Summary
- Organisations recorded an average of 2,422 weekly attacks in Check Point's August telemetry, up 22% year on year.
- Europe registered the fastest regional growth at 28%, while Check Point counted 1,042 organisations publicly listed by double-extortion ransomware groups.
- GenAI use continued to rise, with one in 43 enterprise prompts classified by Check Point as carrying a high data-exposure risk.
Europe recorded the fastest year-on-year growth in cyber attacks during August as ransomware disclosures, phishing, and enterprise use of generative AI all increased, according to new threat telemetry from Check Point.
Check Point Research said organisations worldwide experienced an average of 2,422 attacks per week during the month, up 4% from July and 22% from August 2025. Europe recorded a 28% year-on-year rise, the fastest regional growth reported in the dataset.
Education remained the most heavily targeted sector, averaging 5,354 weekly attacks per organisation. Government followed at 3,067, while hospitality, travel, and recreation reached 3,056 — a 56% annual increase that Check Point linked to seasonal activity and the breadth of digital services used across the sector.
The figures are derived from Check Point’s own threat-intelligence telemetry and therefore describe activity visible to its systems rather than every attack occurring globally. They are most useful as directional indicators of changes across its observed customer and threat data.
Ransomware also accelerated. Check Point counted 1,042 organisations publicly listed by double-extortion ransomware groups during August, nearly twice the figure recorded a year earlier and 8% above July.
That number should not be read as a complete census of ransomware incidents. Victim counts derived from extortion sites omit attacks that are not publicly disclosed by criminals and may include cases where an organisation’s status or the attacker’s claim remains uncertain.
Business services accounted for 36% of the ransomware victims in Check Point’s dataset, followed by industrial manufacturing at 13% and consumer goods and services at 12%. The concentration around business-service providers reinforces the potential for attacks to propagate through commercial dependencies rather than remaining isolated to a single organisation.
The August data also captures a different category of exposure created by generative AI use. Check Point said the average enterprise user generated 106 GenAI prompts during the month, up from 95 in July and around 78 in June.
One in every 43 prompts was classified as presenting a high data-exposure risk. That rate was lower than in several preceding months, but 86% of organisations using generative AI regularly still recorded some high-risk prompt activity.
The combination is more revealing than either number on its own. A falling proportion of risky prompts can coexist with growing absolute exposure if overall usage is increasing rapidly. Organisations in the dataset were using an average of seven AI tools, expanding the number of services through which employees may send information outside conventional enterprise systems.
Healthcare and medical organisations recorded the highest high-risk prompt rate at 4%, followed by software at 3.6% and business services at 3.5%. Those sectors handle combinations of personal, proprietary, and regulated information that can make accidental disclosure particularly consequential.
Email remains a more established route into enterprise environments. Check Point classified one in every 112 emails as phishing in August, compared with one in 128 in July. Links appeared in 72% of phishing emails, while 14% used attachments.
The August picture is therefore not defined by a single new attack technique. Established routes such as phishing and ransomware are operating alongside a fast-growing layer of AI-related information handling. Europe’s 28% annual increase adds regional urgency, but the more structural issue is the growing number of channels through which enterprise data and access can be exposed.





