SecurityBrief UK - Technology news for CISOs & cybersecurity decision-makers
United Kingdom
Check Point warns of rising attacks & AI data leak risk

Check Point warns of rising attacks & AI data leak risk

Wed, 9th Sep 2026 (Today)
Joseph Gabriel Lagonsin
JOSEPH GABRIEL LAGONSIN News Editor

Check Point reported a rise in cyberattacks, phishing and ransomware in its August 2026 threat data, while warning that growing use of generative AI is increasing organisations' risk of data leakage.

Organisations faced an average of 2,422 weekly cyberattacks in August, up 4% from July and 22% from a year earlier.

The figures suggest sustained pressure rather than a one-off surge. Since May, the average number of weekly attacks per organisation has risen from 2,055 to 2,422, according to the company's monthly assessment of cyber activity.

Attack trends

Education remained the most targeted sector, with 5,354 weekly attacks per organisation. Government followed with 3,067, while Hospitality, Travel, and Recreation moved into third place with 3,056.

One of the more notable shifts in the data was the rise in attacks on travel-related businesses. The sector recorded a 56% year-on-year increase, overtaking telecommunications and suggesting attackers are focusing on industries under heavy operational pressure.

Regional patterns also shifted. Latin America recorded the highest average attack volume at 3,577 weekly attacks per organisation, up 25% from a year earlier.

Africa ranked second at 3,335, followed closely by Asia-Pacific at 3,325. Europe posted the fastest annual increase, rising 28% to 2,155 attacks per organisation, while North America rose 18% to 1,744.

AI exposure

Alongside the increase in conventional attack activity, the report highlighted a growing governance challenge tied to workplace use of generative AI. Average usage continued to rise, with users generating 106 prompts in August, up from 95 in July and about 78 in June.

High-risk prompts accounted for 1 in every 43 entries, or 2.3% of prompts, the lowest rate in several months. Even so, 86% of organisations that regularly use generative AI were affected by high-risk prompt activity.

The pattern suggests safer routine use is expanding, but sensitive information is still being entered into AI systems at scale. Organisations used seven different AI tools on average, increasing the difficulty of oversight and control, Check Point said.

Healthcare & Medical recorded the highest rate of high-risk prompt exposure at 4%, or 1 in every 25 prompts. Software followed at 3.6%, while Business Services stood at 3.5%, or about 1 in every 28 prompts.

By region, Latin America again showed the highest rate of high-risk AI prompts at 3.5%, or 1 in every 29 prompts. North America followed at 1 in 40 prompts, Asia-Pacific at 1 in 51 and Europe at 1 in 56.

The type of data being exposed also shifted. Network and IT infrastructure information was the most common category, appearing in 67% of organisations where sensitive data was found in AI prompts.

Financial data appeared in 65% of affected organisations, legal and regulatory data in 64%, employee and HR information in 59%, and personally identifiable information in 57%.

Phishing activity

Email phishing also increased during the month. Check Point reported that 1 in every 112 emails, or 0.89%, was classified as phishing, compared with 1 in 128 in July.

Most phishing emails relied on links rather than attachments. Among malicious messages, 72% contained links and 14% included attachments, while some campaigns used social engineering alone to push recipients to make contact or follow instructions outside the email itself.

North America recorded the highest phishing rate, with 1 in every 107 emails classified as malicious. By sector, Associations and Nonprofits had the highest rate at 1.87%, or 1 in every 54 emails, about twice the global average.

Construction and Engineering followed at 1.74%, while Real Estate, Rental, and Leasing recorded a rate of 1.13%.

Ransomware rise

Ransomware activity continued to climb. A total of 1,042 ransomware attacks were reported in August, up 8% from July and nearly double the level recorded a year earlier.

Business Services was the most targeted industry, accounting for 36% of reported ransomware attacks. Industrial Manufacturing followed at 13%, with Consumer Goods & Services at 12%.

Financial Services accounted for 8% of reported victims, while Healthcare & Medical represented 7%. Transportation & Logistics and Information Technology each made up 4.1%, Government 3.7%, Automotive 3.3% and Education 2.3%.

North America remained the most affected region, accounting for 49% of reported ransomware incidents. Europe followed with 27% and Asia-Pacific with 16%.

At the country level, the United States accounted for 45% of reported ransomware attacks. Germany and Italy each represented close to 5% of victims, while Canada, the United Kingdom and France were also among the most affected countries.

Active groups

Qilin was the most prevalent ransomware group in August, responsible for 15% of published attacks. The Gentlemen followed with 10%.

Orova entered the top three for the first time with 4% of published attacks, showing how quickly newer groups can establish a visible presence in the ransomware market.

The ransomware figures were based on disclosures posted to extortion sites run by double-extortion groups. That source does not capture every incident, but it remains widely used to track trends in the market.

The August figures point to mounting pressure across several channels at once, from direct cyberattacks and phishing to ransomware and data exposure through workplace AI use.