Summary
- Comparitech recorded 997 August incidents, of which 77 had been confirmed by affected organisations.
- Germany and Italy each recorded 48 cases and the UK 36, with the UK total rising 44% from July.
- Sector increases included healthcare, utilities, legal services, technology, finance, retail, and manufacturing, but unconfirmed leak-site claims remain distinct from verified attacks.
Ransomware activity reached the highest monthly level in Comparitech’s tracking dataset during August, with 997 confirmed and claimed incidents and substantial volumes recorded across Germany, Italy, and the UK.
Comparitech said the August total was 23% higher than July’s 809 cases and exceeded its previous monthly record of 988 incidents in February 2025. The figures equate to roughly 32 recorded incidents a day.
The headline number does not represent 997 independently verified breaches. Seventy-seven of the August cases had been confirmed by the affected organisations, while 920 remained unconfirmed ransomware-group claims in the dataset.
Comparitech defines an attack as confirmed where the targeted organisation publicly discloses ransomware or acknowledges a cyberattack that coincides with a ransomware group’s claim. A leak-site claim without corresponding acknowledgement remains unconfirmed.
That methodology is essential to interpreting the record. Ransomware groups can exaggerate attacks, name organisations incorrectly, publish old data, or make claims that victims never substantiate. Comparitech also notes that incidents can be reclassified later as disclosures emerge.
The geographical figures nevertheless show substantial European exposure. Germany and Italy each recorded 48 cases during August, behind only the United States. The UK recorded 36. Comparitech says Germany’s figure rose 14% from July, while the UK increased by 44% and Italy by 200%.
Sector movements were similarly broad. Healthcare incidents increased 30%, while utility attacks doubled from five in July to ten in August. Legal services rose 52%, technology 42%, and finance 40%. Retail and manufacturing also recorded increases.
Those percentages include confirmed and unconfirmed cases, so they indicate the volume of observed and claimed activity rather than a definitive incidence rate across each industry.
The utilities figure is notable because infrastructure operators face consequences beyond data confidentiality. An attack can leave power or water production intact while disrupting customer services, billing, communications, procurement, and administrative systems.
The current incident affecting Stadtwerke Landsberg in Bavaria illustrates that separation. Central IT was encrypted while the utility reported continued operation of electricity, water, district heating, fibre, and other principal services.
Healthcare creates a different concentration of risk. Hospitals and care providers combine sensitive information, complex supplier estates, high availability requirements, and limited tolerance for prolonged outages. A ransomware incident can therefore create simultaneous operational, privacy, and safety pressures.
The dataset also reflects how far ransomware has moved beyond encryption as a defining characteristic. Some operators continue to encrypt systems, while others rely heavily on data theft and extortion. Initial access can involve vulnerabilities, stolen sessions, compromised suppliers, phishing, remote-management tools, or purchased credentials.
Operational impact is consequently becoming a more useful measure than malware branding. Recovery costs, service disruption, data exposure, regulatory notification, contractual consequences, supplier effects, and the time needed to restore trusted systems can remain significant whether or not an attacker encrypts every endpoint.
European organisations increasingly handle those incidents within overlapping regulatory frameworks. NIS2, DORA, data-protection law, sector-specific requirements, and other national obligations can create different thresholds and reporting clocks from the same underlying event.
Comparitech’s August total should therefore be read as 997 recorded confirmed and claimed cases, not 997 proven breaches. Even with that qualification, the distribution across Germany, Italy, the UK, healthcare, utilities, finance, and technology indicates that extortion remains a sustained operational problem across sectors expected to continue functioning while incidents are investigated and systems are rebuilt.




