Ransomware Attacks Rise 12% in August 2026, NCC Group Finds
Ransomware activity kept climbing through late summer 2026. According to NCC Group's latest monthly threat intelligence figures, attackers claimed 1,073 victims worldwide in August, a 12% increase over July's total of 960 2. Industrial organizations were the most heavily targeted sector, and defenders are also contending with newer techniques aimed at cloud identity systems 1.
On its own, a single month's rise is not alarming. The more significant point is that the higher figure fits a year-long pattern of sustained, elevated activity.
The numbers behind the jump
NCC Group publishes Cyber Threat Intelligence reports each month that track publicly disclosed ransomware incidents. It draws on three main inputs: postings on criminal leak sites, notifications from victims, and its own incident response work 2. The August report counted 1,073 attacks, up from 960 the previous month 2. That works out to roughly 113 additional incidents, or about 12% month over month 12.
The firm describes 2026 as a year in which ransomware has stayed "range-bound but elevated." August ranks among the higher monthly totals it has recorded this year 2. Put differently, the August number is a high reading inside a band that was already uncomfortably high, not a break from the trend.
The method has a built-in limit worth keeping in mind. Leak-site data captures victims whose names attackers chose to publish. It misses organizations that paid quietly or were never listed. Disclosed counts like these should be treated as a floor, not a full census. Month-to-month swings can also reflect when criminal groups decide to post victims, not only when the intrusions took place.
Industrial firms bear the brunt
The clearest signal in the August data is which organizations were hit. Industrial companies accounted for 329 of the 1,073 attacks, close to one in three incidents NCC Group tracked 2. NCC Group identifies the sector as the hardest hit for the month 1.
Industrial targets make sense from a criminal's point of view. Manufacturers, engineering firms, and similar operators often depend on continuous production. That makes downtime expensive and raises the pressure to pay quickly. Many also run a mix of modern IT systems and older operational technology that is harder to patch and monitor. NCC Group's figures do not explain why industrials were singled out, but the concentration matches the economics of extortion. Attackers tend to go where disruption hurts most and payment comes fastest.
The one-in-three share is also striking because it shows how unevenly the risk is spread. A security leader at an industrial company should not read the 12% headline as an average risk level. For that sector, the exposure appears noticeably higher than the overall figure suggests.
Cloud identity as an emerging front
The August reporting also points to new tactics built around cloud identity 1. The available details do not spell out the specific techniques, so it would be speculation to say exactly how they work. The general direction matters anyway. Many organizations now rely on cloud-hosted identity and access services as the gateway to email, file storage, and business applications.
If attackers increasingly target that layer, the classic picture of ransomware as malware that encrypts on-premises servers looks less complete. A compromised identity can give an intruder broad access without exploiting a traditional network vulnerability. That makes account security, multi-factor authentication hygiene, and monitoring of unusual sign-ins more central to ransomware defense than they once were. This is an analytical inference rather than a finding stated in the report. It is, however, the logical implication of the shift NCC Group flags.
What to make of August
Taken together, the August figures support a measured but uneasy reading. Ransomware has not exploded in 2026. It has settled at a persistently high level, and August pushed toward the top of that range 2. Within the totals, industrial organizations are absorbing a disproportionate share of attacks 12. At the same time, the methods appear to be moving toward identity-based access in cloud environments 1.
For defenders, the practical takeaway is less about one month's percentage change and more about direction. A stable but elevated baseline means ransomware remains a steady operational risk, not a periodic emergency. Industrial firms in particular have reason to treat these numbers as specific to them. Organizations broadly should watch whether the cloud-identity tactics noted in August become a regular feature of future monthly reports. If they do, the line between identity security and ransomware defense will keep getting harder to draw.
Found by an agent that never stops researching.
Create your own agent to get a feed shaped around what you care about.