Close Menu
  • Home
  • News
  • Security
  • Privacy
  • Cybercrime
    • Threat Groups
    • Ransomware
    • Explainers
    • Stealer Logs
  • AI
  • OSINT
  • Tools
    • Ransomtracker
    • Stealercheck
    • FortiBleed Checker
    • Site Check
  • Data
    • Ransomware statistics
    • Ransom payment rate
    • Breach verification
  • Newsletter
  • About Us
Facebook X (Twitter) Instagram Threads
Ransomnews
  • Home
  • News
  • Security
  • Privacy
  • Cybercrime
    • Threat Groups
    • Ransomware
    • Explainers
    • Stealer Logs
  • AI
  • OSINT
  • Tools
    • Ransomtracker
    • Stealercheck
    • FortiBleed Checker
    • Site Check
  • Data
    • Ransomware statistics
    • Ransom payment rate
    • Breach verification
  • Newsletter
  • About Us
Facebook X (Twitter) LinkedIn
Ransomnews
News

Confirmed ransomware attacks, September 2026: 55 verified so far, Qilin and The Gentlemen lead

Ransomnews Research TeamBy Ransomnews Research TeamOctober 5, 2026No Comments4 Mins Read102 Views
Share Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
Chart of confirmed ransomware attacks per month to September 2026, showing 55 confirmed so far for September
Share
Facebook Twitter LinkedIn Pinterest Email Copy Link

Ransomnews has confirmed 55 ransomware attacks in September 2026, against 107 in August 2026 and 151 in September 2025. The figure is provisional: September closed recently, and confirmed counts keep climbing for months after a month ends, so this total will rise. Government bodies led the sectors with 14 incidents, and Qilin and The Gentlemen each had four confirmed victims.

The count, and why it will rise

Every row behind this report is an incident verified against a public source, which means a month only fills in as organisations issue statements, regulators publish notifications and local outlets pick up the story. Over the twelve months to August 2026 the confirmed table averaged about 109 incidents a month, and a month’s figure typically keeps rising for three to four months after it ends. September’s 55 should therefore be read as a floor, not a total, and the gap with August’s 107 is mostly a reporting lag rather than a measured drop in activity.

The live September 2026 page carries the full incident list with a source link for every entry, and it updates as new disclosures are verified. For the wider year, 859 incidents are confirmed across 2026 so far, against 1,128 over the same January to September window in 2025.

Which groups had the most confirmed victims

Of the 55 confirmed incidents, 38 carry an attributed group, so roughly a third are recorded without one. Qilin and The Gentlemen tied at the top with four confirmed victims each. Dire Wolf, Rhysida and INC each had three, and SETTRA, LockBit and Kairos each had two. The counts are small enough that one late disclosure can reorder the table, and attribution usually rests on a leak-site listing or on the victim naming the group, so the shape of the month matters more than the ranking.

Sectors and countries

Government was the most affected sector with 14 incidents, followed by healthcare with 11 and education with eight. Technology recorded five, retail four, transportation three, and services and manufacturing two each. Public bodies and hospitals are over-represented in confirmed data partly because they are obliged to tell people when services stop.

Incidents came from 29 countries. The United States led with 12, then Japan with six, Germany with five and Australia with three, with France, Spain, Italy and South Africa on two each. That distribution reflects disclosure rules as much as targeting: US breach-notification law pushes more incidents onto the public record than most other jurisdictions do.

Free tool

How does your own site score?

Run the same forty passive checks against your own domain: TLS and certificates, security headers, SPF and DMARC, cookies before consent, and what your stack quietly reveals. A grade out of 100 in about fifteen seconds.

No signup. Nothing installed. We only request what your site already serves publicly.

Notable confirmed incidents

  • Air Traffic and Navigation Services, Gauteng, South Africa, government, group not attributed. Source
  • Namibian Defence Force, Windhoek, Namibia, government, attributed to RansomHouse. Source
  • Tottori Prefecture environmental radiation monitoring system, Tottori, Japan, government, group not attributed. Source
  • Poder Judicial de la Provincia de Jujuy, Jujuy, Argentina, government, attributed to EMPERADOR. Source
  • Mississippi Institutions of Higher Learning, Mississippi, United States, government, group not attributed. Source
  • Springfield Public Schools, Massachusetts, United States, education, attributed to Interlock. Source
  • DFI Retail Group, Quarry Bay, Hong Kong, retail, attributed to SETTRA. Source
  • Data Hub, Kathmandu, Nepal, technology, group not attributed, with stock market trading halted. Source

Springfield Public Schools is also the month’s largest confirmed incident by records, at about 10,000. It is the only September row so far with a records figure attached, which is normal this early: record counts tend to surface in regulator filings weeks or months after the attack itself.

Ransom outcomes

No September 2026 row records a ransom payment, and eight record a refusal. The remaining 47 are unknown, which is the usual outcome: most victims never say either way, and the ones who do speak are disproportionately those who refused and recovered from backups. The confirmed figures therefore describe what organisations have disclosed, not how often ransoms are actually paid. Our payment-rate analysis sets out how far the public record can be pushed on this question.

Frequently asked questions

How many ransomware attacks were confirmed in September 2026?

Ransomnews has confirmed 55 ransomware attacks in September 2026, each verified against a public source. The figure is provisional and will rise as further disclosures are verified.

Which ransomware group was most active in September 2026?

Qilin and The Gentlemen tied on four confirmed victims each. Dire Wolf, Rhysida and INC had three each. Of the 55 incidents, 38 carry an attributed group.

Which industry was hit most in September 2026?

Government, with 14 confirmed incidents, ahead of healthcare on 11 and education on eight.

Is the September 2026 figure final?

No. A month’s confirmed count typically keeps rising for three to four months after it ends, as statements, regulator notifications and local reporting arrive. Treat 55 as a floor.

Sources and further reading

  • Ransomware attacks, September 2026, the live incident list with sources
  • Ransomware attacks, 2026, the year to date
  • Ransomware statistics
  • Ransomware payment rate
  • Confirmed ransomware attacks hub

The Ransomnews Monthly

One email a month. Original leak-site data, victim census updates, and the findings that did not make the articles. No spam, unsubscribe any time.

Double opt-in. We store your email, signup time, and IP for consent records (GDPR Art. 7). See our privacy policy.

Share. Facebook Twitter Pinterest LinkedIn Tumblr Telegram Email Copy Link
Previous ArticleNovo Nordisk breach lawsuits: what the complaints get wrong
Ransomnews Research Team

The Ransomnews Research Team is the collective byline used for collaborative pieces, editorial briefings, and articles drawing on contributions from multiple researchers. Coverage spans ransomware operations, breach economics, threat actor profiling, OSINT methodology, and emerging risks across security, privacy, and AI.

Related Posts

Is it illegal to pay a ransomware ransom in 2026?

September 7, 2026

Confirmed ransomware attacks, August 2026: 51 verified so far, Qilin leads

September 7, 2026

ESXi ransomware in 2026: one host, the whole datacenter

June 24, 2026

Comments are closed.

The Ransomnews Monthly

What leaked, what held up

One email a month: the datasets we verified, and the ones that fell apart under scrutiny.

Double opt-in. We store your email, signup time, and IP for consent records (GDPR Art. 7). See our privacy policy.

Free tool

How does your own site score?

Forty passive checks on TLS, security headers, email spoofing and privacy. A grade out of 100 in about fifteen seconds.

No signup. Nothing installed. We only request what your site already serves publicly.

Free tool

Were you in a leak?

Check whether an email address has surfaced in infostealer logs. No signup, no data stored.

Run StealerCheck

Live data

Ransomtracker

Victims as they are posted to ransomware leak sites, tracked continuously and checked against the claims.

Open the tracker

9,711 confirmed attacks tracked

Facebook X (Twitter) LinkedIn
© 2026 Ransomnews.com

Type above and press Enter to search. Press Esc to cancel.

Cookies on Ransomnews

We use strictly-necessary cookies to run the site and may use first-party analytics to understand which articles are read. Some pages contain affiliate links; when you click one, the affiliate network sets cookies on the merchant's domain to attribute the referral. See the Cookie Policy and Affiliate Disclosure for detail.

RANSOMNEWS.COM

Tracking the criminal infrastructure of the internet.

Independent coverage of ransomware, breach economics, threat actors, privacy, AI security, and the open-source investigation toolkit.

Topics

  • News
  • Security
  • Privacy
  • Cybercrime
  • AI
  • OSINT
  • Threat Groups
  • Stealer Logs
  • Ransomtracker
  • Stealercheck
  • FortiBleed Checker
  • Site Check

Site

  • About Us
  • Editorial Team
  • Contact
  • Tip Line
  • Editorial

Legal

  • Privacy Policy
  • Terms of Service
  • Cookie Policy
  • Funding & Independence
  • RSS Feed
© 2026 Ransomnews.com · Tracking the criminal infrastructure of the internet.