Security2 publishers3 min readPublished
Ransomware climbed to a second straight 2026 high of 1,073 attacks in August
NCC Group counted 1,073 ransomware attacks in August, a second straight 2026 high and 12% above July. Industrial companies took 31% of them, up from 28% in July, so the hardest-hit sector drew a larger slice of a larger total.
The Watch · Security desk

What happened
- Qilin was linked to 164 of August's attacks, which put it ahead of The Gentlemen at 116 and made it the most active group of the month.
- North America took 44% of the attacks and Europe 26%, the same concentration in Western regions that NCC reported in earlier months.
- NCC's incident responders worked an August case at a transportation company where the Aurora group left a short ransom note on an encrypted hypervisor.
- According to NCC's report, an intrusion at Boston Scientific disrupted the company's manufacturing, shipping and customer order processing worldwide.
Compiled by The WatchSomething wrong?How this is made
Why it matters
- contradiction NCC and Infosecurity give different July totals, so anyone tracking month-on-month growth has two baselines, and only NCC's 960 produces the published 12%.
- exposure On NCC's own rounded shares, industrial operators took a larger part of August's growth than their share of the total would suggest.
- precedent Qilin and The Gentlemen have swapped the top spot several times this year, so another swap is likely and Qilin moving ahead says little about whether the threat is growing.
- decision NCC's own casework points defensive spending at exposed VPNs and at recovering encrypted hypervisors, however much weight Hull's AI explanation deserves.
The 12% figure only works from NCC's own baseline. The release puts July at 960 attacks, which was itself the year's high at the time [2]. Against 960, August's 1,073 is an 11.8% rise [1]. Infosecurity Magazine covered the report after its September 23 publication [4] and gave July as 973 [3]. On that base the rise is 10.3% [2]. Either base leaves two record months in a row, July and August, and that is as far as the figures in hand go. Matt Hull, NCC's vice president of cyber intelligence and response, reads a trend into them. "August was the second consecutive month of highest ransomware levels for the year, indicating a steady rise in global activity," he said [5].
Industrial companies took more of the growth than their share suggests. The sector had 28% of July's 960 attacks and 31% of August's 1,073. That is roughly 269 attacks rising to roughly 333, an increase of about 24% [4]. Because the shares are rounded, the true rise is somewhere between about 20% and 28%. Even the low end is well above the overall 12% [4]. NCC called the higher share "a signal of the growing target on critical infrastructure organisations as threat actors look to cause mass disruption" [14].
Qilin's count comes to 15.3% of the month [3]. That matches the 15% NCC gave when it said Qilin had overtaken The Gentlemen [7]. Infosecurity reported that the two groups have regularly traded places as the most prolific actor of 2026 [9]. Clop was third with 89 attacks, and Dire Wolf and INC Ransom had 43 each [10]. Those five groups account for 455 attacks, about 42% of the total. The other 618 belong to smaller groups or could not be linked to a known actor [5].
Aurora is the one group the release profiles from NCC's own incident work. It first appeared this year. It has hit organisations in manufacturing, legal, and research and development, and it has broken in by exploiting VPNs, "a technique already common" in NCC's words [15]. In the transportation case, the ransom note told the victim to get in touch through the Tor browser at a supplied .onion link, using the organisation's access key [16]. NCC did not name the VPN products or the vulnerabilities Aurora used. The firm wrote that "data extortion is now also a priority end goal, alongside encryption and, in some cases, destruction" [17].
Hull puts the rise down to AI and geopolitics. "A combination of factors is driving this increase including rapid advancements in AI and ongoing geopolitical volatility which are fuelling state-sponsored threats," he said [6]. The same release calls Aurora's methods "nothing new" [17].
What to watch
- NCC's September report: a third record month in a row would lengthen the run, while a drop would make July and August look like a peak.
- Publication of the VPN products or CVEs Aurora exploits, which would give defenders something specific to patch.
- Whether The Gentlemen take the top spot back from Qilin in September, as the two groups have done repeatedly this year according to Infosecurity.