Ransomware hits 2026 high in August as Qilin leads
NCC Group recorded 1,073 ransomware attacks in August, up 12%, with industrial firms hit hardest and Qilin the most active group.
By Mira Castell · Published · Updated · 4 min read

Ransomware attacks reached their highest level of 2026 in August, according to NCC Group data reported by Industrial Cyber.
Key figures
| Measure | August 2026 |
|---|---|
| Total attacks | 1,073 (up 12% from 960 in July) |
| Most targeted sector | Industrials, 329 attacks (31%) |
| Next sectors | Consumer discretionary (18%), healthcare (12%) |
| Most targeted region | North America, 473 attacks (44%) |
| Most active group | Qilin, 164 attacks (15%) |
Who is behind it
Qilin overtook The Gentlemen as the most active group. NCC's incident responders also studied an emerging group called Aurora, which broke in by exploiting VPNs and harvesting credentials, targeting manufacturing, legal, research and transport organizations.
Why industrial firms are targeted
Manufacturers and industrial companies cannot afford downtime. When production lines stop, losses grow by the hour, which puts pressure on them to pay quickly. Many also run older systems that are hard to patch.
How to reduce your risk
- Patch VPNs and remote-access gateways first — they remain a top entry point.
- Require phishing-resistant multi-factor authentication for all remote access.
- Keep offline, tested backups and practise restoring them.
- Watch for large outbound data transfers, since most gangs now steal data before encrypting.


