Skip to content
Live newsroom 146 readers online
Wednesday, August 26, 2026 Live Sync: Just now
Demystifying Finance, Technology, and Global Markets for the Next Generation.
BreakingApple’s September iPhone event: Date, time, and what will launch
Important BUY HINDUNILVR Stage 2 (Conv: 5/5 | Size: 20%)

Ransomware attack volumes hit ‘high-water-mark’ in July

July saw ransomware attacks reach a peak of 894 recorded attacks, hitting the highest level seen so far this year, up almost a quarter on June, according to NCC Group’s latest monthly Threat Intelligence Report. Though much attention remains on the impact of artificial intelligence (AI) on the cyber security world, NCC said the number […]

By deepak · August 26, 2026 · 3 min read

July saw ransomware attacks reach a peak of 894 recorded attacks, hitting the highest level seen so far this year, up almost a quarter on June, according to NCC Group’s latest monthly Threat Intelligence Report.

Though much attention remains on the impact of artificial intelligence (AI) on the cyber security world, NCC said the number of ransomware incidents remains high, although still substantially lower than the current monthly record, 1,099, set in February 2025.

And the July rise may have been driven at least in part by advances in AI. In early July, the existence emerged of an agentic threat actor known as Jadepuffer that appeared to be able to execute a successful, end-to-end ransomware intrusion entirely autonomously.

Given the proliferation of other incidents involving AI agents in recent weeks, NCC said that agents capable of operating without human oversight are clearly now reality – although to date they have been motivated less by financial gain and more as a proof of concept – and that similar attacks could become more common in future

“AI is changing the speed and scale of cyber attacks. It’s allowing attackers to automate more of what they do, operate at greater scale and create increasingly convincing phishing, social engineering and other malicious content. That can make threats harder for both organisations and individuals to identify,” said NCC vice president of cyber intelligence and response, Matt Hull.

"For organisations, the response doesn’t need to be complicated. Getting the fundamentals right remains incredibly important: strong identity and access controls, good vulnerability management, visibility across your environment and the ability to detect and respond quickly when something goes wrong.

"There’s also a human element,” said Hull. “As AI-generated content becomes more convincing, employees need to understand what threats look like, know when something doesn’t feel right and have a simple way to report it.

"AI is equally valuable for defenders, helping security teams process information faster and identify potentially malicious activity. The challenge is making sure we use that technology effectively while maintaining the human judgement needed to understand what represents a genuine threat,” he added.

Of the almost-900 attacks, 41% targeted organisations in North America, and 29% in Europe, and The Gentlemen accounted for 15% of all attacks. Originally a splinter group from the Qilin operation – supposedly the split happened following an argument over a ransom payment – The Gentlemen have scaled more rapidly than any other group recorded, claiming well over 300 victims in a year.

Also on the rise in July was a group dubbed CRPxO, which claimed responsibility for 36 attacks last month. However, said NCC, this new player may not be all it is cracked up to be.

“CRPxO should be assessed as a credible but only partially verified actor, with moderate confidence that at least some of its victim claims are legitimate,” wrote the report’s authors.

NCC said that while it does operate a functioning ransomware-as-a-service RaaS ecosystem including a leak site and affiliate programme, inconsistent evidence, dubious claims, and operational security weakness suggest it is still highly immature. T

This may reflect an increasingly prevalent tactic among emergent ransomware gangs of exaggerating their activities to make themselves seem more threatening but, added the analysts, this tactic may yet backfire on the person or persons behind CRPxO.

“The long-term success of the ransomware group will likely depend on its ability to show credible victim compromises and maintain trust among potential affiliates,” explained the team.

“If unsupported or exaggerated victim claims continue to appear prominently on its leak site, it could damage its reputation within the cybercriminal ecosystem and limit its ability to compete with more established RaaS operations.”

Source: Read the original article on www.computerweekly.com