SecurityNot yet confirmed elsewhere1 publisher2 min readPublished
Victims confirmed 247 of a record 2,627 ransomware claims in Q3, Comparitech says
Comparitech counted 2,627 ransomware attacks claimed in Q3 2026, a quarterly record up 27% on Q2 and 61% on a year earlier. Victims have confirmed 247 of those claims, so the record is mostly a count of what the gangs themselves assert.
The Watch · Security desk

What happened
- Finance and technology grew fastest against Q2, with claimed attacks up 72% and 70% respectively.
- Qilin claimed 357 attacks and The Gentlemen 342, making them the quarter's most prolific groups, up 24% and 29% on Q2.
- Organisations in the US accounted for 1,066 claimed attacks, 41% of the quarter's total and 34% more than in Q2.
- The average ransom demand Comparitech recorded for the quarter was $602,400.
Compiled by The WatchSomething wrong?How this is made
Why it matters
- constraint Every sector rate in the report is built on claims, so a growth figure for finance or healthcare cannot be read as the same growth in confirmed breaches until more victims disclose.
- exposure Clients of a breached supplier become extortion targets in their own right, reachable through the supplier's stolen data even after the supplier has paid.
- decision Deletion is a weaker reason to pay. MIP paid for it, and Moody said the case shows a ransom is no guarantee the attacker keeps its word on deleting data.
Victims have confirmed 9.4% of the quarter's claims [21]. The other 2,380 rest on the word of the group that claimed them [22]. Comparitech's report, published October 7, counts attacks claimed by ransomware groups, and the 247 confirmations came from the entities involved [5][11].
"Figures frequently fluctuate and a sector might see a bit of an increase one month, only to see a slight decrease the next month. However, Q3 2026 is different. We're not seeing slight increases or decreases. We're seeing significant increases across all key sectors," said Rebecca Moody, head of data research at Comparitech [6]. The growth she describes goes beyond the two fastest-rising sectors. Claims against education rose 50% on Q2, healthcare 39%, government 36% and utilities 32% [4]. Working back from the 27% quarterly rise puts Q2 at roughly 2,070 claims [23].
Qilin and The Gentlemen together claimed 699 attacks, 26.6% of the quarter [24]. Clop's 4,700% rise is one claim in Q2 becoming 48 in Q3, an increase of 47 [16][25]. Direwolf's claims rose 1,450% over the same period [17].
Germany followed the US with 121 claims, up 22% [19]. Claims against Argentina and India rose fastest on Q2, by 150% and 116% [20].
Infosecurity Magazine's account of the report offers developments in AI as a possible explanation for the surge. It says the technology lets attackers raise the scale, speed and effectiveness of campaigns [26]. It cites JadePuffer, a campaign researchers identified in July and believed to be the first ransomware attack completely driven by AI [7]. The account does not attribute any share of the 2,627 claims to AI-run operations [26].
Triple extortion adds a third step after encryption and data theft. The gang goes after the individuals affected by the attack, and the report found more attackers doing it [8]. The clearest case in the report involves The Gentlemen, second only to Qilin by claimed volume [15]. Moody said the group hit MIP Holdings, a South African tech company [9]. "After being targeted by the group in June 2026, MIP paid a ransom to have stolen data deleted. Over the last few weeks, however, The Gentlemen has started adding MIP's clients to its data leak site in a bid to get a ransom out of them, too," she said [9].
The victims refused in both of the quarter's largest known demands [13][14]. Everest asked Swiss railway manufacturer Stadler Rail for $12.3m in July and leaked 201 GB of stolen data after Stadler refused [13]. Rhysida demanded $2.3m from the State of Berlin, then published 5.7 TB, including citizens' personal information, after the state government publicly refused [14].
What to watch
- Whether more of the 2,380 unconfirmed Q3 claims are confirmed by the named organisations as disclosures catch up.
- Whether The Gentlemen's listing of MIP Holdings' clients produces payments, or the group starts listing the clients of other victims that paid.
- Comparitech's Q4 2026 count, and whether Qilin and The Gentlemen keep the growth they showed from Q2 to Q3.
Clarity's read
What the record supports and how the coverage leans. The claims behind it follow.
Reality
- Evidence42
- Adoption
- Insufficient
- Hype gap+30
- Incentives
- Insufficient
- Confidence40
Claim ledger
Ranked by verification strength, evidence, and original report placement.
- [1]
Comparitech identified 2,627 claimed ransomware attacks from July to September 2026, the highest quarterly volume on record.
- [2]
The Q3 2026 total was a 27% increase on Q2 2026 and a 61% rise on Q3 2025.
- [3]
Finance and technology saw the biggest growth in ransomware incidents in Q3 compared with Q2 2026, up 72% and 70% respectively.
- [4]
Attacks rose in education (up 50%), healthcare (39%), government (36%) and utilities (32%) in Q3 compared with Q2.
- [5]
Of the 2,627 attacks claimed by ransomware groups in Q3, 247 have been confirmed by the entity involved.
- [6]
Figures frequently fluctuate and a sector might see a bit of an increase one month, only to see a slight decrease the next month. However, Q3 2026 is different. We're not seeing slight increases or decreases. We're seeing significant increases across all key sectors.
- [7]
In July, researchers identified the JadePuffer campaign, believed to be the world's first ransomware attack completely driven by AI.
- [8]
The report highlighted an increase in triple extortion, in which attackers encrypt systems, exfiltrate data and also target individuals impacted by the attack.
- [9]
A prime example is The Gentlemen's recent attack on MIP Holdings (a South African tech company). After being targeted by the group in June 2026, MIP paid a ransom to have stolen data deleted. Over the last few weeks, however, The Gentlemen has started adding MIP's clients to its data leak site in a bid to get a ransom out of them, too.
- [10]
Moody said the tactic shows that paying a ransom is no guarantee the attacker will keep its word about deleting stolen data.
- [11]
The Comparitech report was published on October 7.
- [12]
The average ransomware demand in Q3 was $602,400.
- [13]
The largest known demand in the period was $12.3m, issued by Everest against Swiss railway manufacturer Stadler Rail in July 2026; Stadler refused to pay and Everest leaked 201 GB of stolen data.
- [14]
Next largest, Rhysida demanded $2.3m from the State of Berlin after compromising its network and published 5.7 TB of stolen data, including citizens' personal information, after the state government publicly refused to pay.
- [15]
Qilin and The Gentlemen were the most prolific groups in Q3, claiming 357 and 342 attacks, rises of 24% and 29% on Q2.
- [16]
Clop increased its claimed attacks by 4,700%, from one in Q2 to 48 in Q3.
- [17]
Claimed attacks by Direwolf rose 1,450% over the same period.
- [18]
The US had the most attacks in Q3 at 1,066, 41% of the total and a 34% rise from Q2.
- [19]
Germany followed the US with 121 attacks, up 22%.
- [20]
Argentina and India had the biggest jumps in claimed attacks in Q3 compared with Q2, up 150% and 116%.
- [21]
Victims have confirmed about 9.4% of the Q3 claims.
- [22]
2,380 of the Q3 claims are unconfirmed by the entities named.
- [23]
The implied Q2 2026 total is roughly 2,070 claimed attacks.
- [24]
Qilin and The Gentlemen together claimed 699 attacks, 26.6% of the Q3 total.
- [25]
Clop's 4,700% rise is an increase of 47 claimed attacks.
- [26]
Infosecurity Magazine's account presents developments in AI as a possible explanation for the surge, enabling attackers to increase the scale, speed and effectiveness of campaigns; it does not quantify any share of claims attributable to AI.
Sources
1 independent publisher whose own reporting we read for this story.
- infosecurity-magazine.comQ3 2026 Sets New Record for Ransomware Attacks
1 article · October 9, 2026
Topics and entities
Follow any of these and your For You feed starts watching them — no settings page required.