Summary
- Europe recorded 61% annual growth in measured attacks.
- Globally the research found 2,803 weekly attacks per organisation.
- The figures measure vendor-observed attack activity rather than confirmed successful compromises.
Europe experienced the strongest annual growth in observed cyberattack activity during September 2026, according to new telemetry from Check Point Research, as the company reported rising malicious traffic across multiple sectors.
The research recorded an average of 2,803 attacks per organisation each week worldwide, representing a 48% rise against September 2025 and a 16% increase from August. Europe’s annual growth reached 61%, compared with 50% in North America, although other regions recorded higher absolute weekly volumes.
The regional comparison requires care because the figures are based on Check Point’s observed and classified activity rather than an independently enumerated record of successful breaches. An attempted attack that is blocked or fails is different from an incident that compromises a system or exposes information.
Educational organisations experienced the highest global volume in the vendor’s dataset, averaging 6,656 weekly attacks per organisation, up 59% from a year earlier. Telecommunications averaged 3,483 and government 3,443, placing sectors with extensive digital services and broad user bases near the top of the rankings.
The start of the academic year may have contributed to changing traffic and user activity in education, but the coincidence does not establish a causal explanation for every attempted attack identified by the vendor.
The September results also describe changing phishing pressure. Check Point classified one in 91 emails as phishing, compared with one in 112 in August. Links appeared in 81% of phishing emails and attachments in 11%, indicating that many campaigns relied on directing recipients to external content rather than delivering a malicious file directly.
Separately, Check Point reported that one in 39 enterprise generative AI prompts posed a high risk of sensitive information exposure. The company observed high-risk prompts at 89% of organisations regularly using the tools. That metric refers to the presence of potentially sensitive content in monitored prompts, not verified theft by an external attacker.
Ransomware figures also rose, with 824 reported victims or attacks in September, a 53% annual increase. Europe accounted for a quarter of reported incidents in that dataset, while North America remained the largest regional category.
The different measurement systems should not be collapsed into a single count. Network attack detections, phishing classifications, AI prompt analysis and ransomware claims each represent a different kind of observation, with different possible gaps and biases.
Check Point reports that phishing accounted for about one in 91 emails during September, compared with one in 112 in August. Links appeared in 81% of the phishing emails identified, while attachments accounted for 11%. Those figures describe how malicious messages were classified in the vendor’s monitored email traffic; they do not demonstrate that recipients followed links or executed files.
Business services represented 31.3% of reported ransomware victims in the September dataset, followed by consumer goods and services at 15.2% and industrial manufacturing at 11.0%. Because a service provider may handle customer data or privileged access for several organisations, a single confirmed supplier intrusion can require investigations by parties that were not directly attacked.
Check Point recorded a high-risk sensitive-data indicator in one of every 39 enterprise generative AI prompts. Its reported organisational percentages describe whether a category appeared anywhere within an organisation’s observed prompts, rather than the share of prompts containing that category. Financial, regulatory, employee and identity information were represented in the sample, but the figures alone cannot establish that an external party received confidential material.
The regional growth comparisons were made against September 2025, while the month-on-month global comparison was against August 2026. Both rates can rise even when the absolute number of incidents varies widely among regions. The report offers no independent verification of a direct causal relationship between adoption of generative AI and the number of cyberattack attempts recorded.
Ransomware figures in the same release use reported victims and group publications, which can differ from independently confirmed compromises. Treating those counts separately from network attack attempts avoids combining incomparable measures into a single apparent incident total.





