Comparitech counted 799 ransomware incidents in July 2026, up from 668 in June — a jump of nearly 20% in a single month, and the second-busiest month of the year behind March's 805.

The shape of the surge

The headline number matters less than what's underneath it:

  • Qilin is dominant. It was the most common ransomware family across Europe, hitting organizations in 26 of the 31 countries analyzed, with 372 recorded incidents attributed to it.
  • Consolidation, not fragmentation. Q2 2026 analysis points to leading gangs consolidating attacks rather than the ecosystem splintering — fewer, bigger operators running more volume.
  • AI is streamlining extortion. Not the exploitation itself so much as the industrialized parts: victim triage, negotiation, and pressure campaigns.

Who got hit in early August

The pace didn't slow going into August:

  • TUI China — hit by Dragonforce, with passports and financial documents reportedly at risk.
  • Freedom Claims Management, a US insurance firm — hit by Qilin.
  • Hans & Jos. Kronenberg GmbH, a German elevator industry firm — hit by the Payload group.

That spread is the point: a travel company, an insurer, and an industrial manufacturer, in three countries, in roughly a week. There is no sector consensus about who's a target anymore.

The Register's framing was blunt: ransomware attacks are spiking while the world is distracted by AI. Attention is a finite security resource, and right now most of it is pointed elsewhere.

The "new normal" framing is doing work

Industry reporting has started describing this volume as an elevated new normal — attack rates holding steady at a level that would have been considered a crisis spike two years ago, now treated as the baseline.

That reframing matters for how you set expectations internally. If your incident response plan was sized against 2023 volumes, it's sized against a baseline that no longer exists.

What to actually do about it

  1. Check whether Qilin's known TTPs are covered by your detections specifically — a single family accounting for that share of incidents justifies naming it in your threat model rather than treating ransomware as one generic category.
  2. Test the restore, not the backup. Backup jobs that complete successfully and restores that actually work are different claims.
  3. Assume the extortion is multi-channel. Data theft plus encryption plus direct customer contact is standard now; a recovery plan that only addresses "can we get our files back" addresses a third of the problem.