Ransomware Hits Record in August 2026: 1,073 Victims
NCC Group report reveals 1,073 ransomware victims in August, a 12% increase over July and the highest count of the year. The industrial sector accounted for 31% of cases, with Qilin and The Gentlemen leading.

The number of companies affected by ransomware in August reached 1,073, the highest monthly total of 2026, according to the NCC Group's threat intelligence report published on September 23. This volume represents a 12% increase from July, when 973 organizations were listed as victims, previously holding the record for the year. The British consultancy describes August as the second consecutive month of an annual high, indicating an upward trend rather than a one-off peak.
NCC’s count is based on victims published on the leak sites of criminal groups. It reflects public extortion, not the total number of attacks: companies that pay before exposure do not appear, and false or recycled claims sometimes enter. Even with this limitation, the monthly series is one of the few comparable over time and is monitored by insurers and incident response teams.
The Industrial Sector Becomes the Primary Target
The industrial sector accounted for nearly one-third of August’s cases, comprising 31% of the total, according to NCC. The operational rationale is well-known to any CISO in the field: a halted factory incurs high hourly costs, increasing the willingness to negotiate, and environments that mix IT systems with aging automation equipment have long correction windows.
In comparison to July, the industrial participation weighs more heavily because the total has grown: 31% of 1,073 translates to over 330 victims from the sector in a single month, a number surpassing that of any isolated criminal group during this period.
Qilin and The Gentlemen Lead the Pack
Among the attacks attributable to known groups, Qilin accounted for 164 cases in August and The Gentlemen for 116, according to the report. Together, these two represent 280 victims, approximately 26% of the month’s total. Qilin operates on a ransomware-as-a-service model, where affiliates rent encryption and extortion infrastructure and share the ransom with operators, placing it at the top of NCC’s count in August.
This concentration has practical implications. When two groups account for a quarter of the victims, the tactics, techniques, and procedures they use, documented by security vendors and government agencies, become the most efficient checklist for prioritizing controls. It is more cost-effective to close entry vectors from two dominant groups than to defend against a generic catalog of threats.
Where Attacks Occur: U.S., Europe, and Asia
North America accounted for 44% of August's incidents, Europe 26%, and Asia 13%, according to NCC. This distribution aligns with market sizes and propensity to pay ransoms but has distinct readings in each region.
In the U.S., publicly traded companies must report material cyber incidents to the SEC within four business days of determining materiality, a rule in effect since December 2023. This turns each successful attack into a market event. An example surfaced on the same day as the report: Astrana Health, an American healthcare service operator, reported to the SEC on September 23 a material cyber incident at a subsidiary.
In the UK and the European Union, the pressure comes from sector regulation. The NIS2 directive imposes short notification deadlines on operators of essential services, including transport and manufacturing, while the UK is discussing its own notification rules and restrictions on ransom payments in the public sector. In Asia, the 13% represents a smaller share, but industrial supply chains crossing Japan, South Korea, and Southeast Asia make local suppliers a gateway for American and European clients.
What Changes for 2027 Planning
The August record arrives as companies finalize security budgets for the upcoming year. Two consecutive months of increase weaken the argument that ransomware volume had stabilized following law enforcement operations in 2024 against groups like LockBit.
For boards of directors, the useful question is not whether the company is exposed, but how long operations can endure without their core systems. In the industrial sector, which accounts for nearly one-third of the victims, this calculation involves the separation between corporate networks and shop floor networks, the existence of backups out of reach of common administrative credentials, and a tested manual operation plan. These are the three areas where the response is often worse than the board imagines.