July’s cyber threat landscape was shaped by pressure across multiple fronts. Global cyber attacks continued to rise, ransomware activity broke from the more stable pattern seen earlier in the year, and GenAI exposure became a clearer operational risk as employees used more tools and generated more prompts across the enterprise.
Cyber Attacks Keep Climbing
The global attack curve continued upward in July. Organizations faced an average of 2,336 weekly cyber attacks, up 3% from June and 16% from July 2025. While the monthly rise was more moderate than June’s rebound, the broader trend remains clear: average weekly attacks per organization have increased by 13.7% since May, signaling sustained pressure rather than a temporary spike.
Education Remains the Top Target
Education remained the most targeted sector, averaging 4,848 weekly attacks per organization, up 14% year over year. Government ranked second with 3,044 weekly attacks, up 11%, followed by Telecommunications at 2,927, up 6%. Energy and Utilities moved into fourth place with 2,759 weekly attacks, up 20%, while Hospitality, Travel and Recreation entered the top five with 2,614 attacks, up 28%, possibly reflecting higher exposure during the summer travel period.
Latin America Leads in Volume as Europe Sees a Sharp Rise
Regionally, Latin America continued to face the highest attack volume, with 3,561 weekly attacks per organization on average, up 19% from July 2025. APAC followed with 3,316 weekly attacks, while Africa ranked third despite a 5% year-over-year decline. Europe stood out for its growth rate, with attacks up 18% year over year, while North America rose 9%.
GenAI Risk Moves from Theory to Daily Business Reality
GenAI risk is becoming a daily business issue. The main concern is not only how AI tools are used, but what employees enter into them, from customer records and internal documents to infrastructure, legal, financial, or HR information. July’s data shows how quickly that exposure can scale:
- 1 in every 36 prompts from enterprise networks carried a high risk of sensitive data leakage
- 88% of regular GenAI-using organizations were affected by high-risk prompt activity
- 22% of prompts contained potentially sensitive information.
- Organizations used an average of 8 GenAI tools, while the average user generated 95 prompts during the month
This makes GenAI both a governance and security issue, especially as adoption moves faster than policies, training, and controls. Exposure was highest in Latin America and North America, while Europe and APAC were slightly below the global average. By industry, Business Services and Healthcare and Medical recorded the highest risk, followed by Information Technology and Government.
The type of information being exposed is also important. Personal data remained the most common sensitive category, appearing in 70% of organizations. Financial Data and Network and IT Infrastructure followed at 68% each, while Legal and Regulatory content appeared in 63% and Employee and HR data in 62%. The issue is not limited to one team, use case, or document type. It cuts across the core information organizations rely on every day.
Email Remains a Key Entry Point for Cyber Risk
Despite growing focus on newer attack surfaces, email remained a high-volume risk channel in July. One in every 128 emails, or 0.78%, was classified as phishing, while another 20% fell into unwanted or risky categories such as graymail, spam, and suspicious messages, adding to the daily burden security teams need to filter and investigate.
Africa recorded the highest phishing rate, with one in every 106 emails classified as phishing, followed by North America at one in every 117. Beyond the regional differences, the trend reinforces email’s role as a common starting point for broader attack chains, from credential theft and malware delivery to business email compromise. In July, that escalation was most visible in ransomware activity.
Ransomware Breaks the Pattern
* This ransomware data draws from ransomware “shame sites” operated by double-extortion groups, which publicly disclose victim information. While these sources have inherent biases, they provide valuable insight into the ransomware landscape.
The clearest shift in July came from ransomware. Reported attacks reached 964, up 87% from July 2025 and 49% from June. This marked a decisive break from the first half of 2026, when monthly ransomware activity averaged around 672 incidents.
The increase was broad, touching multiple regions and industries, but Business Services remained the most affected sector, accounting for almost one third of reported victims.
North America remained the most affected region, accounting for 45% of reported ransomware incidents. Europe followed at 28%, while APAC accounted for 17%.
At country level, the United States continued to dominate the victim count with 39.4% of reported attacks, followed by Germany, Canada, the United Kingdom, and Italy.
The Gentlemen and Qilin Lead as the Ransomware Landscape Shifts
The Gentlemen and Qilin were the most prevalent ransomware groups in July, each responsible for 14% of published attacks. DeadLock climbed to the top three, with 10% and 97 reported victims.
- The Gentlemen: A fast-growing Ransomware-as-a-Service operation launched in mid-2025. The group combines ransomware operations with initial access brokering, helping it scale quickly in a short period of time.
- Qilin: An established Ransomware-as-a-Service group with victim disclosures dating back to 2022. Its mature affiliate model and renewed recruitment activity have helped it increase victim listings and regain momentum.
- DeadLock: A group first observed in July 2025. It has gained attention for using blockchain-based techniques to rotate command-and-control proxy addresses, alongside the use of legitimate remote management tools.
What July Tells Us
July’s threat landscape was defined by accumulation rather than a single dominant risk. Global attacks kept rising, ransomware accelerated sharply, and GenAI exposure became more visible as part of routine business activity. For security teams, the message is clear: prevention cannot be limited to one layer or one threat category. Organizations need coordinated protection across network, cloud, endpoint, email, and AI usage, supported by the visibility to understand where sensitive data and attacker activity are moving next.











The Check Point Q2 2026 Ransomware Report Is Out
Posted in Commentary with tags Check Point on August 13, 2026 by itnerdRansomware kept its grip on organizations through the second quarter of 2026, and the headline number barely moved. What changed underneath that number is more interesting: new research gave us a rare look inside a top tier operation as it was being built, and it revealed just how little it now takes for a small and skilled group to reach the top of the field. Here’s what the quarter actually showed, and what it means for how you defend against it.
Key takeaways
What actually happened in Q2 2026?
Data leak sites, where ransomware groups publish victims who refuse to pay, logged 2,139 victims in Q2, essentially flat against Q1 and up 33% year over year. The ecosystem is holding at the elevated baseline it settled into through 2025.
What shifted is who’s doing the attacking. In Q1, the top 10 groups controlled 71% of victims across just 71 active groups, a tight, top heavy market. By Q2, that eased to 57.6%, and active groups climbed to 93, the highest on record. Cl0p, whose Oracle E-Business Suite campaign drove much of Q1’s numbers, nearly vanished, and a wider mid tier filled the gap. Qilin held the top spot for a fourth straight quarter with 279 victims, narrowly ahead of The Gentlemen, which grew 62% and outpaced Qilin in June.
Figure 1 – Total Number of Reported Ransomware Victims in data leakage websites, per month
(June 2024 – June 2026)
Figure 2 – Top-10 share and active group count, Q2 2026
What did the leaked Gentlemen chat logs actually reveal?
A leak of The Gentlemen’s own backend and chat history, giving researchers a rare inside view of a top tier operation. The core team was just nine people, running a 90/10 split with a broader affiliate base that carried out most of the intrusion work, the highest cut advertised in the market.
The detail worth remembering: the group’s admin, Zeta88, built the operation’s ransomware management panel in about three days using AI coding assistants, with a candid admission that the tools still require someone who understands the code well enough to guide and correct it. That’s genuine evidence AI is speeding up how ransomware tooling gets built, though its use here was about writing software faster, not running operations or picking targets. The bigger signal: the barriers to building a serious ransomware business have narrowed enough that one experienced operator can reach the top tier in months.
Figure 3 – The Gentlemen monthly victim trajectory, Sep 2025 – Jun 2026
Why does data theft matter more than encryption right now?
Payment rates have fallen for six straight years, from 85% in 2019 to roughly 23% today, largely because backups have gotten better at neutralizing encryption. Backups don’t help against data theft, though. If files are already stolen and about to be published, restoring systems doesn’t stop the leak, which is why operators are leaning into exfiltration first extortion. Total dollars paid haven’t followed payment rates down: on chain payments still exceeded $820 million in 2025.
Law enforcement spent the quarter chasing shared infrastructure rather than individual groups, dismantling a laundering platform, sanctioning exchanges tied to ransomware actors, and taking down a malware signing service and major infostealer networks. None of that shows up as a drop in Q2’s victim count, and seized infrastructure tends to get rebuilt elsewhere, but raising the cost of laundering, signing, and credential harvesting adds friction that compounds over time.
What should defenders actually prioritize?
A few things fall out of the quarter’s data. Initial access remains the fight that matters most: The Gentlemen’s own pipeline ran on VPN scanning, brute forcing, and brokered credentials, the same route used across most of the ecosystem, so phishing and exposed remote access deserve defense in proportion to how often they’re the opening move. Exfiltration detection now deserves the same weight backup and recovery has traditionally received, and remediation speed matters more too, since the gap between disclosure and exploitation is now measured in hours. Defenses still running on a human review cycle are working against AI assisted tooling that no longer waits for one.
How does Check Point address what this Ransomware quarter found?
Most of what this report documents starts with a person, usually through phishing or stolen credentials feeding the same pipeline The Gentlemen relied on. Workspace Security protects users across email, browsers, SaaS applications, and endpoints, using AI driven detection to stop ransomware delivery before execution and limit lateral movement and exfiltration after a compromise.
Hybrid Mesh Network Security applies consistent, AI driven controls at every connectivity point, from firewalls that block malicious files before they reach devices to CASB scanning that catches malware entering through SaaS platforms like OneDrive and Slack, a route access brokers increasingly favor. If a compromise happens anyway, Zero Trust access through SASE Private Access limits the blast radius so ransomware can only reach what the compromised user was authorized to touch.
Exposure Management answers the harder question of which vulnerabilities ransomware groups can actually reach and use, not just which ones exist. Check Point’s 2026 Exposure Gap Report found vulnerabilities now make up 42.6% of critical exposures, more than double the year before, and that they can realistically be closed in under an hour, with utilities sector organizations using the platform resolving 30% of theirs within that window.
AI Security addresses the same tooling ransomware groups are learning to use. ThreatCloud AI keeps protection moving on the same accelerated timeline as AI assisted exploitation, AI Agent Security governs the agent permissions that let an admin like Zeta88 build tooling in days, AI Red Teaming tests an organization’s own AI applications before deployment, and Workforce AI Security stops credentials and data from leaking through the AI tools employees already use.
Leave a comment »