SecurityBrief UK - Technology news for CISOs & cybersecurity decision-makers
United Kingdom
Ransomware attacks hit 894 as AI boosts cyber crime

Ransomware attacks hit 894 as AI boosts cyber crime

Thu, 27th Aug 2026 (Today)
Joseph Gabriel Lagonsin
JOSEPH GABRIEL LAGONSIN News Editor

Ransomware activity rose to 894 cases in July, up 22% from June, according to NCC Group.

The cyber security company's monthly threat intelligence report said July was the highest level recorded so far this year. The total was still 19% below the monthly record of 1,099 attacks in February 2025.

The figures showed a concentrated pattern among a handful of threat groups. The Gentlemen was the most active in July, accounting for 15% of all attacks after rising to 138 incidents from 88 in June. Qilin ranked second with 127 attacks, up from 79 a month earlier, while Deadlock placed third with 9% of incidents.

A newer group, CRPxO, claimed responsibility for 36 victims in July, or about 4% of the total. NCC Group said those claims had not been confirmed and cited inconsistent evidence over whether the group was behind the attacks.

Regional Focus

North America and Europe remained the main targets for ransomware operators, together accounting for 70% of attacks in July. North America represented 41% and Europe 29%.

Industrials was the most affected sector, accounting for 28% of attacks during the month. It led other industries as ransomware groups continued to focus on organisations with complex operations and broad supplier networks.

The report also linked the rise in activity in part to developments in artificial intelligence. It cited JADEPUFFER as the first known fully autonomous end-to-end AI-driven agent shown to infiltrate systems and carry out attacks without human instruction.

Such tools could shift the economics of cyber crime by allowing attackers to automate more of the process, from initial compromise to extortion. Early examples appeared to be driven less by immediate financial gain than by a desire to demonstrate what autonomous systems can do.

The assessment comes as security researchers and corporate defenders track a broader move towards automation in cyber attacks. For companies, the concern is not only the volume of incidents, but also the prospect that autonomous agents could help less sophisticated criminals launch more effective campaigns at greater scale.

The report also examined Operational Relay Box networks and their growing role in China-linked cyber operations. These networks route activity through compromised devices and infrastructure, making malicious traffic harder to trace and attribution more difficult.

Matt Hull, Vice President of Cyber Intelligence and Response at NCC Group, said organisations should keep their focus on the basics as threats become more automated.

"AI is changing the speed and scale of cyber attacks. It's allowing attackers to automate more of what they do, operate at greater scale, and create increasingly convincing phishing, social engineering, and other malicious content. That can make threats harder for both organisations and individuals to identify.

"For organisations, the response doesn't need to be complicated. Getting the fundamentals right remains incredibly important: strong identity and access controls, good vulnerability management, visibility across your environment, and the ability to detect and respond quickly when something goes wrong.

"There's also a human element. As AI-generated content becomes more convincing, employees need to understand what threats look like, know when something doesn't feel right, and have a simple way to report it.

"AI is equally valuable for defenders, helping security teams process information faster and identify potentially malicious activity. The challenge is making sure we use that technology effectively while maintaining the human judgement needed to understand what represents a genuine threat."