Our own convention is unambiguous: a leak-site claim is reported as a claim, attributed, and never as established fact.

The utilities line, read against this week

One figure in the table runs against the week's headlines. Ransomware attacks on utilities fell 44% in July, in the same period that water systems in twelve US states were being broken into.

Both things are true because they are different activities. The water intrusions were not ransomware — the attackers changed controller passwords and IP addresses to take away operator control, with no extortion attached. Attacks on critical infrastructure and attacks for money involve different threat models, actors, and remedies. A month's data can therefore show opposite trends for each.

A falling ransomware count for a given sector, then, says nothing about whether it is actually under attack.

Two groups, a third of the month

Concentration is the structural fact under the total, and it changes what the number means.

The Gentlemen and Qilin together claimed 260 of July's 799. When a third of recorded activity comes from two operations, the monthly figure is substantially a measure of how busy two organisations were — their affiliate recruitment, their infrastructure uptime, whether a takedown disrupted them. A 6% month-on-month move in the total may describe one group's operational tempo rather than any change in the threat facing a given company.

It also means the count is fragile in a specific direction. If either group were disrupted, the total would fall sharply, and the fall would be reported as ransomware declining rather than as one supplier going offline. The same arithmetic that makes concentration a defensive opportunity makes the statistic unreliable as a trend line.

For a defender the practical consequence is more useful than the caution: the tradecraft you are most likely to encounter is not an average of all ransomware. It is these two, plus whoever is active in your sector, and that is a far smaller body of published reporting to actually read.

What a defender should take from it

Not the total. Three things underneath it.

If you are in finance, technology, pharmaceutical billing or education, your sector's share of attacker attention rose materially last month, and in finance the reason is likely that your peers pay. That is worth knowing before an incident. The decision to pay is one of the few that is easier to make in advance than under pressure.

Two groups accounting for a third of activity means the tradecraft you are most likely to meet is theirs. Published reporting on The Gentlemen and Qilin is a better guide to what to detect than a generic ransomware playbook.

And treat any figure sourced from leak sites as a floor with unknown error, not a precise measurement, especially when it appears in a vendor's slide showing your industry is under siege.

What to watch

Whether August passes March's 805 and makes 2026 a record year on this measure. Whether the finance increase persists or was a one-month concentration by one group. And whether anyone publishes a confirmed-incident series alongside the claimed one, because the gap between 799 and 51 is the most interesting unmeasured quantity in this field.