Site icon Back End News

Cyble: Ransomware attacks reach 2026 high in August

Cybersecurity - Data

The Philippines had 10 organizations named on ransomware gangs’ leak sites in August, as the global number of claimed victims reached its highest monthly level so far in 2026, according to Cyble Research and Intelligence Labs (CRIL).

The country tied with China for fifth place in Asia-Pacific. Five of the Philippine claims were attributed to Qilin, the world’s most active ransomware gang that month. The figures count claims posted by gangs; they do not establish that every claim was verified.

Worldwide, gangs publicly named 1,034 organizations in August, up 25% from July. July’s total had already risen 60% after ransomware activity declined from March through June, according to CRIL, the research arm of global AI-native cybersecurity company Cyble.

For businesses, the increase means ransomware planning based on quieter months earlier this year may underestimate the current volume of threats. The attacks can halt operations, expose customer information, and put pressure on companies to pay to keep stolen data private.

“The quieter first half of the year was never a sign that ransomware was fading. Gangs were regrouping, and August shows what they regrouped into,” said Daksh Nakra, senior manager of Research and Intelligence at Cyble. 

Manufacturing had the most claimed victims worldwide at 151, followed by professional services at 147, IT and IT-enabled services at 126, and healthcare at 98. Disruption can be costly in these sectors, while access to client or patient data gives attackers another way to demand payment.

Asia-Pacific accounted for 143 claimed victims, or about 14% of the global total. The Americas had 603, while Europe had 270. Regional patterns also differed from the global picture: The Gentlemen claimed 20 victims in Asia-Pacific, compared with Qilin’s 16. Two other gangs, Krybit and orova, claimed 13 and 12, respectively.

Globally, Qilin claimed 145 victims and The Gentlemen claimed 110. CRIL linked the surge to gangs recruiting more affiliates and exploiting systems accessible from the internet. It also reported cases of extortion based on stolen data alone, without locking a company’s files.

“For Indian organizations, the lesson is to stop planning against the names in the headlines,” Nakra said. “The groups most active in this region often have little global profile, and the defences that hold against them are the fundamentals: knowing what is exposed to the internet, who can reach it, and whether you can recover without paying.”

CRIL advised organizations to prioritize fixes for exposed systems, use phishing-resistant multifactor authentication for third parties, limit access between networks, and test backups kept offline.

Exit mobile version