September 2026 Cyber Threat Landscape: Global Attacks Jump 48% as Phishing and GenAI Data Exposure Rise
Key takeaways
Organizations experienced 2,803 weekly cyber attacks on average in September, up 16% month over month and 48% year over year.
Education remained the most targeted sector, averaging 6,656 weekly attacks per organization, a 59% year-over-year increase.
Europe recorded the sharpest regional rise at 61% year over year, while Latin America faced the highest volume at 3,813 weekly attacks per organization.
One in every 39 enterprise GenAI prompts posed a high risk of sensitive data leakage, affecting 89% of organizations that regularly use GenAI tools.
One in every 91 emails was classified as phishing, up from 1 in 112 in August; 81% of phishing emails contained links.
A total of 824 ransomware attacks were reported, 53% more than in September 2025.
September’s data shows cyber pressure rising across multiple fronts. Weekly attack volumes increased sharply, phishing became more prevalent, GenAI use continued to expand alongside sensitive-data exposure, and ransomware remained well above last year’s level. Together, these findings reinforce Check Point’s prevention-first view: organizations need AI-powered security, consistent visibility and shared intelligence across the full attack surface to reduce risk before it becomes business impact.
Global Cyber Attacks Accelerate
Organizations experienced an average of 2,803 cyber attacks per week in September 2026. That represents a 16% increase from August and a 48% increase compared with September 2025. The longer trend is equally significant: weekly attacks per organization rose from 2,055 in May to 2,803 in September, an increase of 36% over five months.
This sustained growth points to more than an isolated monthly spike, making resilience, exposure reduction and prevention increasingly important across networks, cloud, endpoints, email and AI services.
Education Faces the Highest Attack Volume
Education remained the most targeted industry in September, averaging 6,656 weekly attacks per organization, up 59% year over year. Attacks also rose 24% from August—the second-highest monthly growth across industries— and surpassing the previous steepest monthly increase for this sector seen in September 2024. The increase coincided with the start of the academic year, when students, faculty, parents and other users reconnect to institutional networks.
Telecommunications ranked second with 3,483 weekly attacks per organization, up 29% year over year, followed by Government with 3,443, up 37%. The figures show sustained pressure on sectors with broad user bases, essential services and complex digital environments.
Latin America Leads in Volume as Europe Records the Sharpest Increase
Latin America recorded the highest regional attack volume in September, averaging 3,813 weekly attacks per organization, up 35% year over year. Africa ranked second at 3,701 weekly attacks, followed by APAC at 3,593. Europe experienced the highest rate of growth, with attacks increasing 61% compared with September 2025. North America also rose sharply, up 50% year over year. Although Europe’s overall volume remains lower than that of the leading regions, it recorded the fastest growth of any region, signaling a rapidly intensifying threat environment for organizations there.
GenAI Risk Expands Alongside Enterprise Use
In September, 1 in every 39 enterprise GenAI prompts posed a high risk of sensitive data leakage, affecting 89% of organizations that regularly use GenAI tools. A further 14% of prompts contained potentially sensitive information, making prompt-based data exposure a mainstream governance concern. The average user generated 131 GenAI prompts during the month, a significant increase from August, while each organization used an average of eight tools. Rising prompt volumes and a broader toolset make it increasingly important to understand what information employees share, where it is processed and which controls apply.
Latin America recorded the highest regional rate of high-risk prompts at 1 in 25, or 4%, above the global average of 2.5%. North America followed at 1 in 37 prompts, APAC at 1 in 48 and Europe at 1 in 57. These ratios put the risk into practical terms: the lower the number, the more often employees are entering information that could expose sensitive data.
By industry, Business Services had the highest high-risk exposure rate at 4.9%, or 1 in every 20 prompts, moving up two places from August. Financial Services followed at 4.1%, or 1 in 25 prompts, with Healthcare & Medical at 3.5%, or 1 in 29. These sectors routinely handle client, financial and patient information, which helps explain why everyday use of GenAI tools can carry a greater risk of sensitive data exposure.
Sensitive Data Exposure Spans Core Business Information
Network and IT Infrastructure was the most common sensitive-data category, observed in GenAI prompts at 71% of organizations. Financial Data followed at 70%, Legal and Regulatory data at 68%, Employee and HR data at 62%, and personally identifiable information at 60%. These percentages reflect the share of organizations where each category was observed, not the share of prompts. The leading category includes information such as hardware and network configurations and IP addresses—details that could give attackers valuable insight into an organization’s internal environment if exposed.
Email Phishing Risk Increases
One in every 91 emails, or 1.1%, was classified as phishing in September, up from 1 in 112, or 0.89%, in August. Among phishing emails, 81% contained links and 11% contained attachments, confirming malicious links as the primary delivery method. Others relied on social engineering without either. In practical terms, phishing emails reached inboxes more frequently than in August, and the heavy reliance on links underlines the importance of checking URLs before users click.
North America recorded the highest regional phishing rate, with 1 in 79 emails, or 1.26%, classified as malicious.
By industry, Associations & Nonprofits had the highest rate at 2.17%, or 1 in 46 emails, twice the global average. Construction & Engineering followed at 2.05%, or 1 in 49 emails, and Real Estate, Rentals & Leasing at 1.38%, or 1 in 72. For Associations & Nonprofits, this means employees were exposed to phishing at roughly double the typical frequency.
Ransomware Remains Elevated Year over Year
* Ransomware data is drawn from double-extortion groups’ public “shame sites.” Although these sources have inherent biases, they provide useful insight into the ransomware landscape.
A total of 824 ransomware attacks were reported in September, representing a 53% increase compared with September 2025. Business Services was the most targeted industry, accounting for 31.3% of reported victims. Consumer Goods & Services followed at 15.2%, with Industrial Manufacturing at 11.0%. Because business services providers often hold data or system access on behalf of multiple clients, a single incident can have consequences that extend beyond the organization itself.
North America was the most affected region, accounting for 46% of reported ransomware incidents, followed by Europe at 25% and APAC at 17%. The United States accounted for 41.9% of reported victims, substantially ahead of Germany at 4.0% and Canada at 3.6%. These figures show where publicly claimed victims are concentrated, rather than the level of risk faced by an individual organization in each country.
The Gentlemen Leads the Ransomware Rankings
The Gentlemen was the most prevalent ransomware group in September, responsible for 13% of published attacks. Qilin followed with 9%, while Akira accounted for 5%. On top of the leading three actors, 80 further extortion groups reported ransomware attacks last month.
The Gentlemen: A fast-growing Ransomware-as-a-Service operation founded in mid-2025. It operates as both a RaaS provider and an Initial Access Broker and supports Windows, Linux and ESXi environments.
Qilin: An established Ransomware-as-a-Service group with victim disclosures dating back to 2022. It provides affiliates with encryption, negotiation and support infrastructure.
Akira: A Ransomware-as-a-Service actor first reported in 2023, with payloads targeting Windows, Linux and ESXi systems.
What September Tells Us
September’s figures show cyber risk increasing in both volume and breadth. Attack rates rose across every region, phishing became more frequent and ransomware remained well above last year’s level, while expanding GenAI use continued to expose sensitive information.
Organizations should focus on reducing exposure before it becomes business impact. Check Point’s prevention-first approach brings together AI-powered protection, shared intelligence and consistent governance across hybrid networks, cloud environments, digital workspaces and AI systems. As established and emerging risks converge, a unified security architecture can help teams prevent threats earlier, reduce complexity and secure AI adoption with greater confidence.
This entry was posted on October 8, 2026 at 1:18 pm and is filed under Commentary with tags Check Point. You can follow any responses to this entry through the RSS 2.0 feed.
You can leave a response, or trackback from your own site.
September 2026 Cyber Threat Landscape: Global Attacks Jump 48% as Phishing and GenAI Data Exposure Rise
Key takeaways
September’s data shows cyber pressure rising across multiple fronts. Weekly attack volumes increased sharply, phishing became more prevalent, GenAI use continued to expand alongside sensitive-data exposure, and ransomware remained well above last year’s level. Together, these findings reinforce Check Point’s prevention-first view: organizations need AI-powered security, consistent visibility and shared intelligence across the full attack surface to reduce risk before it becomes business impact.
Global Cyber Attacks Accelerate
Organizations experienced an average of 2,803 cyber attacks per week in September 2026. That represents a 16% increase from August and a 48% increase compared with September 2025. The longer trend is equally significant: weekly attacks per organization rose from 2,055 in May to 2,803 in September, an increase of 36% over five months.
This sustained growth points to more than an isolated monthly spike, making resilience, exposure reduction and prevention increasingly important across networks, cloud, endpoints, email and AI services.
Education Faces the Highest Attack Volume
Education remained the most targeted industry in September, averaging 6,656 weekly attacks per organization, up 59% year over year. Attacks also rose 24% from August—the second-highest monthly growth across industries— and surpassing the previous steepest monthly increase for this sector seen in September 2024. The increase coincided with the start of the academic year, when students, faculty, parents and other users reconnect to institutional networks.
Telecommunications ranked second with 3,483 weekly attacks per organization, up 29% year over year, followed by Government with 3,443, up 37%. The figures show sustained pressure on sectors with broad user bases, essential services and complex digital environments.
Latin America Leads in Volume as Europe Records the Sharpest Increase
Latin America recorded the highest regional attack volume in September, averaging 3,813 weekly attacks per organization, up 35% year over year. Africa ranked second at 3,701 weekly attacks, followed by APAC at 3,593. Europe experienced the highest rate of growth, with attacks increasing 61% compared with September 2025. North America also rose sharply, up 50% year over year. Although Europe’s overall volume remains lower than that of the leading regions, it recorded the fastest growth of any region, signaling a rapidly intensifying threat environment for organizations there.
GenAI Risk Expands Alongside Enterprise Use
In September, 1 in every 39 enterprise GenAI prompts posed a high risk of sensitive data leakage, affecting 89% of organizations that regularly use GenAI tools. A further 14% of prompts contained potentially sensitive information, making prompt-based data exposure a mainstream governance concern. The average user generated 131 GenAI prompts during the month, a significant increase from August, while each organization used an average of eight tools. Rising prompt volumes and a broader toolset make it increasingly important to understand what information employees share, where it is processed and which controls apply.
Latin America recorded the highest regional rate of high-risk prompts at 1 in 25, or 4%, above the global average of 2.5%. North America followed at 1 in 37 prompts, APAC at 1 in 48 and Europe at 1 in 57. These ratios put the risk into practical terms: the lower the number, the more often employees are entering information that could expose sensitive data.
By industry, Business Services had the highest high-risk exposure rate at 4.9%, or 1 in every 20 prompts, moving up two places from August. Financial Services followed at 4.1%, or 1 in 25 prompts, with Healthcare & Medical at 3.5%, or 1 in 29. These sectors routinely handle client, financial and patient information, which helps explain why everyday use of GenAI tools can carry a greater risk of sensitive data exposure.
Sensitive Data Exposure Spans Core Business Information
Network and IT Infrastructure was the most common sensitive-data category, observed in GenAI prompts at 71% of organizations. Financial Data followed at 70%, Legal and Regulatory data at 68%, Employee and HR data at 62%, and personally identifiable information at 60%. These percentages reflect the share of organizations where each category was observed, not the share of prompts. The leading category includes information such as hardware and network configurations and IP addresses—details that could give attackers valuable insight into an organization’s internal environment if exposed.
Email Phishing Risk Increases
One in every 91 emails, or 1.1%, was classified as phishing in September, up from 1 in 112, or 0.89%, in August. Among phishing emails, 81% contained links and 11% contained attachments, confirming malicious links as the primary delivery method. Others relied on social engineering without either. In practical terms, phishing emails reached inboxes more frequently than in August, and the heavy reliance on links underlines the importance of checking URLs before users click.
North America recorded the highest regional phishing rate, with 1 in 79 emails, or 1.26%, classified as malicious.
By industry, Associations & Nonprofits had the highest rate at 2.17%, or 1 in 46 emails, twice the global average. Construction & Engineering followed at 2.05%, or 1 in 49 emails, and Real Estate, Rentals & Leasing at 1.38%, or 1 in 72. For Associations & Nonprofits, this means employees were exposed to phishing at roughly double the typical frequency.
Ransomware Remains Elevated Year over Year
* Ransomware data is drawn from double-extortion groups’ public “shame sites.” Although these sources have inherent biases, they provide useful insight into the ransomware landscape.
A total of 824 ransomware attacks were reported in September, representing a 53% increase compared with September 2025. Business Services was the most targeted industry, accounting for 31.3% of reported victims. Consumer Goods & Services followed at 15.2%, with Industrial Manufacturing at 11.0%. Because business services providers often hold data or system access on behalf of multiple clients, a single incident can have consequences that extend beyond the organization itself.
North America was the most affected region, accounting for 46% of reported ransomware incidents, followed by Europe at 25% and APAC at 17%. The United States accounted for 41.9% of reported victims, substantially ahead of Germany at 4.0% and Canada at 3.6%. These figures show where publicly claimed victims are concentrated, rather than the level of risk faced by an individual organization in each country.
The Gentlemen Leads the Ransomware Rankings
The Gentlemen was the most prevalent ransomware group in September, responsible for 13% of published attacks. Qilin followed with 9%, while Akira accounted for 5%. On top of the leading three actors, 80 further extortion groups reported ransomware attacks last month.
What September Tells Us
September’s figures show cyber risk increasing in both volume and breadth. Attack rates rose across every region, phishing became more frequent and ransomware remained well above last year’s level, while expanding GenAI use continued to expose sensitive information.
Organizations should focus on reducing exposure before it becomes business impact. Check Point’s prevention-first approach brings together AI-powered protection, shared intelligence and consistent governance across hybrid networks, cloud environments, digital workspaces and AI systems. As established and emerging risks converge, a unified security architecture can help teams prevent threats earlier, reduce complexity and secure AI adoption with greater confidence.
Share this:
Like this:
Related
This entry was posted on October 8, 2026 at 1:18 pm and is filed under Commentary with tags Check Point. You can follow any responses to this entry through the RSS 2.0 feed. You can leave a response, or trackback from your own site.