Archive for Comparitech

Comparitech Healthcare Ransomware Roundup: H1 2026 stats on attacks, ransoms, and data breaches

Posted in Commentary with tags on July 9, 2026 by itnerd

Comparitech researchers have published a new study looking at ransomware attacks against the healthcare sector in H1 2026. 

According to the findings, during the first six months of 2026, the healthcare sector suffered an average of 2.3 ransomware attacks per day. Attacks increased by nearly 14 percent when compared to H2 2025, rising from 360 to 410.

Rebecca Moody, Head of Data Research at Comparitech, provided the following comment: 

“As ransomware attacks remain at a consistently high level, the healthcare sector is no exception. Here, attacks continue to increase, particularly among healthcare businesses (e.g. pharmaceutical manufacturers, drug wholesalers, and medical billing providers). This means healthcare providers (those offering direct care) continue to face the threat of attacks within their own systems and within the systems of the third parties they entrust to carry out various services. 

The March 2026 attack on the University of Mississippi Medical Center, which caused two weeks of disruptions, serves as a stark reminder of the devastating impact system encryption can have on healthcare providers. Meanwhile, attacks on third parties, like Unimed in Germany, demonstrate the far-reaching consequences of data theft following these attacks. In Unimed’s case, numerous clinics and hospitals were impacted, with the breach figure growing into the hundreds of thousands.”

You can read the research here: https://www.comparitech.com/news/healthcare-ransomware-roundup-h1-2026-stats-on-attacks-ransoms-and-data-breaches/

Ransomware Roundup: H1 2026 stats on attacks, ransoms, and active gangs 

Posted in Commentary with tags on July 2, 2026 by itnerd

Acording to a newly published Comparitech report, global ransomware attacks reached a new high in H1 of 2026 with an average of 23 attacks per day. During the first six months of 2026, researchers logged 4,217 ransomware attacks. This is an 11 percent increase on the second half of 2025 (3,809).

Additional key findings include: 

  • 484 confirmed ransomware attacks
    • 319 were on businesses
    • 83 were on government entities
    • 49 were on healthcare companies
    • 33 were on educational institutions
  • 3,733 unconfirmed attacks*
    • 3,356 were on businesses
    • 102 were on government entities
    • 198 were on healthcare companies
    • 71 were on educational institutions
  • 5,019,204 records compromised in the confirmed attacks
  • Median ransom demand: $150,000 (average: $1.36M)
  • Qilin was the most prolific ransomware group with 641 victims in total, followed by The Gentlemen (464) and Akira (317)
  • Qilin (54) and The Gentlemen (51) had the most confirmed attacks
  • The United States was the most targeted country with 1,832 attacks in total, followed by Canada (200), Germany (164), the United Kingdom (157), Italy (131), France (117), and Spain (100)
  • China saw one of the biggest upticks in attacks from H2 2025 to H1 2026 (up 540% from 5 to 30)

Commenting on these findings is Rebecca Moody, Head of Data Research at Comparitech: 

“One thing that stands out in this report is how the growth of one ransomware group can start to change the threat landscape. The Gentlemen overtook Qilin in the number of attack claims last month, and, as the group operates a more “international” approach to its targets, attack figures dropped in the US (when compared to H2 of 2025), despite figures increasing in most other countries. 

Around half of Qilin’s targets tend to be US-based, but less than 1 in 5 of The Gentlemen’s victims in June 2026 were based in the US. Perhaps seeing how saturated ransomware attacks are in the US, The Gentlemen has decided to focus more of its efforts further afield — and with relative success. 51 of its 2026 victims have confirmed their attacks to date, with notable names including Mackay Sugar in Australia, the Grand Hotel Taipei in Taiwan, and NATO contractor Indra (Spanish HQ but subsidiary affected).”

For full details, you can read the study here: https://www.comparitech.com/news/ransomware-roundup-h1-2026-stats-on-attacks-ransoms-and-active-gangs/

Comparitech Research: Which industry & country has the worst email security? An analysis of 5,800+ domains

Posted in Commentary with tags on July 1, 2026 by itnerd

Every day, cybercriminals send around 3.4 billion phishing emails. 90 percent of successful cyber attacks originate from one of these emails. 96 percent of IT security and decision makers expect to see email security challenges throughout 2026, so you’d be forgiven for thinking that most organizations would be meeting the basics. However, Comparitech’s findings found that more than eight percent of organizations’ domains are fully unprotected. 

This Wednesday, Comparitech researchers will be publishing a new study looking into this very subject by analyszing the live DNS records for 5,849 domains across 13 sectors, scoring each based on a series of frameworks. 

Key findings include: 

  • 487 of the total domains scanned (5,849) had zero protection (8.3%)
  • Government domains had the lowest average score – 2.73
  • Tech company domains had the highest average score – 4.83
  • China had the lowest average score – 2.3

Additionally, Rebecca Moody, Head of Data Research at Comparitech, provided the following comment on the subject: 

“If you asked people which industries they’d like to assume are meeting basic cybersecurity standards, government agencies and healthcare providers would likely be among some of the most popular answers. Our study highlights that, when it comes to standard email security, this couldn’t be further from the truth. 

The fact that over 1 in 4 government agencies and 1 in 5 healthcare providers have zero email protection is incredibly concerning, particularly when the factors we’ve assessed (SPF, DMARC, DKIM, or MTA-STS) are what many would call “standard” protocols. Equally, these sectors are often subject to more regulation, demonstrating that even when they should be meeting these requirements by law, they often aren’t.

One of the biggest risks of having gaps in email security is spoofing. Without the necessary protocols in place, hackers can spoof an organization’s domain, which adds to the legitimacy of their campaign. They could use this to send phishing emails, malware, or carry out a wire fraud scam, for example. Ultimately, the email security protocols we’ve assessed shouldn’t be seen as a recommendation or “good to have,” they should be viewed as being essential for all organizations.”

You can read the research here: https://www.comparitech.com/news/which-industry-country-has-the-worst-email-security-an-analysis-of-5800-domains-for-spf-dmarc-dkim-mta-sts-protocols/

Ohio city warns 123,000+ people of data breach that leaked SSNs, financial and medical info

Posted in Commentary with tags on July 1, 2026 by itnerd

Comparitech is reporting that the city of Middletown, Ohio today confirmed it notified 123,791 people of a July 2025 data breach that compromised names, SSNs, financial account info, medical info, health insurance info, addresses, and government-issued IDs. 

The cyberattack disrupted city services including water utility billing, which wasn’t fully restored until months later in January 2026.

Commenting on this news is Rebecca Moody, Head of Data Research at Comparitech

“This attack highlights why government agencies remain a key target for hackers.

First, the case shows just how disruptive these attacks can be, with Middletown only being able to restore its water billing system in January of this year, around six months after the attack took place. Second, governments are often in possession of vast quantities of data. Accessing such data not only gives hackers further leverage to demand a ransom, but it also gives them key data that they can sell on the dark web if negotiations fail. The fact that SafePay posted the City of Middletown to its data leak site suggests ransom negotiations failed (for the data theft at least). 

While government agencies are sometimes prevented from paying ransoms (or have to meet strict conditions in order to pay one, as is the case in Ohio), we saw a case just last month (Murray County in Georgia) where the ransom was paid in order to prevent county data from being published. 

It’s win-win for hackers. Receive a ransom demand to decrypt systems and/or delete data, or sell highly sensitive personal data on the dark web.”

I guess hackers are about to have a field day because they seriously hit the jackpot here. Which illustrates why stopping the bad guys from doing evil things is preferable to getting pwned.

May Ransomware Attacks: Education on the Rise and Healthcare on the Decline

Posted in Commentary with tags on June 4, 2026 by itnerd

Comparitech researchers published a new study looking at all tracked ransomware attacks in the month of May 2026. According to the findings, attacks increased by just over three percent since April, but remained relatively low compared to the previous months of the year. 

Interestingly, it was found that attacks on the education sector increased significantly from April (up by 54%), while helathcare providers and utilities companies saw the largest decline in attacks (down 21% and 29% respectively).

Key findings for May 2026 include: 

  • 661 attacks in total — 48 confirmed attacks (confirmed by the entity involved)
  • The most prolific ransomware gangs were Qilin (97), The Gentlemen (71), and DragonForce (51)
  • Qilin had the most confirmed attacks (9), followed by The Gentlemen (4) and INC (3)
  • Nearly 115 TB of data was stolen across all of these attacks
  • The US saw the most attacks (272), followed by Canada (31), the United Kingdom (28), and Germany (26)

Additionally, Rebecca Moody, Head of Data Research at Comparitech, commented: 

“While we should take some comfort in the fact that attack figures remained low(er) again in May, it’s important to remember that these figures are still incredibly high, particularly when compared to previous years. Furthermore, this slight reprieve isn’t being witnessed across all sectors and illustrates how hackers are often targeting specific sectors at certain times. For example, May saw a spike in the number of attacks being carried out in the education sector. This may not be a coincidence. As schools and teachers look forward to the holidays, hackers likely see this as a great opportunity to worm their way in while everyone’s starting to unwind and maybe isn’t as focused as usual.”

For full details, including a breakdown of most prolific ransomware gangs, the countries most targeted, and some of the most stand-out ransomware attacks of the month, the research can be read here: https://www.comparitech.com/news/ransomware-roundup-may-2026/

UK Surveillance Levels Exposed

Posted in Commentary with tags on May 28, 2026 by itnerd

Britain has become one of the most watched nations on Earth. According to a 2021 British Security Industry Association report, approximately 21 million CCTV cameras now operate across the country,  yet what’s far less understood is the dramatic variation in who’s watching whom, and with what technology.

To find out, Comparitech filed Freedom of Information requests with all 380 UK councils and 48 police forces, mapping exactly which parts of the country are under the heaviest surveillance. The research doesn’t stop at camera counts as it reveals which councils and forces have quietly adopted facial recognition technology (FRT) and automatic number plate recognition (ANPR)  and benchmarks UK surveillance levels against major cities around the world.

Key findings include:

  • Britain is home to seven of the world’s 20 most surveilled places, putting UK towns and cities in the same league as authoritarian regimes
  • A single London police force operates 31,000+ cameras, a surveillance network bigger than some entire countries
  • One East London council alone has over 3,000 cameras making it the highest of any council in the UK
  • A Northern England council has quietly built the UK’s biggest facial recognition network with 120 cameras that can scan and identify faces in real time
  • One UK police force monitors residents at a rate of nearly 49 cameras per 1,000 people
  • Council camera coverage peaks in one UK country, reaching 3.6 cameras per 1,000 people

Additionally, Rebecca Moody, Head of Data Research at Comparitech has provided her insights on the findings:

“The report highlights a clear imbalance in the levels of surveillance across the UK. While some councils have opted for widespread camera systems, others have steered clear — and, as we found, this has little (if anything) to do with crime rates.

From a privacy perspective, what’s also concerning is the use of real-time systems, such as ANPR and facial recognition. While they’re in place for certain tasks, e.g. to monitor cars for traffic violations and to seek out persons of interest, they ultimately subject all citizens to mass surveillance. And, as we note, there’s also a worrying risk of “mission creep”, whereby these systems are promoted as helping X but, after a while, they’re also used to combat Y, and then Z, until, before we know it, their use is extensive and widespread. Essentially, once a system is installed under the guise of combating a certain crime, it can be easily rolled out into other areas. For example, ANPR was introduced as an anti-terrorism tool but has quickly become a key system to help with traffic enforcement.”

You can find more here: https://www.comparitech.com/news/watching-you-funded-by-you-number-of-cctv-cameras-by-uk-council-police-force/

Which Island Nations Are Most Vulnerable to Undersea Cable Attacks?

Posted in Commentary with tags on May 13, 2026 by itnerd

This morning, Comparitech researchers published an analysis looking at all 48 island nations and their reliance on 126 undersea cables for access to the world’s internet.

These cables are often no thicker than a garden hose, leaving them vulnerable to damage. The International Cable Protection Committee (ICPC) reports 150 to 200 faults are reported on undersea cables each year. Of those, 70 to 80 percent resulted from accidental human activities, primarily anchors from shipping vessels. The rest are technical failures or natural disasters.

To gauge which of the island nations are most at risk of being cut off by accident or design, Comparitech looked at the number of undersea cables connecting them, the level of fishing activity that could cause accidental damage, and their proximity to conflict areas that could result in malicious damage.

New Zealand saw the least risk, while Brunei, Bahrain, Dominica, and Haiti were found to be at most risk. In terms of population, cable damage in Haiti would have the most significant impact due to the island’s 11.6 million population. 

The full study can be read here: https://www.comparitech.com/news/cut-off-which-island-nations-are-most-vulnerable-to-undersea-cable-attacks/

April Ransomware Report From Comparitech: Decline in Attacks, but Qilin Now Back on the Rise

Posted in Commentary with tags on May 5, 2026 by itnerd

This morning, Comparitech researchers published a study looking at all the ransomware attacks for April, finding that attacks actually dropped by nearly 22 percent, falling to the lowest level in six months. The only sector that did not see a decline in attacks, however, was the healthcare sector. 

Rebecca Moody, Head of Data Research at Comparitech, commented:

“While the dip in ransomware figures does make for positive reading, I don’t think we can pop the champagne cork just yet. As noted in the report, Qilin’s claims were down last month, which contributed significantly to the decline in attacks. But with 14 victims added to its site this month already, it looks like the small reprieve may be over. What the report also highlights is the ongoing focus on healthcare companies — both those providing direct care and those operating within the sector (e.g. medical billing providers). Some significant attacks were reported last month (namely Signature Healthcare and ChipSoft), which only served to remind us how extensive the impact these attacks can have on all types of healthcare companies.”

Key findings also included: 

  • 628 attacks in total — 43 confirmed attacks (confirmed by the entity involved)
  • Of the 43 confirmed attacks:
    • 27 were on businesses
    • 8 were on government entities
    • 4 were on healthcare companies
    • 4 were on educational institutions
  • Of the 585 unconfirmed attacks:
    • 524 were on businesses
    • 11 were on government entities
    • 41 were on healthcare companies
    • 9 were on educational institutions
  • The most prolific ransomware gangs were Qilin (105), The Gentlemen (67), and DragonForce (60)
  • INC had the most confirmed attacks (5), followed by Payload and The Gentlemen (4 each), and LockBit and DragonForce (3 each)
  • Nearly 125 TB of data was stolen across all of these attacks
  • The US saw the most attacks (260), followed by Canada (32), the United Kingdom (30), and Germany (29)

For full details, the study can be read here: https://www.comparitech.com/news/ransomware-roundup-april-2026/

Healthcare ransomware: Q1 2026 stats on attacks, ransoms, and data breaches 

Posted in Commentary with tags on April 29, 2026 by itnerd

Comparitech researchers have released a study looking at all the healthcare ransomware attacks in the first quarter of 2026. According to the findings, Q1 2026 saw 120 a recorded 120 ransomware attacks on hospitals, clinics, and other healthcare providers. Additionally, business operating within the healthcare sector (such as pharmaceutical/medical manufacturers, medical billing providers, or healthcare tech companies), saw a recorded 81 ransomware attacks. 

Interestingly, attacks on providers dipped 15% from the previous quarter, but attacks on healthcare businesses jumped 35%. 

Commenting on these findings is Rebecca Moody, Comparitech’s Head of Data Research: 

“Our latest quarterly healthcare report highlights how this sector remains one of the most dominant targets for hackers. For the last two quarters, attacks have been consistently high with hackers focusing on healthcare providers and businesses operating within the healthcare industry. This means healthcare providers not only have to safeguard their own systems from attacks but also need to ensure the third parties they’re using are reaching the same standards.

As the most dominant strain for many months now, Qilin’s attack figures far exceed those of other groups. But this isn’t the case when it comes to healthcare businesses. It claimed just three attacks in three months here, despite claiming 550 victims in total across Q1 of 2026. In contrast, it claimed 23 attacks on healthcare companies. 

LockBit and The Gentlemen are other key threats to healthcare providers, while INC appears to focus more on healthcare businesses (claiming eight attacks here compared to five on healthcare providers).

The focus on certain sectors by certain groups could be due to the success of certain campaigns within a particular industry, or an attempt to infiltrate a sector that isn’t as saturated/high profile when it comes to ransomware. For example, over the last year or so, we have noted a shift toward healthcare businesses. This could be due to how heavily targeted healthcare providers were in previous years. So, while some groups are still “enjoying” success in this sector, others have found a lucrative opening within companies that still deal with critical healthcare systems/services and/or store key healthcare data but don’t necessarily deal directly with patients.”

You can read the study here: https://www.comparitech.com/news/healthcare-ransomware-roundup-q1-2026-stats-on-attacks-ransoms-and-data-breaches/

Inside RAMP: What a leaked database reveals about Russia’s ransomware marketplace

Posted in Commentary with tags on April 22, 2026 by itnerd

Comparitech researchers have publised an in-depth analysis of RAMP (Russian Anonymous Marketplace), a Russian-language cybercrime forum that operated from late 2021 until being seized by the FBI in January 2026. 

Comparitech researchers gained exclusive access to a leaked database from RAMP, the dump containing user records, forum threats, private messages, IP logs, and admin activity from November 2021 through January 2024. 

In the analysis of this dump, the researchers have broken down details regarding the access market, the biggest listings, the affiliate splits, the criminal job market, the top vendors, the top buyers, and more. 

You can read the analysis here: https://www.comparitech.com/news/inside-ramp-what-a-leaked-database-reveals-about-russias-ransomware-marketplace/