← All stories
● Covered by 1 source · 1 reportMedium impact1 neutral

Ransomware Victim Claims Reached Year-to-Date High in July 2026, NCC Group Reports

🔄 Updated 1h ago
New to BrevFeed? We gather this story from every outlet covering it into one summary — ranked by real-world impact, not just the latest headline — so you never miss what matters. What is BrevFeed? →

Key points

  • July 2026 saw 894 ransomware victim listings, a year-to-date high.
  • Global ransomware attacks increased by 22% in July compared to June.
  • First incident of a fully agentic AI ransomware attack chain recorded in July.
  • Industrial, consumer services, and technology sectors were primary targets.

Ransomware Activity Surges in July 2026

NCC Group's July threat advisory report indicates a significant increase in ransomware activity, with 894 victim organization listings recorded in July 2026. This marks a year-to-date high and represents a 22% increase in global ransomware attacks compared to June 2026. The report also noted the first recorded incident of a fully agentic AI ransomware attack chain during this period.

Contributing Factors and Targeted Sectors

The surge in ransomware activity is attributed to the emergence of new ransomware groups, including "The Gentleman," and the use of agentic AI in attack chains. Industrial, consumer services, and technology sectors were the most frequently targeted, alongside critical services, finance, and healthcare. Geographically, 41% of recorded incidents occurred in the US, 29% in Europe, 14% in Asia, and 9% in South America.

Notable Incidents and Cybercriminal Claims

Several high-profile organizations were affected in July, including Ernst & Young (EY), which experienced a data breach claimed by ShinyHunters, and Coca-Cola's Fairlife, which suffered an attack attributed to Anubis. While some incidents involved verified data theft, the report suggests that some new cybercriminal groups, such as CRPxO, may inflate victim claims to establish their reputation. CRPxO, operating a Ransomware-as-a-Service (RaaS) model, claimed 36 hacks shortly after its emergence.

✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →

The daily brief

One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.

One email a day. Unsubscribe in one click, any time.

Today's brief

Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.

~10 min · 8 stories · Aug 26

▶ Play today's brief Listen on Spotify

New every morning, and the back catalogue is archived by date.

Primary sources

GitHub uuidjs/uuid

Reporting from

Ransomware activity recorded a year-to-date high of 894 victim organization listings in July 2026, according to NCC Group research. This increase is attributed to new ransomware groups, the emergence of agentic AI in attacks, and potentially inflated claims by cybercriminals. The rise in activity impacts various sectors globally, with a significant portion of incidents occurring in the US.