Security1 publisherNot yet confirmed elsewhere2 min readPublished
Check Point counts 2,803 weekly attacks per organization in September, up 48% on last year
Check Point says organizations averaged 2,803 cyber attacks a week in September, up 48% on a year earlier. The figures come from the vendor's own count, and they support checking mail link filtering and AI prompt controls before spending anything new.
The Watch · Security desk

What happened
- Check Point counted 824 ransomware attacks in September, 53% more than in September 2025.
- One in 39 enterprise GenAI prompts posed a high risk of leaking sensitive data, and 89% of organizations that use GenAI tools regularly were affected.
- Education was the most targeted sector, averaging 6,656 weekly attacks per organization, up 59% on the year as the academic year began.
Compiled by The WatchSomething wrong?How this is made
Why it matters
- decision A spending case built on the phishing rise has one month of movement behind it. The weekly attack climb from May to September is the steadier figure to put in a budget argument.
- constraint Attachment scanning does not inspect links, and 81% of this phishing carried them, so link handling is the mail control that covers most of the volume.
- exposure At more than three high-risk prompts per average user a month, leakage risk comes from ordinary staff use of AI tools, and Business Services firms run at about twice the global rate.
As a share of all email, phishing rose from about 0.89% in August to about 1.10% in September [15]. That works out to roughly 23% more phishing per message in one month [15]. Check Point found links in 81% of the phishing emails [4].
The weekly attack series covers a longer period. Check Point puts attacks per organization at 2,055 a week in May and 2,803 in September, a 36% rise over five months [2]. September alone was 16% above August [1].
Ransomware grew slightly faster than attacks overall, 53% on the year against 48% [5][1]. A 53% rise to 824 means about 539 attacks in September 2025 [16]. The published summary does not say how Check Point counts a ransomware attack, or what qualifies as an attack in its weekly totals [5].
The GenAI numbers count prompts Check Point flagged as a high risk of leaking sensitive data, at a global average of 2.5% [6][9]. Another 14% of prompts contained potentially sensitive information [7]. The average user wrote 131 prompts in September, and the average organization used eight GenAI tools [8]. At the global rate, 131 prompts include about 3.4 high-risk ones per user per month [17].
The rates vary widely by sector and region. Business Services ran at 4.9%, or 1 in 20 prompts, and Financial Services at 4.1%, or 1 in 25 [10]. Latin America had the highest regional rate at 1 in 25. North America was at 1 in 37, APAC at 1 in 48 and Europe at 1 in 57 [9].
Ranked by attack volume, the order changes. Education's count rose 24% from August alone [11]. Telecommunications was second at 3,483 weekly attacks per organization, up 29% on the year, and Government third at 3,443, up 37% [12]. Latin America led the regions on volume at 3,813 a week. Europe grew fastest at 61%, and North America rose 50% [13].
Check Point describes its conclusion as a "prevention-first view" and wrote that "organizations need AI-powered security, consistent visibility and shared intelligence across the full attack surface to reduce risk before it becomes business impact" [14].
What to watch
- Whether Check Point's October report keeps phishing near 1 in 91 emails or shows it falling back toward August's 1 in 112.
- Whether education's weekly attack count eases once the start-of-term reconnection period is over.
- Independent ransomware tallies for September that confirm or contradict Check Point's count of 824.
Clarity's read
What the record supports and how the coverage leans. The claims behind it follow.
Reality
- Evidence35
- Adoption
- Insufficient
- Hype gap+20
- Incentives80
- Confidence45
Claim ledger
Ranked by verification strength, evidence, and original report placement.
- [1]
Organizations experienced an average of 2,803 cyber attacks per week in September 2026, a 16% increase from August and a 48% increase compared with September 2025.
ReportedSupportedSource: Check Point Research, September 2026 Cyber Threat LandscapeView cited source - [2]
Weekly attacks per organization rose from 2,055 in May to 2,803 in September, an increase of 36% over five months.
- [3]
One in every 91 emails was classified as phishing in September, up from 1 in 112 in August.
- [4]
81% of phishing emails contained links.
- [5]
A total of 824 ransomware attacks were reported in September 2026, 53% more than in September 2025.
- [6]
One in every 39 enterprise GenAI prompts posed a high risk of sensitive data leakage, affecting 89% of organizations that regularly use GenAI tools.
- [7]
A further 14% of GenAI prompts contained potentially sensitive information.
- [8]
The average user generated 131 GenAI prompts during September, a significant increase from August, while each organization used an average of eight tools.
- [9]
Latin America recorded the highest regional rate of high-risk prompts at 1 in 25, or 4%, above the global average of 2.5%. North America followed at 1 in 37 prompts, APAC at 1 in 48 and Europe at 1 in 57.
- [10]
Business Services had the highest high-risk GenAI exposure rate at 4.9%, or 1 in every 20 prompts; Financial Services followed at 4.1%, or 1 in 25 prompts.
- [11]
Education was the most targeted industry in September, averaging 6,656 weekly attacks per organization, up 59% year over year and up 24% from August; the increase coincided with the start of the academic year.
- [12]
Telecommunications ranked second with 3,483 weekly attacks per organization, up 29% year over year, followed by Government with 3,443, up 37%.
- [13]
Latin America recorded the highest regional attack volume at 3,813 weekly attacks per organization, up 35% year over year; Europe had the highest growth rate at 61% year over year; North America rose 50% year over year.
- [14]
"Together, these findings reinforce Check Point's prevention-first view: organizations need AI-powered security, consistent visibility and shared intelligence across the full attack surface to reduce risk before it becomes business impact."
- [15]
Phishing share of email rose from about 0.89% in August to about 1.10% in September, roughly 23% more phishing per message.
- [16]
A 53% rise to 824 ransomware attacks implies about 539 attacks in September 2025.
- [17]
At 1 high-risk prompt in 39, the average user's 131 monthly prompts include about 3.4 high-risk prompts.
- [18]
Business Services' high-risk prompt rate of 4.9% is about twice the 2.5% global average.
Sources
1 independent publisher whose own reporting we read for this story.
Topics and entities
Follow any of these and your For You feed starts watching them — no settings page required.
Entities
- Check Point Software TechnologiesFollow