Brian Sims
Editor

“Ransomware volumes rise to 2026 high” reports NCC Group

RANSOMWARE LEVELS peaked in July, reaching the highest volume since the start of the year and representing a 22% uptick on June. The rise in volume is reported in the NCC Group’s monthly Threat Intelligence Report for July, which recorded a year-to-date high of 894 cases of ransomware activity for the month. This is only 19% lower than the current monthly record, which is 1,099 attacks reported back in February 2025.

In line with recent trends, North America and Europe have continued to be the most targeted regions for ransomware activity. Almost three-quarters (70%, in fact) of ransomware attacks occurred across the two continents: 41% in North America and 29% in Europe.

The new ransomware group CRPxO has claimed responsibility for 36 victims in July. However, the NCC Group warns that its credibility is not yet guaranteed, with inconsistent evidence to suggest that it’s actually behind the attacks. This is a common tactic of new ransomware groups: they make false claims about their activity levels in order to create an exaggerated sense of threat.

In July, prominent threat group The Gentlemen continued to assert its dominance across the global landscape, assuming responsible for 15% of all reported attack episodes.

AI advancements accelerate attacks

At least in part, the rise of ransomware activity in July was driven by advancements in AI. JADEPUFFER, the first known fully autonomous end-to-end Artificial Intelligence (AI)-driven agent, which demonstrated its ability to infiltrate systems and conduct attacks without human instruction.

As competition in the AI space continues to intensify, similar future attacks could become more common, raising concerns that increases in attack volume in times ahead may be driven less by new tactics and more by the proliferation of autonomous agents.

AI agents capable of operating without human intervention can adapt and execute an attack from initial compromise all the way through to extortion. So far, these attacks appear to have been motivated less by financial gain and more by demonstrating what the technology can achieve.

Now that the concept has been proven, though, further development could enable cyber criminals to conduct attacks with greater speed and scale.

Speed and scale

Matt Hull, vice-president of cyber intelligence and response at the NCC Group explained: “AI is changing the speed and scale of cyber attacks. It’s allowing attackers to automate more of what they do, operate at greater scale and create increasingly convincing phishing, social engineering and other malicious content. That can make threats far harder for both organisations and individuals to identify.”

Hull continued: “For organisations, the response doesn’t need to be complicated. Making sure the fundamentals are right remains incredibly important: strong identity and access control, good vulnerability management, visibility across your environment and the ability to detect and respond quickly when something goes wrong are all vital areas for consideration.”

Further, Hull noted: “There’s also a human element. As AI-generated content becomes more convincing, employees need to understand what threats look like, know when something doesn’t feel right and have a simple way to report it.”

In conclusion, Hull informed Security Matters: “AI is equally valuable for defenders, helping security teams to process information faster and identify potentially malicious activity. The challenge is making sure we use that technology effectively, while in parallel maintaining the human judgement needed to understand what represents a genuine threat.”

*Further information is available online at www.nccgroup/com/uk

Company Info

Western Business Media Limited

Dorset House
64 High Street
East Grinstead
RH19 3DE
UNITED KINGDOM

Login / Sign up