Recorded ransomware activity rose 22% month over month to 894 victim organizations in July, the highest monthly total reported in 2026. North America and Europe accounted for 70% of incidents, with the United States representing 41%; the industrial sector was the most targeted, accounting for 28% of reported attacks. Notable reported victims included EY, Fairlife, and Analog Devices, although some public claims have not been independently verified.
The Gentlemen was the most active named operation, responsible for 15% of recorded attacks, while Qilin was also among the leading groups. Newly observed group CRPxO claimed 36 victims but had not provided credible evidence supporting those claims, underscoring the limitations of leak-site metrics. Researchers also warned that AI-enabled capabilities, including the reportedly autonomous JADEPUFFER agent, could allow ransomware operators to accelerate and scale attacks.

TTPs, infrastructure, and targeting history in one profile.
6 events from the most recent confirmed update back to the earliest known activity.
Ernst & Young suffered a data leak involving client information and tax records in July 2026. ShinyHunters claimed responsibility for the attack.
The newly observed ransomware-as-a-service group CRPxO appeared in July 2026 and claimed compromises of 36 organizations, including Johnson & Johnson and Turkish Airlines. NCC Group found the supporting evidence inconsistent and assessed the group’s credibility as low to moderate.
NCC Group recorded 894 ransomware cases worldwide in July 2026, a 22% increase from June and the highest monthly volume of 2026 to that point. Industrials accounted for 28% of incidents, while North America and Europe represented 41% and 29% of reported activity, respectively.
NCC Group described JADEPUFFER as the first known fully autonomous, end-to-end AI-driven agent capable of infiltrating systems and carrying out attacks without human instruction. The assessment warned that such agents could accelerate intrusions from compromise through extortion.
ExfilSquad claimed it stole 570,000 records from Analog Devices, although the claim had not been verified.
Fairlife, a Coca-Cola subsidiary, reportedly suffered a ransomware attack attributed to Anubis. The group claimed it had stolen more than 1 TB of data.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.