Decoding the world of cybersecurity

·

Germany ranks second in global ransomware claims as quarterly reports reach 2,627

Comparitech recorded 2,627 ransomware attacks and claims in the third quarter, with Germany accounting for 121, although most incidents were not independently confirmed.

Germany ranks second in global ransomware claims as quarterly reports reach 2,627
Summary
  • Only 247 of the 2,627 recorded Q3 attacks were independently confirmed.
  • Germany had 121 reports, behind the United States at 1,066.
  • The dataset must distinguish criminal-group claims from verified victim incidents.

Germany accounted for 121 ransomware attacks and claims in the third quarter of 2026, ranking second behind the United States in research from Comparitech that recorded 2,627 incidents and allegations worldwide.

The total was 29% higher than the second quarter and 61% above the corresponding period in 2025, according to the organisation’s tracking. However, only 247 entries had been confirmed by the affected entity, while 2,380 remained unconfirmed reports, generally associated with criminal group claims.

That evidential split is fundamental to the findings. Ransomware groups may exaggerate victim lists, reuse older data or name organisations before public verification. A listing on a leak site is a relevant investigative lead, but it is not definitive evidence that a network was compromised during the stated period.

The United States dominated the national figures with 1,066 recorded attacks or claims, while Germany’s 121 placed it ahead of Canada, which accounted for 103. Those counts describe the geography assigned within Comparitech’s dataset and do not automatically represent the complete prevalence of ransomware in each country.

Of the confirmed attacks, 138 affected businesses, 53 involved government organisations, 36 affected healthcare and 20 involved education. The remaining unconfirmed dataset was also concentrated heavily in businesses, where an alleged attack may have consequences for customers and suppliers if access or data theft is later verified.

Comparitech identified 1,611,971 records compromised across confirmed attacks. That count is narrower than the number of people potentially affected by every claim in the wider dataset, which cannot be established solely from criminal publication.

The researchers reported a median ransom demand of $150,000 and an average of $602,400 where demand figures were available. Both describe reported demands, not necessarily payments, while substantial variations between incidents limit the explanatory value of the average.

Qilin led the group-claim rankings with 357 alleged attacks, followed by The Gentlemen with 342. The same groups accounted for 27 and 26 confirmed incidents respectively, again demonstrating why claim totals and confirmed incidents require separate reporting.

In some cases, criminals may attempt further extortion against organisations or individuals connected to an original victim, increasing possible downstream exposure. Comparitech describes such activity but the presence of a name on a criminal site does not establish that the claimed data remains authentic or current.

Victim categories likewise require care. A supplier serving many other companies may appear in the business-services sector even where its compromise has implications for customers in banking, manufacturing or public administration. The knock-on exposure cannot be calculated merely from the original victim’s industry classification.

Comparitech counted 138 confirmed incidents involving businesses, 53 involving government bodies, 36 in healthcare and 20 in education. Those figures are a subset of 247 independently confirmed attacks and must not be added to the unverified claims as though each had equal evidential support.

North America accounted for the largest geographic share of ransomware reporting, but the dataset recorded Germany as the second-highest individual country with 121 attacks or claims. The figures reflect publicly available disclosures and extortion listings, and therefore cannot be treated as a complete measure of successful intrusions across national networks.

Alongside encryption and data theft, the researchers documented instances in which attackers sought payment from other organisations or individuals connected with a breached supplier. Public accusations of data possession are still claims until independently supported, and a payment does not provide independent proof that attackers have destroyed copies of stolen information.

Comparitech’s account also documents the increasing use of multiple extortion pressures. Some attackers threaten disclosure of information or contact customers and affected people after the initial compromise. An allegation posted by a criminal group is not proof that the threatened information was stolen, and any claimed ransom transaction requires independent corroboration.

×