Ransomware Attacks Hit Record High in August 2026 as Qilin Leads Global Surge
- 34 minutes ago
- 2 min read
Comparitech recorded 997 known and suspected ransomware attacks during August, averaging more than 32 incidents per day. The United States accounted for nearly 42 percent of the total.
Ransomware activity reached a record high in August 2026, with cybersecurity researchers tracking 997 attacks worldwide during the month, according to new research from Comparitech.
The total represents an average of more than 32 ransomware attacks per day. Researchers independently confirmed 77 incidents through disclosures from the affected organizations, while the remaining 920 were claimed by ransomware groups but had not been publicly verified.
Businesses absorbed most of the damage. Of the confirmed incidents, 49 affected companies, 18 struck government organizations, eight involved healthcare providers and two targeted educational institutions.
The same pattern appeared among unconfirmed claims. Businesses accounted for 812 alleged attacks, followed by 61 against healthcare organizations, 22 involving educational institutions and 21 targeting government entities.
Qilin emerged as the most active ransomware group, claiming 157 victims and accounting for 12 confirmed attacks. The Gentlemen ranked second with 107 claimed victims and eight confirmed incidents.
The United States remained the largest target by a significant margin, recording 417 attacks. Germany and Italy followed with 48 each, while the United Kingdom recorded 36 and Canada registered 35.
One of August’s most consequential incidents involved the Berlin state government. Officials reportedly rejected a $2.3 million ransom demand from the Rhysida ransomware group, but the financial fallout could be far greater. Rebuilding compromised computer systems may cost as much as €100 million, or approximately $116 million, while more than 1 million files were reportedly exposed.
“Ransomware threats are escalating across most sectors and continue to have a devastating impact on those affected,” said Rebecca Moody, head of data research at Comparitech.
The Berlin breach may also have exposed information connected to critical infrastructure. Moody warned that increased attacks against utilities, healthcare providers, manufacturers, technology companies and financial institutions demonstrate why essential services remain attractive targets.
“By targeting these sectors, hackers are not only causing mass disruption by encrypting systems but they're also gaining access to highly sensitive data, including personal data and information about critical systems and infrastructure,” Moody said.
The August figures reinforce a persistent problem for defenders. Modern ransomware operations increasingly combine system encryption with data theft, giving attackers multiple ways to pressure victims even when organizations refuse to pay.
Read the full Comparitech ransomware report.

