Skip to content

SecurityNot yet confirmed elsewhere1 publisher2 min readPublished

Victims confirmed 247 of a record 2,627 ransomware claims in Q3, Comparitech says

Comparitech counted 2,627 ransomware attacks claimed in Q3 2026, a quarterly record up 27% on Q2 and 61% on a year earlier. Victims have confirmed 247 of those claims, so the record is mostly a count of what the gangs themselves assert.

The Watch · Security desk

How we use AISend a correction

Illustration accompanying Victims confirmed 247 of a record 2,627 ransomware claims in Q3, Comparitech says
Generated illustration

What happened

  • Finance and technology grew fastest against Q2, with claimed attacks up 72% and 70% respectively.
  • Qilin claimed 357 attacks and The Gentlemen 342, making them the quarter's most prolific groups, up 24% and 29% on Q2.
  • Organisations in the US accounted for 1,066 claimed attacks, 41% of the quarter's total and 34% more than in Q2.
  • The average ransom demand Comparitech recorded for the quarter was $602,400.

Compiled by The WatchSomething wrong?How this is made

Why it matters

  • constraint Every sector rate in the report is built on claims, so a growth figure for finance or healthcare cannot be read as the same growth in confirmed breaches until more victims disclose.
  • exposure Clients of a breached supplier become extortion targets in their own right, reachable through the supplier's stolen data even after the supplier has paid.
  • decision Deletion is a weaker reason to pay. MIP paid for it, and Moody said the case shows a ransom is no guarantee the attacker keeps its word on deleting data.

Victims have confirmed 9.4% of the quarter's claims [21]. The other 2,380 rest on the word of the group that claimed them [22]. Comparitech's report, published October 7, counts attacks claimed by ransomware groups, and the 247 confirmations came from the entities involved [5][11].

"Figures frequently fluctuate and a sector might see a bit of an increase one month, only to see a slight decrease the next month. However, Q3 2026 is different. We're not seeing slight increases or decreases. We're seeing significant increases across all key sectors," said Rebecca Moody, head of data research at Comparitech [6]. The growth she describes goes beyond the two fastest-rising sectors. Claims against education rose 50% on Q2, healthcare 39%, government 36% and utilities 32% [4]. Working back from the 27% quarterly rise puts Q2 at roughly 2,070 claims [23].

Qilin and The Gentlemen together claimed 699 attacks, 26.6% of the quarter [24]. Clop's 4,700% rise is one claim in Q2 becoming 48 in Q3, an increase of 47 [16][25]. Direwolf's claims rose 1,450% over the same period [17].

Germany followed the US with 121 claims, up 22% [19]. Claims against Argentina and India rose fastest on Q2, by 150% and 116% [20].

Infosecurity Magazine's account of the report offers developments in AI as a possible explanation for the surge. It says the technology lets attackers raise the scale, speed and effectiveness of campaigns [26]. It cites JadePuffer, a campaign researchers identified in July and believed to be the first ransomware attack completely driven by AI [7]. The account does not attribute any share of the 2,627 claims to AI-run operations [26].

Triple extortion adds a third step after encryption and data theft. The gang goes after the individuals affected by the attack, and the report found more attackers doing it [8]. The clearest case in the report involves The Gentlemen, second only to Qilin by claimed volume [15]. Moody said the group hit MIP Holdings, a South African tech company [9]. "After being targeted by the group in June 2026, MIP paid a ransom to have stolen data deleted. Over the last few weeks, however, The Gentlemen has started adding MIP's clients to its data leak site in a bid to get a ransom out of them, too," she said [9].

The victims refused in both of the quarter's largest known demands [13][14]. Everest asked Swiss railway manufacturer Stadler Rail for $12.3m in July and leaked 201 GB of stolen data after Stadler refused [13]. Rhysida demanded $2.3m from the State of Berlin, then published 5.7 TB, including citizens' personal information, after the state government publicly refused [14].

What to watch

  • Whether more of the 2,380 unconfirmed Q3 claims are confirmed by the named organisations as disclosures catch up.
  • Whether The Gentlemen's listing of MIP Holdings' clients produces payments, or the group starts listing the clients of other victims that paid.
  • Comparitech's Q4 2026 count, and whether Qilin and The Gentlemen keep the growth they showed from Q2 to Q3.

Clarity's read

What the record supports and how the coverage leans. The claims behind it follow.

Reality

Evidence42
Adoption
Insufficient
Hype gap+30
Incentives
Insufficient
Confidence40
Why these scores

Claim ledger

Ranked by verification strength, evidence, and original report placement.

  1. [1]

    Comparitech identified 2,627 claimed ransomware attacks from July to September 2026, the highest quarterly volume on record.

    ReportedSupportedSource: Comparitech analysis, reported by Infosecurity MagazineView cited source
  2. [2]

    The Q3 2026 total was a 27% increase on Q2 2026 and a 61% rise on Q3 2025.

    ReportedSupportedSource: ComparitechView cited source
  3. [3]

    Finance and technology saw the biggest growth in ransomware incidents in Q3 compared with Q2 2026, up 72% and 70% respectively.

    ReportedSupportedSource: ComparitechView cited source

Sources

1 independent publisher whose own reporting we read for this story.

  1. infosecurity-magazine.com

    1 article · October 9, 2026

    Q3 2026 Sets New Record for Ransomware Attacks

Share your take

Let Clarity write the post for you.

Signed-in readers get a short post drafted on this story in the register they choose — narrative, analytical, or a direct position — editable to the last word before it goes anywhere. The share buttons at the top of this story work without an account.

Topics and entities

Follow any of these and your For You feed starts watching them — no settings page required.

Entities

Loading related stories