Listen to this Post

A Record-Breaking Month With a Complicated Reality
July 2026 was supposed to be another difficult month for enterprise cybersecurity. Instead, it became a warning sign for how quickly the ransomware economy is expanding, evolving, and learning to exploit new technology.
According to research from NCC Group, ransomware groups publicly listed 894 victim organizations during July, making it the highest monthly figure recorded so far in 2026. The number represented a 22% increase compared with June, putting July at the center of renewed concern over the global ransomware crisis.
But there is an important question hiding behind that dramatic statistic: Does a higher number of claimed victims necessarily mean ransomware attacks are becoming more successful?
Not always.
Ransomware leak sites are not neutral databases. They are part of the extortion ecosystem. Criminal groups use them to pressure victims, attract affiliates, build reputations, and compete with rival operations. Some claims are legitimate. Others can be exaggerated, incomplete, duplicated, or impossible to independently verify.
That distinction matters enormously when analyzing
At the same time, dismissing the increase would be an even bigger mistake. Behind the questionable claims are very real attacks against major organizations, increasingly aggressive ransomware-as-a-service operations, and an emerging generation of attacks experimenting with artificial intelligence.
July therefore represents something more complicated than simply “the worst month for ransomware.”
It may have been the month when the ransomware industry became larger, noisier, more automated, and harder to measure at the same time.
July Delivered 894 Publicly Listed Victims
NCC
That figure represents a 22% month-over-month increase from June and establishes a year-to-date high for 2026.
The statistic immediately sounds catastrophic, and there is certainly reason for concern. Every confirmed victim represents a potentially disrupted organization, stolen information, operational downtime, financial losses, regulatory exposure, or reputational damage.
Yet “victim listing” should not automatically be interpreted as “confirmed successful ransomware attack.”
That distinction is one of the most important lessons from July.
The Industrial Sector Became a Major Target
The industrial sector accounted for almost one-third of the incidents recorded by NCC Group.
That concentration is particularly worrying because industrial organizations often operate systems that cannot simply be taken offline without consequences.
Manufacturing plants, logistics operations, engineering companies, energy-related organizations, and other industrial businesses can face enormous costs when IT systems become unavailable.
A ransomware incident affecting an ordinary office might prevent employees from accessing email and documents.
A ransomware incident affecting an industrial environment can potentially interrupt production itself.
The United States Remained the Biggest Target
Geographically, the United States accounted for approximately 41% of recorded incidents.
Europe represented another 29%, followed by Asia at 14% and South America at 9%.
The distribution reflects the continuing attraction of economically valuable targets.
Attackers are not necessarily searching randomly for organizations. They are looking for environments where disruption creates pressure to pay.
Large companies with sensitive information, complicated supply chains, limited downtime tolerance, or valuable intellectual property can become especially attractive targets.
Ten Groups Dominated
NCC Group attributed a significant portion of the reported activity to ten ransomware organizations.
The Gentlemen: 138 Claims
The Gentlemen reportedly led the July rankings with 138 victim listings.
Its position demonstrates how quickly a ransomware operation can become prominent when its affiliate network and extortion infrastructure begin generating large numbers of claims.
Qilin: 127 Claims
Qilin followed closely behind with 127 listed victims.
Its presence near the top reinforces the importance of established ransomware ecosystems that can repeatedly target organizations rather than relying on isolated attacks.
Deadlock: 84 Claims
Deadlock accounted for 84 claims, placing it firmly among July’s most active groups.
The volume illustrates how fragmented the ransomware landscape has become, with multiple operations competing simultaneously for victims and affiliates.
DragonForce: 43 Claims
DragonForce recorded 43 listings.
Its activity shows that ransomware groups do not need to dominate the overall rankings to remain commercially relevant within the criminal ecosystem.
INC Ransom: 38 Claims
INC Ransom appeared with 38 claimed victims.
The group remains another example of how established ransomware brands can maintain significant activity even while newer operations attempt to enter the market.
CRPxO: 36 Claims
CRPxO is perhaps the most interesting case in July.
The group reportedly appeared with 36 claimed victims shortly after emerging, immediately raising questions about whether its numbers accurately represented confirmed compromises.
SafePay: 33 Claims
SafePay recorded 33 victims.
Its appearance among the leading groups highlights the continuing resilience of ransomware-as-a-service operations.
Global Secret Group: 31 Claims
Global Secret Group accounted for 31 listings.
Its activity contributed to an increasingly crowded ransomware marketplace.
KryBit: 25 Claims
KryBit recorded 25 claims, demonstrating that the ransomware economy is not dependent on just a handful of dominant operators.
Akira: 22 Claims
Akira rounded out the top ten with 22 listings.
The combined activity of these groups paints a picture of an ecosystem with numerous competing operators, affiliates, and extortion campaigns.
Big Numbers Do Not Automatically Mean Bigger Damage
There is a temptation to treat ransomware statistics like a scoreboard.
More victims must mean more successful attacks.
But ransomware does not work that neatly.
A public leak-site listing can represent a confirmed compromise, an alleged compromise, an organization that refuses to negotiate, a victim whose data was stolen, or a claim that has not yet been independently validated.
That makes attribution and measurement extremely difficult.
The distinction becomes particularly important when newly established groups suddenly report dozens of victims.
CRPxO Became
CRPxO is an excellent example of why ransomware statistics require skepticism.
The group reportedly claimed 36 organizations shortly after appearing on the scene.
Among its alleged high-value victims were organizations such as Johnson & Johnson and Turkish Airlines, although those claims had not been confirmed.
That is an extraordinary amount of activity for a newly emerged operation.
The question is simple.
How could a new ransomware group immediately accumulate such a large collection of major victims?
There are several possible explanations.
It could have recruited experienced affiliates who already had access to compromised networks.
It could have inherited or absorbed existing criminal infrastructure.
It could have rapidly scaled through ransomware-as-a-service.
Or, more concerning from a measurement perspective, some of its claims could have been exaggerated.
Ransomware Is Also a Business of Reputation
Modern ransomware groups are not merely trying to encrypt computers.
They are running criminal businesses.
They need affiliates.
They need infrastructure.
They need technical operators.
They need victims.
And perhaps most importantly, they need credibility.
A ransomware group claiming dozens of recognizable victims can make itself look successful to potential affiliates.
That creates a powerful incentive to advertise.
The more impressive the victim list appears, the easier it may become to attract criminals looking for a ransomware platform to join.
CRPxO’s Business Model Raises More Questions
According to the research cited in the original report, CRPxO operates under a ransomware-as-a-service model.
The operation reportedly offered affiliates 70% of ransom payments, while advertising a relatively low entry price of around $333.
That model lowers the technical and financial barrier for criminals who want to participate.
Instead of developing ransomware infrastructure from scratch, affiliates can potentially join an existing ecosystem and concentrate on finding victims.
The group also reportedly had evidence of a leak site, Telegram presence, and Tor-based infrastructure.
Those signs indicate that CRPxO was not simply a random account making claims online.
But infrastructure alone does not prove that every claimed victim was successfully compromised.
NCC Group Rated
NCC Group reportedly assessed
The assessment was influenced by the absence of independently verified victim datasets and what researchers described as inconsistent evidence quality.
That is an important distinction.
The researchers did not simply declare that
Instead, they highlighted the lack of sufficient evidence to treat every claim as reliable.
This is precisely the kind of uncertainty that should accompany ransomware statistics.
Leak Sites Are Part of the Attack
A ransomware leak site is not merely a place where stolen files are published.
It is a psychological weapon.
Attackers use the threat of publication to increase pressure on victims.
A company might have backups and refuse to pay for decryption, but stolen customer records, employee information, contracts, financial documents, or intellectual property can create a second layer of pressure.
The attacker is effectively saying:
You may survive the encryption, but can you survive the disclosure?
That strategy has helped ransomware evolve from a destructive malware problem into a sophisticated extortion industry.
The EY Incident Added to
July also included several notable incidents.
Ernst & Young, commonly known as EY, experienced a data breach during the month that reportedly exposed client information and tax-related records.
The ShinyHunters group claimed responsibility.
The incident illustrates another important trend: ransomware-related criminal ecosystems increasingly overlap with pure data theft and extortion.
An organization does not necessarily need to suffer widespread encryption for attackers to cause serious damage.
Fairlife Was Hit by a Ransomware Incident
Coca-Cola subsidiary Fairlife also suffered a ransomware attack.
The Anubis ransomware group was believed to be involved, and the attackers claimed to have stolen more than 1 TB of data.
As with many criminal claims, the exact scale of the alleged theft should be treated carefully until independently confirmed.
Nevertheless, the incident illustrates why data theft remains one of the most valuable components of modern ransomware operations.
Analog Devices Faced an Unverified Extortion Claim
The ExfilSquad extortion group later claimed that it had stolen approximately 570,000 records from Analog Devices.
However, that claim had not been independently verified.
This is another example of why ransomware reporting requires two separate questions:
Did the group make the claim?
And:
Did the claimed breach actually happen at the stated scale?
Those are not the same question.
Deep Analysis: How to Investigate Ransomware Claims Safely
Start With Evidence, Not Headlines
Security teams should avoid treating leak-site claims as confirmed incidents until evidence is available.
A public claim can be used as an indicator for investigation, but it should not automatically become an incident report.
The first step is to compare the claim against internal telemetry, endpoint alerts, identity logs, network activity, and known indicators of compromise.
Search Endpoint Logs for Suspicious Processes
On Linux systems, administrators can begin investigating unusual processes with commands such as:
ps aux --sort=-%cpu | head -25
This can help identify unexpectedly resource-intensive processes.
For recently created files, defenders can inspect suspicious directories with:
find /tmp /var/tmp -type f -mtime -2 -ls 2>/dev/null
The commands themselves do not prove ransomware activity.
They simply provide starting points for investigation.
Examine Authentication Activity
Unexpected authentication events can reveal early signs of compromise.
On systems using common Linux authentication logs, defenders can inspect recent activity with:
grep -Ei "failed|accepted|invalid" /var/log/auth.log | tail -100
Organizations should adapt the path and logging configuration to their distribution.
Repeated authentication failures followed by a successful login can deserve immediate investigation.
Look for Unusual File Encryption Activity
A sudden explosion in file modifications can be an important ransomware indicator.
For example:
find /important/data -type f -mmin -30 -printf '%TY-%Tm-%Td %TH:%TM %p ' 2>/dev/null | head -200
This can help investigators identify recently modified files.
Again, file modification alone does not prove ransomware.
Backup jobs, software updates, database operations, and legitimate administrative activity can produce similar patterns.
Check Network Connections
Unexpected outbound connections can also provide valuable evidence.
A basic Linux check is:
ss -tupn
Security teams can compare unusual remote connections against known corporate services, approved infrastructure, threat intelligence, and historical network behavior.
Review Windows Event Logs
Windows environments require a different investigative approach.
PowerShell can be used to review recent security events:
Get-WinEvent -LogName Security -MaxEvents 100
Defenders can then investigate suspicious account activity, privilege escalation, remote logins, and process execution.
For enterprise environments, centralized SIEM telemetry should generally be preferred over checking individual endpoints manually.
Search for Known Indicators
If a security team receives indicators associated with a ransomware group, it can search them across logs and endpoint telemetry.
For example:
IP addresses
Domains
File hashes
Suspicious filenames
Known malware paths
Unusual PowerShell commands
Unexpected administrative accounts
Indicators should always be validated before blocking because threat intelligence can contain false positives or outdated infrastructure.
Protect Backups Before the Attack Happens
The most valuable ransomware command is sometimes no command at all.
It is a verified backup.
Organizations should maintain backups that ransomware operators cannot easily access, delete, encrypt, or modify.
Offline or logically isolated copies can dramatically improve recovery options.
A backup that remains permanently connected to the same administrative environment as production systems may become another ransomware target.
Test Restoration, Not Just Backup Creation
A backup system is not proven because it successfully reports “backup completed.”
It is proven when an organization can restore critical systems within an acceptable recovery window.
Security teams should periodically test:
Backup integrity
Restoration procedures
Recovery time
Recovery point objectives
Credential availability
Application dependencies
Database consistency
The question should be:
If every production server disappeared tonight, could the organization actually recover?
July’s Numbers May Contain Both Truth and Noise
This is perhaps the most important conclusion from the entire report.
The ransomware problem is real.
The attacks are real.
The financial consequences are real.
But the public victim-counting system is imperfect.
That means cybersecurity professionals should resist both extremes.
It would be irresponsible to dismiss the 894 figure simply because some claims may be unreliable.
It would also be irresponsible to interpret all 894 listings as independently confirmed successful attacks.
The truth is likely somewhere between those extremes.
What Undercode Say:
A Record Is a Warning, Not the Entire Story
The 894 victim listings recorded in July are alarming, but the most interesting part of the story is not the number itself.
It is the uncertainty surrounding the number.
Ransomware Has Become a Reputation Economy
Criminal groups now compete for affiliates and credibility much like legitimate technology companies compete for customers.
A large victim list can become a marketing tool.
CRPxO Shows Why Attribution Matters
CRPxO’s rapid appearance with 36 claimed victims demonstrates how quickly a new operation can create the appearance of scale.
That appearance may attract more criminals.
RaaS Has Lowered the Entry Barrier
Ransomware-as-a-service means attackers do not necessarily need to understand every technical component of ransomware development.
They can increasingly buy access to an ecosystem.
Cheap Access Can Produce Expensive Damage
A reported $333 entry price is insignificant compared with the potential financial damage caused by a successful enterprise intrusion.
That imbalance is one reason the criminal business remains attractive.
Affiliates Are the Multipliers
The ransomware developer does not need to personally attack every organization.
Affiliates can conduct intrusions while the core operation provides infrastructure, malware, payment mechanisms, and negotiation support.
Leak Sites Are Psychological Infrastructure
The public victim site is part of the extortion mechanism.
It creates urgency, embarrassment, fear, and reputational pressure.
Public Claims Can Become Self-Reinforcing
A criminal group announces dozens of victims.
Security researchers report the claims.
News organizations report the research.
Potential affiliates see the publicity.
The group suddenly looks more successful.
That can produce additional recruitment.
Measurement Is Becoming Harder
Traditional ransomware statistics often depend on observable victim claims.
But criminals have an incentive to manipulate what is observable.
That makes raw counts increasingly imperfect.
AI Could Make Measurement Even Harder
The appearance of AI-assisted or agentic ransomware introduces another complication.
If automated systems can perform reconnaissance, decision-making, tool selection, and portions of intrusion activity, attribution becomes more difficult.
JadePuffer Is a Major Warning Sign
The reported JadePuffer campaign is particularly significant because it was described as the first documented ransomware attack powered by AI from beginning to end.
Even if such attacks remain relatively uncommon, the concept changes the threat model.
AI Does Not Need to Replace Humans Completely
Attackers do not need fully autonomous ransomware to benefit from AI.
An AI system that accelerates reconnaissance or automates repetitive intrusion tasks could already provide meaningful advantages.
Automation Can Increase Scale
A human operator has limited time.
An automated system can potentially investigate many targets simultaneously.
That creates an obvious scaling advantage.
Defenders Have the Same Opportunity
The situation is not entirely one-sided.
AI can also help defenders identify suspicious activity, correlate logs, summarize alerts, detect anomalies, and prioritize incidents.
The coming security race will therefore involve automation on both sides.
The Industrial Sector Deserves Special Attention
Industrial organizations are particularly sensitive because downtime can directly translate into lost production.
Security programs protecting these environments need to account for operational technology, not just conventional IT systems.
Critical Infrastructure Remains Attractive
The same economics that make industrial companies attractive can apply to healthcare, financial services, energy, transportation, and other critical sectors.
Where downtime is expensive, extortion pressure becomes stronger.
Healthcare Is Especially Vulnerable
Healthcare organizations hold highly valuable information while operating under intense availability requirements.
A ransomware incident can therefore create both financial and operational pressure.
Data Theft Makes Encryption Less Important
Modern ransomware does not always depend on encryption.
If attackers steal enough valuable information, they can threaten disclosure even when the victim can restore systems from backups.
Strong Backups Reduce Extortion Power
Reliable backups do not necessarily prevent data theft.
But they can remove one of the
Identity Security Is Increasingly Important
Attackers often seek credentials and privileged access because administrative accounts can provide enormous control.
Strong authentication, least privilege, and careful monitoring are therefore essential.
MFA Is Not a Magic Shield
Multi-factor authentication dramatically improves security in many scenarios.
However, compromised sessions, stolen tokens, social engineering, and other techniques can still create risk.
Organizations should treat MFA as one layer, not the entire defense.
Segmentation Can Limit Blast Radius
Network segmentation can prevent one compromised system from becoming a gateway to an entire organization.
The goal is containment.
If an attacker breaches one workstation, they should not automatically receive access to every server.
Least Privilege Limits Criminal Freedom
A compromised account should have only the permissions necessary for legitimate work.
The fewer privileges an attacker obtains, the more difficult widespread compromise becomes.
Monitoring Needs Context
Security teams should not simply collect enormous quantities of logs.
They need useful correlations.
A failed login followed by an unusual privileged login from a new location may be far more valuable than thousands of ordinary events.
Ransomware Detection Must Be Fast
The difference between an isolated compromised endpoint and an enterprise-wide incident can sometimes be measured in hours.
Rapid detection is therefore a strategic capability.
Incident Response Plans Need Practice
An incident response document that has never been tested is not a reliable defense.
Organizations should conduct tabletop exercises and technical recovery drills.
Communication Is Part of Cybersecurity
Ransomware incidents can involve legal, regulatory, operational, financial, and public-relations decisions.
Security teams cannot operate in isolation.
Cyber Insurance Does Not Eliminate Risk
Insurance can help with financial consequences.
It cannot restore lost trust automatically.
It cannot undo stolen information.
It cannot instantly recover a disrupted production environment.
Paying Ransom Is Not a Complete Solution
Even when organizations pay, there is no guarantee that stolen data will be deleted or that attackers will not return.
Recovery and containment remain essential.
Criminal Groups Will Continue to Rebrand
Ransomware operations frequently disappear, reorganize, rename themselves, or split into competing groups.
That means today’s leading group may not be tomorrow’s leading group.
The Business Model Is More Important Than the Brand
Security teams should focus less on memorizing every ransomware name and more on understanding attacker behaviors.
Credential theft, privilege escalation, lateral movement, data exfiltration, and destructive actions remain important regardless of the malware’s branding.
July Could Be a Turning Point
The combination of high victim claims, new ransomware groups, questionable reporting, and AI experimentation makes July particularly significant.
It is not simply another month in a long ransomware timeline.
It could represent the beginning of a more automated phase.
The Biggest Risk May Be Scale
Ransomware has already demonstrated that small criminal teams can cause enormous damage.
AI could potentially allow those teams to operate more efficiently.
The Biggest Defense Is Resilience
Organizations cannot guarantee that attackers will never get inside.
They can, however, make compromise less damaging.
Strong identity controls, segmentation, backups, monitoring, patching, and tested recovery all contribute to resilience.
The 894 Figure Should Trigger Investigation
Rather than asking only whether 894 is the “real” number, security leaders should ask what the trend is telling them.
Attackers remain active.
Criminal infrastructure remains profitable.
New groups continue appearing.
And automation is beginning to enter the equation.
The Ransomware Economy Is Adapting
The criminals are learning from every failed attack.
They are improving recruitment.
They are experimenting with AI.
They are refining extortion.
Defenders need to adapt just as quickly.
The Most Dangerous Number Is Not 894
The most concerning number may be the number of organizations that discover an attack only after the attackers have already obtained administrative access.
That number is much harder to measure.
July’s Lesson Is Simple
Do not confuse visibility with reality.
A ransomware leak site shows what criminals want the world to see.
Defensive telemetry shows what happened inside the environment.
The second source is ultimately more valuable.
Prediction
(+1) AI-Assisted Ransomware Will Become More Common
AI will increasingly be used to automate reconnaissance, analyze stolen information, generate scripts, identify valuable systems, and accelerate repetitive attacker tasks.
Fully autonomous ransomware may remain uncommon for some time, but partial automation is likely to become increasingly normal.
(+1) Ransomware-as-a-Service Will Continue Growing
Low entry barriers and affiliate-based revenue models make ransomware attractive to criminals who lack the resources to develop complete operations themselves.
New groups are therefore likely to continue appearing.
(+1) Victim Claims Will Become Harder to Verify
As criminal groups compete for attention and affiliates, exaggerated or questionable claims may become more common.
Security researchers will increasingly need confidence ratings rather than simple victim counts.
(+1) Defensive Automation Will Become Essential
Security teams will increasingly use AI and automation to correlate telemetry, detect anomalies, investigate suspicious behavior, and accelerate incident response.
Human analysts will remain important, but they will increasingly supervise automated systems.
(-1) Ransomware Victim Numbers Are Unlikely to Fall Quickly
As long as extortion remains profitable and organizations continue to hold valuable data, ransomware will remain an attractive criminal business.
A major reduction will require improvements across identity security, vulnerability management, backups, segmentation, detection, law enforcement, and criminal infrastructure disruption.
✅ July 2026 Recorded 894 Ransomware Victim Listings
The supplied article accurately attributes the 894 figure to NCC Group’s July research and describes it as a year-to-date high.
The important qualification is that these are recorded victim listings, not necessarily 894 independently confirmed successful compromises.
✅ Ransomware Activity Increased 22% Month Over Month
The article states that NCC Group measured a 22% increase compared with June 2026.
This supports the conclusion that July represented a significant increase in publicly recorded ransomware activity.
⚠️ Some Victim Claims Remained Unverified
Claims involving organizations such as Turkish Airlines, Johnson & Johnson, and Analog Devices were not independently confirmed in the supplied material.
Those allegations should therefore be presented as claims, rather than established facts.
✅ CRPxO Was Assessed With Limited Confidence
The supplied report says NCC Group assessed CRPxO’s credibility as low to moderate because of limited datasets, absent victim confirmation, and inconsistent evidence quality.
That makes CRPxO one of the strongest examples of why raw ransomware statistics should be interpreted carefully.
⚠️ 894 Does Not Equal 894 Confirmed Attacks
The headline number is useful for measuring publicly observed ransomware activity, but it should not be interpreted as a perfect measurement of real-world successful attacks.
Ransomware reporting contains both legitimate incidents and varying levels of unverified criminal claims.
✅ AI Is Becoming Part of the Ransomware Threat
The supplied article identifies JadePuffer as a reported example of an AI-powered ransomware attack chain.
Whether fully autonomous ransomware becomes widespread remains uncertain, but the increasing experimentation with AI by cybercriminals is a legitimate security concern.
▶️ Related Video (76% Match):
🕵️📝Let’s dive deep and fact‑check.
🎓 Live Courses & Certifications:
Join Undercode Academy for Verified Certifications
🚀 Request a Custom Project:
Secure, high-velocity infrastructure and disruptive technological engineering. Contact our engineering team for high-tier development and proprietary systems:
[email protected]
💎 Smart Architecture | 🛡️ Secure by Design | ⭐ Trusted by Thousands
References:
Reported By: www.zdnet.com
Extra Source Hub (Possible Sources for article):
https://www.instagram.com
Wikipedia
OpenAi & Undercode AI
Image Source:
Unsplash
Undercode AI DI v2
🔐JOIN OUR CYBER WORLD [ CVE News • HackMonitor • UndercodeNews ]
📢 Follow UndercodeNews & Stay Tuned:
𝕏 formerly Twitter 🐦 | @ Threads | 🔗 Linkedin | 🦋BlueSky | 🐘Mastodon | 📺Youtube




