According to a new Comparitech study published today, Q3 2026 saw the highest quarterly figures to date with 2,627 ransomware attacks in total – an average of nearly 29 per day. This is a 29 percent increase on Q2 2026 which logged 2,030 attacks in total, and a 61 percent increase on the same period last year (Q3 2025).
Additional key findings include:
- Of 247 confirmed attacks:
- 138 were on businesses
- 53 were on government entities
- 36 were on healthcare companies
- 20 were on educational institutions
- Of the 2,380 unconfirmed attacks*:
- 2,096 were on businesses
- 71 were on government entities
- 152 were on healthcare companies
- 55 were on educational institutions
- Median ransom demand: $150,000 (average: $602,400)
- The most prolific ransomware gangs were Qilin and The Gentlemen
For full details, the research can be read here: https://www.comparitech.com/news/ransomware-roundup-q3-2026-stats-on-attacks-ransoms-and-active-gangs/
Rebecca Moody, Head of Data Research at Comparitech, provided the following comment:
“I’m often asked what I think lies ahead in the ransomware threat landscape, and it’s notoriously difficult to predict. Figures frequently fluctuate and a sector might see a bit of an increase one month, only to see a slight decrease the next month. However, Q3 2026 is different. We’re not seeing slight increases or decreases. We’re seeing significant increases across all key sectors.
Government agencies, healthcare providers, and the education sector all saw huge increases, as did the majority of business sectors. Seeing some of the most significant rises were tech companies (who often deal with multiple companies and are, therefore, a great central target for hackers), finance companies (who may also deal with a number of companies and/or store highly sensitive data), and utility companies (that form an integral part of our critical infrastructure).
What’s also of note is hackers’ increasing attempts at triple extortion. They’re not only seeking to encrypt systems and steal data, but are also looking to target individuals/individual companies impacted in an attack. A prime example is The Gentlemen’s recent attack on MIP Holdings (a South African tech company). After being targeted by the group in June 2026, MIP paid a ransom to have stolen data deleted. Over the last few weeks, however, The Gentlemen has started adding MIP’s clients to its data leak site in a bid to get a ransom out of them, too. A key reminder that paying a ransom is absolutely no guarantee that your stolen data will be deleted!”
Related
This entry was posted on October 6, 2026 at 9:34 am and is filed under Commentary with tags Comparitech. You can follow any responses to this entry through the RSS 2.0 feed.
You can leave a response, or trackback from your own site.
Q3 2026 Ransomware Roundup: Stats on attacks, ransoms, and active gangs
According to a new Comparitech study published today, Q3 2026 saw the highest quarterly figures to date with 2,627 ransomware attacks in total – an average of nearly 29 per day. This is a 29 percent increase on Q2 2026 which logged 2,030 attacks in total, and a 61 percent increase on the same period last year (Q3 2025).
Additional key findings include:
For full details, the research can be read here: https://www.comparitech.com/news/ransomware-roundup-q3-2026-stats-on-attacks-ransoms-and-active-gangs/
Rebecca Moody, Head of Data Research at Comparitech, provided the following comment:
“I’m often asked what I think lies ahead in the ransomware threat landscape, and it’s notoriously difficult to predict. Figures frequently fluctuate and a sector might see a bit of an increase one month, only to see a slight decrease the next month. However, Q3 2026 is different. We’re not seeing slight increases or decreases. We’re seeing significant increases across all key sectors.
Government agencies, healthcare providers, and the education sector all saw huge increases, as did the majority of business sectors. Seeing some of the most significant rises were tech companies (who often deal with multiple companies and are, therefore, a great central target for hackers), finance companies (who may also deal with a number of companies and/or store highly sensitive data), and utility companies (that form an integral part of our critical infrastructure).
What’s also of note is hackers’ increasing attempts at triple extortion. They’re not only seeking to encrypt systems and steal data, but are also looking to target individuals/individual companies impacted in an attack. A prime example is The Gentlemen’s recent attack on MIP Holdings (a South African tech company). After being targeted by the group in June 2026, MIP paid a ransom to have stolen data deleted. Over the last few weeks, however, The Gentlemen has started adding MIP’s clients to its data leak site in a bid to get a ransom out of them, too. A key reminder that paying a ransom is absolutely no guarantee that your stolen data will be deleted!”
Share this:
Like this:
Related
This entry was posted on October 6, 2026 at 9:34 am and is filed under Commentary with tags Comparitech. You can follow any responses to this entry through the RSS 2.0 feed. You can leave a response, or trackback from your own site.