Decoding the world of cybersecurity

Ransomware claims rise as confirmations lag

Comparitech recorded 799 ransomware incidents and criminal claims in July, but only 51 had been confirmed by affected organisations when its analysis was published.

Ransomware claims rise as confirmations lag
Summary
  • July’s dataset contained 51 confirmed incidents and 748 unconfirmed ransomware-group claims.
  • Germany recorded 40 entries, the UK 25, and France 23, behind the United States, Canada, and India.
  • The large evidential gap limits the conclusions that can be drawn from the overall monthly total.

Ransomware researchers recorded 799 incidents and criminal leak-site claims during July, although fewer than one in 15 had been publicly confirmed by an affected organisation.

The monthly analysis from Comparitech identified 51 confirmed attacks and 748 unconfirmed claims. Its total increased by 19% from 668 entries in June and was the second-highest monthly figure recorded during 2026, behind March’s 805.

Businesses accounted for 31 of the confirmed incidents, while ten involved government entities, seven affected educational organisations, and three involved healthcare providers. Among the unconfirmed claims, 657 concerned businesses, 50 healthcare organisations, 24 government bodies, and 16 educational institutions. One entry involved an unidentified entity.

The United States accounted for 322 confirmed and unconfirmed entries, followed by Germany with 40, Canada with 36, India with 30, the UK with 25, and France with 23.

The Gentlemen was the most active named group in the dataset, with 135 claims, followed by Qilin with 125. Nine of The Gentlemen’s listed attacks and six of Qilin’s had been confirmed.

Rebecca Moody, head of data research at Comparitech, said: “If we needed a reminder of how dominant a threat ransomware attacks remain, July’s figures provide us with just that.”

The overall figure requires substantial qualification. Comparitech classes an attack as confirmed when an organisation publicly discloses ransomware or acknowledges a cyberattack corresponding with a criminal group’s claim. A leak-site listing without acknowledgement remains unconfirmed.

Those claims can represent genuine compromises that have not yet been disclosed, but they can also be false, duplicated, delayed, or attached to the wrong month. A group may publish a victim weeks after gaining access, while an organisation may use broader terms such as “cyber incident” during an active investigation.

Comparitech consequently revises its records as new information emerges. An entry initially placed among July’s unconfirmed claims could later be assigned to an earlier month if the underlying incident occurred before the group published it.

The dataset nevertheless provides a view of extortion activity and criminal workload. The Gentlemen and Qilin together accounted for almost one-third of July’s entries, while the number attributed to Qilin increased substantially from June.

Sector changes were uneven. Comparitech recorded increases of 71% among finance companies, 62% among technology businesses, 46% in healthcare-related businesses, and 44% in education. Entries involving utilities, legal organisations, and government bodies declined.

The confirmed cases also produced markedly different consequences. Some disrupted production or public services, others involved stolen files without an outage, and Romania’s land-registry incident resulted in destructive data loss. Treating every listing as an equivalent event can obscure those distinctions.

Germany, the UK, and France were prominent in the country totals, but public disclosure rules and organisational reporting practices vary. A larger number can reflect the visibility of incidents and leak-site claims as well as the underlying level of criminal activity.

July’s 799 entries point to sustained ransomware and extortion pressure. The firmer finding is narrower: 51 organisations had publicly acknowledged an attack or an incident matching a ransomware claim when Comparitech published its analysis.

×