Close Menu
  • Home
  • News
  • Security
  • Privacy
  • Cybercrime
    • Threat Groups
    • Ransomware
    • Explainers
    • Stealer Logs
  • AI
  • OSINT
  • Tools
    • Ransomtracker
    • Stealercheck
    • FortiBleed Checker
    • Site Check
  • Data
    • Ransomware statistics
    • Ransom payment rate
  • Newsletter
  • About Us
Facebook X (Twitter) Instagram Threads
Ransomnews
  • Home
  • News
  • Security
  • Privacy
  • Cybercrime
    • Threat Groups
    • Ransomware
    • Explainers
    • Stealer Logs
  • AI
  • OSINT
  • Tools
    • Ransomtracker
    • Stealercheck
    • FortiBleed Checker
    • Site Check
  • Data
    • Ransomware statistics
    • Ransom payment rate
  • Newsletter
  • About Us
Facebook X (Twitter) LinkedIn
Ransomnews
News

Confirmed ransomware attacks, August 2026: 51 verified so far, Qilin leads

Ransomnews Research TeamBy Ransomnews Research TeamSeptember 7, 2026No Comments5 Mins Read43 Views
Share Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
51 confirmed ransomware attacks in August 2026 so far, with a bar chart of confirmed attacks per month from August 2025 to August 2026
Share
Facebook Twitter LinkedIn Pinterest Email Copy Link

Ransomnews has confirmed 51 ransomware attacks in August 2026, down from the 62 recorded so far for July 2026 and well below the 136 now listed for August 2025. That gap is mostly a matter of timing rather than a fall in activity: recent months are still filling up as disclosures arrive, so the August figure is provisional and will rise over the coming weeks.

The count, and why it will rise

Every incident is checked against a public source, so a month only reaches its true size once victims, regulators and local press have caught up. The twelve months before August 2026 show the pattern clearly: months that have had a year to settle sit between 95 and 149 confirmed incidents, while the three most recent ones stand at 82 for May, 87 for June and 62 for July. A month typically keeps gaining entries for three to four months after it closes, so August will not look like this for long.

The running total for 2026 is 698 confirmed incidents through August, against 972 for the same eight months of 2025. Some of that difference is the same maturity effect, so it is too early to read a trend into it. The full list of August incidents, with the source link for each one, sits on the live page at confirmed ransomware attacks, August 2026, which updates as new disclosures are verified.

Which groups had the most confirmed victims

Of the 51 confirmed incidents, 36 carry an attribution to a named group and 15 do not. Qilin leads with nine confirmed victims, roughly a quarter of all attributed incidents for the month. The Gentlemen follow with four. DeadLock, Storm and Clop have two each, and Play, AiLock and Titan appear once apiece. The remaining attributed incidents are spread thinly across groups with a single confirmed victim each, so the named leaders account for a minority of the month’s total.

Attribution reflects what a public source recorded rather than an independent assessment.

Sectors and countries

Government bodies were the most affected sector with 12 confirmed incidents, ahead of manufacturing on 10. Healthcare recorded five, retail and technology four each, and finance three. A further nine incidents sit in a mixed category covering organisations that do not fit the main sector groupings, including housing associations, publishers and sports clubs.

// Free tool

How does your own site score?

Run the same forty passive checks against your own domain — TLS and certificates, security headers, SPF and DMARC, cookies before consent, and what your stack quietly reveals. A grade out of 100 in about fifteen seconds.

No signup. Nothing installed. We only request what your site already serves publicly.

Victims were spread across 27 countries. The United States accounted for 10, Japan for five, France and Germany for three each, and Italy, the United Kingdom, Taiwan and Austria for two each. One caveat applies to every country comparison of this kind: US breach-notification law pushes more incidents onto the public record than most other jurisdictions require, so the American share of any confirmed dataset reflects disclosure rules as much as attacker targeting.

Notable confirmed incidents

  • Bureau of Alcohol, Tobacco, Firearms and Explosives, Washington DC, United States, government, attributed to Qilin (source)
  • Arbeiterkammer, the Austrian Chamber of Labour, Salzburg, Austria, attributed to The Gentlemen, and the month’s largest incident by disclosed record count at around 270,000 (source)
  • Shell, London, United Kingdom, attributed to Clop (source)
  • Philips, Amsterdam, Netherlands, manufacturing, attributed to Clop (source)
  • Health Sciences Centre, Winnipeg, Canada, healthcare, no group named (source)
  • Hvidovre Hospital, Hvidovre, Denmark, healthcare, no group named (source)
  • Gobierno de Castilla-La Mancha, Spain, government, attributed to Panzer (source)
  • Corte de Constitucionalidad, Guatemala City, Guatemala, government, no group named, and one of the few victims recorded as having refused to pay (source)

Ransom outcomes

One of the 51 confirmed victims is recorded as having paid, three as having refused, and the remaining 47 give no public indication either way. Most organisations never say what they did, and those that do usually have a legal or regulatory reason to speak. Any payment rate calculated from confirmed incidents is therefore a floor built on a small and self-selecting sample, a point covered in more detail in the ransomware payment rate analysis.

Record counts are similarly thin: only three incidents disclosed a number of affected records, totalling about 270,500, almost all of that the Austrian Chamber of Labour case. Absence of a figure means nothing was published, not that nothing was taken.

Frequently asked questions

How many ransomware attacks were confirmed in August 2026?

Ransomnews has confirmed 51 ransomware attacks in August 2026 so far, each one verified against a public source. The figure is provisional and rises as further disclosures are published and checked.

Which ransomware group was most active in August 2026?

Qilin, with nine confirmed victims. The Gentlemen were second with four. Of the 51 confirmed incidents, 36 carry an attribution to a named group.

Which industry was hit most in August 2026?

Government, with 12 confirmed incidents, ahead of manufacturing on 10 and healthcare on five.

Is the August 2026 figure final?

No. Confirmed counts keep climbing for three to four months after a month ends, because victims, regulators and local press disclose incidents on their own timetables. The live month page carries the current total.

Sources and further reading

  • Confirmed ransomware attacks, August 2026, the live month page with every incident and its source
  • Confirmed ransomware attacks, 2026, the year to date
  • Ransomware statistics
  • Ransomware payment rate
  • The confirmed attacks hub

The Ransomnews Monthly

One email a month. Original leak-site data, victim census updates, and the findings that did not make the articles. No spam, unsubscribe any time.

Double opt-in. We store your email, signup time, and IP for consent records (GDPR Art. 7). See our privacy policy.

Share. Facebook Twitter Pinterest LinkedIn Tumblr Telegram Email Copy Link
Previous ArticleThe Town 2025 ticketing data sold as a Ticketmaster breach
Next Article Condé Nast: 32.8M user records for sale, sample verified
Ransomnews Research Team

The Ransomnews Research Team is the collective byline used for collaborative pieces, editorial briefings, and articles drawing on contributions from multiple researchers. Coverage spans ransomware operations, breach economics, threat actor profiling, OSINT methodology, and emerging risks across security, privacy, and AI.

Related Posts

Is it illegal to pay a ransomware ransom in 2026?

September 7, 2026

ESXi ransomware in 2026: one host, the whole datacenter

June 24, 2026

MSPs: ransomware’s #1 target of 2026 [Field Report]

May 11, 2026

Comments are closed.

// The Ransomnews Monthly

What leaked, what held up

One email a month: the datasets we verified, and the ones that fell apart under scrutiny.

Double opt-in. We store your email, signup time, and IP for consent records (GDPR Art. 7). See our privacy policy.

// Free tool

How does your own site score?

Forty passive checks on TLS, security headers, email spoofing and privacy. A grade out of 100 in about fifteen seconds.

No signup. Nothing installed. We only request what your site already serves publicly.

// Free tool

Were you in a leak?

Check whether an email address has surfaced in infostealer logs. No signup, no data stored.

Run StealerCheck

// Live data

Ransomtracker

Victims as they are posted to ransomware leak sites, tracked continuously and checked against the claims.

Open the tracker

9,520 confirmed attacks tracked

Facebook X (Twitter) LinkedIn
© 2026 Ransomnews.com

Type above and press Enter to search. Press Esc to cancel.

Cookies on Ransomnews

We use strictly-necessary cookies to run the site and may use first-party analytics to understand which articles are read. Some pages contain affiliate links — when you click one, the affiliate network sets cookies on the merchant's domain to attribute the referral. See the Cookie Policy and Affiliate Disclosure for detail.

RANSOMNEWS.COM

Tracking the criminal infrastructure of the internet.

Independent coverage of ransomware, breach economics, threat actors, privacy, AI security, and the open-source investigation toolkit.

// Topics

  • News
  • Security
  • Privacy
  • Cybercrime
  • AI
  • OSINT
  • Threat Groups
  • Stealer Logs
  • Ransomtracker
  • Stealercheck
  • FortiBleed Checker
  • Site Check

// Site

  • About Us
  • Editorial Team
  • Contact
  • Tip Line
  • Editorial

// Legal

  • Privacy Policy
  • Terms of Service
  • Cookie Policy
  • Funding & Independence
  • RSS Feed
© 2026 Ransomnews.com · Tracking the criminal infrastructure of the internet.