Archive for Comparitech

July Ransomware Attacks: Up 19% from June Says Comparitech

Posted in Commentary with tags on August 5, 2026 by itnerd

With ransomware attacks plaguing businesses and individuals around the world, Comparitech have released their Ransomware Roundup for July 2026, finding that last month saw nearly 26 ransomware attacks per day. 

The research looks into attacks by sector, most prolific groups and attacks by country.

Key findings include:

  • 799 attacks in total — 51 confirmed attacks (confirmed by the entity involved)
  • Of the 51 confirmed attacks:
    • 31 were on businesses
    • 10 were on government entities
    • 3 were on healthcare companies
    • 7 were on educational institutions
  • Of the 748 unconfirmed attacks*:
    • 657 were on businesses
    • 24 were on government entities
    • 50 were on healthcare companies
    • 16 were on educational institutions

You can find the full research here: https://www.comparitech.com/news/ransomware-roundup-july-2026/

Commenting on this is Rebecca Moody, Head of Data Research at Comparitech:

“If we needed a reminder of how dominant a threat ransomware attacks remain, July’s figures provide us with just that. Figures reached the third-highest level in the last 17 months and The Gentlemen and Qilin continued to add hundreds of victims to their data-leak sites. We’ve already logged over 100 victims during the first four days of August 2026, too. 

July also saw some of the year’s most significant ransomware attacks. This includes the attack on the Romanian government’s land registry agency, which saw an entire database being wiped, the crippling attacks on AnMed and Fairlife in the US, and the attack on The Craneware Group, which looks set to have resulted in an extensive data breach. 

These attacks highlight how ransomware groups hit organisations in various different ways — taking down key systems, stealing troves of data, and even deleting massive datasets. Never has it been more important for organisations to ensure they’re carrying out regular backups (and backups of their backups!) so they can reset systems and restore data as quickly as possible if the worst does happen.”

I would put aside some time to give this a read as it will help you to structure your defenses.

Cybercrime victims lose an estimated $1.24 trillion a year 

Posted in Commentary with tags on July 29, 2026 by itnerd

Comparitech researchers have published an update to their 2023 study on the cost of cybercrime globally. The new study sees a significant increase in the annual estimated monetary impact of cybercrime — now at $1.24 trillion versus 2023’s figure of $714 billion. 

Key findings include: 

  • 103.9 million people fall victim to cybercrimes globally each year, or more than 1,577 victims per 100,000 people
  • The average victim loss is $9,468 per crime
  • Victims lose an estimated $1.24 trillion to cybercrime annually
  • The United States showed the biggest estimated losses at 6.7 million victims losing an estimated $138.9 billion

For full details, click here.

Data breach at medical billing firm MCBS affects 1.26 million people

Posted in Commentary with tags on July 28, 2026 by itnerd

Healthcare billing company Medical Computer Business Services (MCBS) has disclosed that a 2025 network breach exposed the sensitive information of more than 1.2 million people.

Commenting on this is Rebecca Moody, Head of Data Research at Comparitech

“This is another prime example of why third-party healthcare companies, like medical billing providers, have become a prime target for ransomware groups. By targeting one entity, they’re gaining access to multiple healthcare providers and their data. Our recent H1 healthcare ransomware report found a 35 percent uptick in attacks on these types of companies (those that specialize within the healthcare sector but don’t provide direct care). This breach becomes the second-largest on a third-party healthcare business following a ransomware attack in the last 18 months.”

The report that was linked is a very good one, and I encourage you to read it if you get a chance.

UPDATE: Additional commentary comes via Seemant Sehgal, Founder & CEO, BreachLock:

   “A breach that ran for four days in September 2025 and surfaced in a public disclosure eight months later tells you something about how difficult incident response and forensic review are in environments that handle data across multiple providers simultaneously. The data types here, Social Security numbers, insurance details, medical information, are the combination that makes downstream fraud viable for years, which means the harm timeline for affected individuals extends well beyond the notification date. Eight months is a long time for that data to be in motion before patients knew to watch for it.”

John Strand, Owner, Black Hills Information Security, Inc.:

   “One of the things I absolutely hate about stories like this is that the default response is almost always complimentary identity protection services. Yes, those services can detect some types of fraud, but they don’t come close to addressing the full range of risks created by a data breach. They have value, but they’re far from a complete solution.

   “I’ve started calling this the information security equivalent of thoughts and prayers. It’s the absolute bare minimum a company can offer after a breach without making meaningful changes to improve security or reduce future risk. The reality is that only a fraction of affected people will ever enroll in those services, and even those who do aren’t protected against every way their information can be abused. It’s frustrating because organizations can suffer a major breach, offer a year of identity protection, and too often that’s treated as an adequate response instead of a starting point for real accountability.”

Damon Small, Board of Directors, Xcape, Inc.:

   “Third-party healthcare billing breaches create massive regulatory exposure and systemic supply chain liability when basic detection and response controls fail. The intrusion at Medical Business Office Systems, known as MCBS, allowed attackers to dwell for days and exfiltrate over three terabytes of sensitive patient and insurance data undetected, exposing non-existent data loss prevention and egress monitoring capabilities.

   “Furthermore, an eight-month delay before patient notification, justified by waiting for internal investigation completion, highlights severely flawed incident response processes. Security leaders must mandate continuous network egress monitoring, enforce strict data loss controls on revenue cycle aggregators, and require business associates to report material intrusions within days rather than waiting for post-forensic completion.

   “Critical Takeaways

  • Monitor large-scale data egress: Deploy continuous network monitoring and data loss prevention tools to detect abnormal outbound traffic before terabytes leave the perimeter.
  • Accelerate incident response SLAs: Mandate that third-party vendors establish tight notification timelines rather than withholding breach disclosures for months while conducting internal reviews.
  • Enforce vendor risk accountability: Require revenue cycle partners to submit to regular security telemetry audits and maintain strict field-level data controls for sensitive patient records.

   “If it takes eight months to realize three terabytes of patient data walked out the door, your incident response plan is a post-mortem, not a defense.”

Jacob Krell, Senior Director: Secure AI Solutions & Cybersecurity, Suzu Labs:

   “MCBS had a regulatory shortcut available that would have made this entire disclosure unnecessary. The Health Insurance Portability and Accountability Act (HIPAA) includes a breach notification safe harbor for properly encrypted data, meaning if those 1.26 million Social Security numbers had been encrypted at the field level, the stolen files would have been useless ciphertext and the breach wouldn’t have triggered notification requirements. The encryption was always the cheapest fix. MCBS chose not to implement it when the rule calls encryption “addressable” rather than mandatory.

   “The Department of Health and Human Services proposed eliminating that flexibility in January 2025, making AES-256 encryption at rest mandatory for all electronic protected health information. That rule hasn’t been finalized, and final action has been pushed to July 2027. Encryption remains “addressable” today, and every healthcare billing company that reads “addressable” as “optional” is sitting on the same exposure MCBS had.

   “Credit monitoring as a remedy tells you what the breach responders think the threat model is, and they’re thinking too narrowly. PEAR (Pure Extraction and Ransom) exfiltrated 3.3 terabytes from MCBS, including medical histories, mental health conditions, and diagnosis information. That data enables targeted blackmail, insurance manipulation, and employment discrimination. A credit freeze catches none of it.

   “Under the EU’s General Data Protection Regulation (GDPR) Article 82, affected individuals can claim compensation directly from the company that lost their data. The US gives 1.26 million people a year of free credit monitoring instead. A $4 trillion industry can afford field-level encryption, and it can afford direct liability to patients when it skips it.”

DentaQuest Starts Notifying 15 Million+ Individuals About May 2026 Cyber Incident 

Posted in Commentary with tags on July 24, 2026 by itnerd

The dental benefits administrator DentaQuest has started issuing notification letters to individuals affected by a May 2026 cybersecurity incident. The number of affected individuals has yet to be confirmed, although DentaQuest has confirmed that at least 15 million individuals have been affected.

Commenting on this is Paul Bischoff, Consumer Privacy Advocate at Comparitech

“This is a major data breach both in terms of the number of people affected and the types of personal information involved. DentaQuest customers should take advantage of free credit monitoring offered by DentaQuest and monitor their credit reports, bank accounts, and medical bills for unrecognized activity. Whether or not DentaQuest paid ShinyHunters’ ransom demand, there is no guarantee that the group will delete the stolen data. Breach victims should assume the worst and act accordingly to protect their accounts and identities.”

Comparitech recently published an in-depth research study looking at ransomware attacks against healthcare institutions in the first half of 2026, finding that attacks increased nearly 14% since the last half of 2025. 

Comparitech Education Ransomware Roudup: H1 2026 stats on attacks, ransoms, and data breaches

Posted in Commentary with tags on July 23, 2026 by itnerd

Comparitech has published a new study looking at ransomware attacks against the education sector in H1 2026, finding that while overall attacks against educational institutions declined, attacks on higher education actually increased. 

Key findings include: 

  • 104 attacks in total
  • 36 confirmed attacks
  • 68 unconfirmed attacks
  • Nearly 693,000 records are known to have been breached in the confirmed attacks
  • Median ransom demand: $420,620 – up 53% from $275,000 in H2 2025
  • The ransomware strains that made the most attack claims were The Gentlemen and Qilin (15 each), LockBit (9), Interlock and Nova (6 each)
  • The Gentlemen claimed the most confirmed attacks (6), followed by Interlock (4) and Qilin and LockBit (3 each)

For full details, the research can be read here: https://www.comparitech.com/news/education-ransomware-roundup-h1-2026-stats-on-attacks-ransoms-and-data-breaches/ 

Comparitech Government Ransomware Attack Study Is Out

Posted in Commentary with tags on July 16, 2026 by itnerd

Comparitech researchers have published a new study looking at ransomware attacks targeting the government sector in H1 2026. 

According to the findings, Comparitech researchers logged an average of one ransomware attack on a government entity every day. Attacks jumped by over 13 percent when compared to H2 2025, increasing from 165 to 187 attacks. 

Rebecca Moody, Head of Data Research at Comparitech, provided the following comment: 

“Predicting what’s going to happen within the ransomware threat landscape for the rest of the year is always difficult. However, based on our H1 2026 data and the increased momentum of The Gentlemen, ransomware attacks within the government sector remain a dominant, if not growing, threat. From weeks-long disruptions due to system encryption to extensive data breaches, governments are the ideal target for hackers.

The ongoing attack on Latvia’s state forestry company (LVM) should also serve as a reminder that government agencies have to ensure they’re meeting the basic cybersecurity best practices. In LVM’s case, hackers were able to exploit a vulnerability in a system that hadn’t been updated in two years. Keeping systems up to date, patching vulnerabilities as soon as they’re flagged, carrying out regular backups, and making sure employees are regularly trained and are on high alert at all times are crucial to mitigating the risks of attacks.”

You can read the details here: https://www.comparitech.com/news/government-ransomware-roundup-h1-2026-stats-on-attacks-ransoms-and-data-breaches/

Comparitech Healthcare Ransomware Roundup: H1 2026 stats on attacks, ransoms, and data breaches

Posted in Commentary with tags on July 9, 2026 by itnerd

Comparitech researchers have published a new study looking at ransomware attacks against the healthcare sector in H1 2026. 

According to the findings, during the first six months of 2026, the healthcare sector suffered an average of 2.3 ransomware attacks per day. Attacks increased by nearly 14 percent when compared to H2 2025, rising from 360 to 410.

Rebecca Moody, Head of Data Research at Comparitech, provided the following comment: 

“As ransomware attacks remain at a consistently high level, the healthcare sector is no exception. Here, attacks continue to increase, particularly among healthcare businesses (e.g. pharmaceutical manufacturers, drug wholesalers, and medical billing providers). This means healthcare providers (those offering direct care) continue to face the threat of attacks within their own systems and within the systems of the third parties they entrust to carry out various services. 

The March 2026 attack on the University of Mississippi Medical Center, which caused two weeks of disruptions, serves as a stark reminder of the devastating impact system encryption can have on healthcare providers. Meanwhile, attacks on third parties, like Unimed in Germany, demonstrate the far-reaching consequences of data theft following these attacks. In Unimed’s case, numerous clinics and hospitals were impacted, with the breach figure growing into the hundreds of thousands.”

You can read the research here: https://www.comparitech.com/news/healthcare-ransomware-roundup-h1-2026-stats-on-attacks-ransoms-and-data-breaches/

Ransomware Roundup: H1 2026 stats on attacks, ransoms, and active gangs 

Posted in Commentary with tags on July 2, 2026 by itnerd

Acording to a newly published Comparitech report, global ransomware attacks reached a new high in H1 of 2026 with an average of 23 attacks per day. During the first six months of 2026, researchers logged 4,217 ransomware attacks. This is an 11 percent increase on the second half of 2025 (3,809).

Additional key findings include: 

  • 484 confirmed ransomware attacks
    • 319 were on businesses
    • 83 were on government entities
    • 49 were on healthcare companies
    • 33 were on educational institutions
  • 3,733 unconfirmed attacks*
    • 3,356 were on businesses
    • 102 were on government entities
    • 198 were on healthcare companies
    • 71 were on educational institutions
  • 5,019,204 records compromised in the confirmed attacks
  • Median ransom demand: $150,000 (average: $1.36M)
  • Qilin was the most prolific ransomware group with 641 victims in total, followed by The Gentlemen (464) and Akira (317)
  • Qilin (54) and The Gentlemen (51) had the most confirmed attacks
  • The United States was the most targeted country with 1,832 attacks in total, followed by Canada (200), Germany (164), the United Kingdom (157), Italy (131), France (117), and Spain (100)
  • China saw one of the biggest upticks in attacks from H2 2025 to H1 2026 (up 540% from 5 to 30)

Commenting on these findings is Rebecca Moody, Head of Data Research at Comparitech: 

“One thing that stands out in this report is how the growth of one ransomware group can start to change the threat landscape. The Gentlemen overtook Qilin in the number of attack claims last month, and, as the group operates a more “international” approach to its targets, attack figures dropped in the US (when compared to H2 of 2025), despite figures increasing in most other countries. 

Around half of Qilin’s targets tend to be US-based, but less than 1 in 5 of The Gentlemen’s victims in June 2026 were based in the US. Perhaps seeing how saturated ransomware attacks are in the US, The Gentlemen has decided to focus more of its efforts further afield — and with relative success. 51 of its 2026 victims have confirmed their attacks to date, with notable names including Mackay Sugar in Australia, the Grand Hotel Taipei in Taiwan, and NATO contractor Indra (Spanish HQ but subsidiary affected).”

For full details, you can read the study here: https://www.comparitech.com/news/ransomware-roundup-h1-2026-stats-on-attacks-ransoms-and-active-gangs/

Comparitech Research: Which industry & country has the worst email security? An analysis of 5,800+ domains

Posted in Commentary with tags on July 1, 2026 by itnerd

Every day, cybercriminals send around 3.4 billion phishing emails. 90 percent of successful cyber attacks originate from one of these emails. 96 percent of IT security and decision makers expect to see email security challenges throughout 2026, so you’d be forgiven for thinking that most organizations would be meeting the basics. However, Comparitech’s findings found that more than eight percent of organizations’ domains are fully unprotected. 

This Wednesday, Comparitech researchers will be publishing a new study looking into this very subject by analyszing the live DNS records for 5,849 domains across 13 sectors, scoring each based on a series of frameworks. 

Key findings include: 

  • 487 of the total domains scanned (5,849) had zero protection (8.3%)
  • Government domains had the lowest average score – 2.73
  • Tech company domains had the highest average score – 4.83
  • China had the lowest average score – 2.3

Additionally, Rebecca Moody, Head of Data Research at Comparitech, provided the following comment on the subject: 

“If you asked people which industries they’d like to assume are meeting basic cybersecurity standards, government agencies and healthcare providers would likely be among some of the most popular answers. Our study highlights that, when it comes to standard email security, this couldn’t be further from the truth. 

The fact that over 1 in 4 government agencies and 1 in 5 healthcare providers have zero email protection is incredibly concerning, particularly when the factors we’ve assessed (SPF, DMARC, DKIM, or MTA-STS) are what many would call “standard” protocols. Equally, these sectors are often subject to more regulation, demonstrating that even when they should be meeting these requirements by law, they often aren’t.

One of the biggest risks of having gaps in email security is spoofing. Without the necessary protocols in place, hackers can spoof an organization’s domain, which adds to the legitimacy of their campaign. They could use this to send phishing emails, malware, or carry out a wire fraud scam, for example. Ultimately, the email security protocols we’ve assessed shouldn’t be seen as a recommendation or “good to have,” they should be viewed as being essential for all organizations.”

You can read the research here: https://www.comparitech.com/news/which-industry-country-has-the-worst-email-security-an-analysis-of-5800-domains-for-spf-dmarc-dkim-mta-sts-protocols/

Ohio city warns 123,000+ people of data breach that leaked SSNs, financial and medical info

Posted in Commentary with tags on July 1, 2026 by itnerd

Comparitech is reporting that the city of Middletown, Ohio today confirmed it notified 123,791 people of a July 2025 data breach that compromised names, SSNs, financial account info, medical info, health insurance info, addresses, and government-issued IDs. 

The cyberattack disrupted city services including water utility billing, which wasn’t fully restored until months later in January 2026.

Commenting on this news is Rebecca Moody, Head of Data Research at Comparitech

“This attack highlights why government agencies remain a key target for hackers.

First, the case shows just how disruptive these attacks can be, with Middletown only being able to restore its water billing system in January of this year, around six months after the attack took place. Second, governments are often in possession of vast quantities of data. Accessing such data not only gives hackers further leverage to demand a ransom, but it also gives them key data that they can sell on the dark web if negotiations fail. The fact that SafePay posted the City of Middletown to its data leak site suggests ransom negotiations failed (for the data theft at least). 

While government agencies are sometimes prevented from paying ransoms (or have to meet strict conditions in order to pay one, as is the case in Ohio), we saw a case just last month (Murray County in Georgia) where the ransom was paid in order to prevent county data from being published. 

It’s win-win for hackers. Receive a ransom demand to decrypt systems and/or delete data, or sell highly sensitive personal data on the dark web.”

I guess hackers are about to have a field day because they seriously hit the jackpot here. Which illustrates why stopping the bad guys from doing evil things is preferable to getting pwned.