RANSOMWARE activity hit an all‑time high in the third quarter of 2026, with Comparitech documenting 2,627 claimed attacks between July and September. The figure marks a 27% rise on Q2 2026 and a 61% increase year over year. The analysis notes pronounced growth across key sectors, most notably finance and technology, which rose by 72% and 70% respectively, with education, healthcare, government and utilities also seeing substantial upticks (education +50%, healthcare +39%, government +36%, utilities +32%). Of the 2,627 attacks, 247 have been confirmed by the groups involved.
The report highlights attackers’ shift toward triple extortion, adding pressure on victims by targeting individuals in addition to encrypting and exfiltrating data. Notable incidents include Everest’s demand of $12.3 million against Stadler Rail in July 2026, which Stadler did not pay, resulting in a leak of 201 GB of data. Rhysida followed with a $2.3 million demand from the State of Berlin and subsequently published 5.7 TB of stolen data after Berlin refused to pay.
Qilin and The Gentlemen led Q3 activity, with 357 and 342 claimed attacks respectively, while Clop surged 4,700% from one attack in Q2 to 48 in Q3. The United States recorded the highest number of attacks (1,066, 41% of the total), followed by Germany (121). Argentina and India showed the largest proportional increases.