Comparitech counted 2,627 claimed ransomware attacks in the third quarter of 2026 — July to September — the highest quarterly figure it has recorded. August alone was 997, a monthly record, beating 988 from February 2025.
Against the second quarter's 2,030 that is a rise of about 29 percent. Against the third quarter of 2025, at 1,636, about 61 percent. One outlet reports the quarterly rise as 27 percent; the arithmetic on the two published totals gives 29, and we are going with the arithmetic.
Now the number that should travel with all of those and usually does not.
247
Of the 2,627, 247 were confirmed by the organisations affected. The other 2,380 are unconfirmed.
That is not a criticism of the methodology, which is transparent about this. It is a point about what the figure measures. Counts like this are assembled largely from gang leak sites — the pages where ransomware operations post the names of organisations they say they have hit, to pressure them into paying.
A leak-site post is a claim by an interested party. It can be true. It can also be a re-post of an old victim, a victim who was never encrypted, an organisation reached through a supplier and counted as a direct hit, or a name added for leverage. Nine out of ten entries in a record quarter are claims of that kind.
So the headline reads as a measure of attacks and is also, unavoidably, a measure of how much the gangs are claiming — which is a function of how many leak sites exist, how aggressively they post, and how many groups are competing for attention.
Our own reporting is a reason to doubt the count in the other direction
The count can miss in the other direction too. We wrote this week about a Gentlemen affiliate who published his victims on his own leak site rather than the group's, keeping the proceeds. More than two dozen organisations across six countries, and by CloudSEK's account none of them appeared where a counter would look.
Which lands awkwardly beside this quarter's list of the most prolific groups: Qilin and The Gentlemen. The Gentlemen are near the top of a count assembled from leak-site postings, during a period when at least one of their affiliates was routing victims away from the group's leak site entirely.
The honest conclusion is not that the number is too high or too low. It is that it is a measurement of leak-site activity, and leak-site activity is a choice attackers make.
What the confirmed subset says
The 247 confirmed cases are the firmer ground, and the breakdown is worth more than the headline: 138 businesses, 53 government entities, 36 healthcare organisations, 20 educational institutions.
On sectors, retail is the standout in the full dataset — 199 attacks, up from 154 the previous quarter and nearly double the 101 in the third quarter of 2025. Finance, technology, education and healthcare are also reported as rising significantly.
The average and the median are 450,000 apart
Average demand for the quarter: 602,400 dollars. Median: 150,000.
That gap is the most useful pair of numbers here. A mean four times the median means a small number of very large demands are pulling the average up, and that the typical victim is facing something far smaller than the headline figure suggests.
For anyone sizing a risk, the median is the number that describes the likely case and the mean is the number that describes the tail. Reporting that quotes only the average — most of it — describes an experience most victims will not have.
What to take from it
- The direction is real. Three independent framings — quarter on quarter, year on year, and a record single month — all point up, and that is harder to explain away as counting artefacts than any single figure.
- The magnitude is soft. Treat 2,627 as an upper bound on claimed incidents, not a count of successful encryptions.
- The sector movement is the actionable part. Retail nearly doubling year on year is a reason for retailers to look at their own exposure regardless of what the total says.
- Quote the median alongside the mean, or neither.
What is not established
- How many of the 2,380 unconfirmed claims are real.
- Whether the rise reflects more attacks, more claiming, more groups, or better collection by the researchers. All four would produce this shape.
- How many victims paid. Demand figures are not payment figures, and the payment rate is not in this data.
- How the double-counting of supply-chain victims is handled, where one intrusion produces many affected organisations.
- Whether the groups near the top of the list are the most active or the most public. On this quarter's evidence those are not the same question.