Key Takeaways

  • NCC Group recorded 894 ransomware cases in July, up 22% from June and the highest monthly total of 2026 so far
  • North American and European organisations accounted for 41% and 26% of recorded attacks, respectively
  • AI is helping criminals scale reconnaissance and social engineering, but NCC Group says established security controls remain central to defence

NCC Group recorded 894 ransomware cases in July, marking a 22% increase from June and the highest monthly volume observed so far in 2026. The figures suggest that ransomware operations are becoming faster and more scalable as criminals incorporate artificial intelligence into established attack methods.

North American organisations represented 41% of recorded attacks, while European targets accounted for another 26% (source). Together, those regions made up more than two-thirds of NCC Group’s July cases, underlining the sustained pressure on businesses operating in large, digitally connected markets.

The emergence of autonomous AI agents illustrates how that pressure is changing. Rather than simply helping criminals write more convincing emails, agentic systems can support multiple stages of an operation, including reconnaissance, data identification, and the preparation of targeted malicious content.

Ransomware has become an industrial operation. Criminal groups divide work among initial-access brokers, malware developers, infrastructure operators, and negotiators. AI reduces the time and expertise needed for several of these functions, allowing smaller groups to behave more like mature cybercrime businesses.

“AI is changing the speed and scale of cyber attacks. It’s allowing attackers to automate more of what they do, operate at greater scale and create increasingly convincing phishing, social engineering and other malicious content,” said the vice-president of cyber intelligence and response at NCC Group.

Other threat intelligence supports this assessment. IBM X-Force reported a 49% year-over-year increase in active ransomware and extortion groups during 2025. Vulnerability exploitation was the leading initial cause of attacks, accounting for 40% of incidents, as AI helped accelerate the discovery and targeting of weaknesses.

Meanwhile, BlackFog estimated that roughly 86% of ransomware attacks go undisclosed. Its 2025 State of Ransomware report also highlighted the first large-scale campaign in which an AI model autonomously performed reconnaissance and data-identification tasks. With most attacks remaining outside public reporting, the visible numbers are only a fraction of total incidents.

The victim pool is expanding rapidly. Research covered in the Fortinet 2026 Global Threat Landscape put the number of confirmed ransomware victims at 7,831 in 2025, a 389% year-on-year increase. Manufacturing was the most heavily affected sector, reflecting attackers’ preference for environments where downtime can quickly create financial and operational pressure.

Despite the rise of automated tools, AI does not remove the attacker’s need for an entry point. Compromised credentials, exposed services, unpatched vulnerabilities, and weak access controls still provide much of the opening. This makes conventional security fundamentals essential to preventing breaches.

Organisations should focus on strong identity and access controls, effective vulnerability management, visibility across their environments, and the ability to detect and respond quickly. These controls limit an intruder’s initial access and make lateral movement more difficult. Segmented networks, protected backups, and tested recovery procedures also reduce the leverage behind an extortion demand.

When an email looks authentic, uses correct internal language, and appears to come from a familiar executive, employee awareness remains a critical defense layer, although annual training alone struggles against rapidly changing tactics. Staff need a straightforward reporting route, while security teams need processes that examine suspicious messages without penalizing the employee who raised the alarm.

AI provides advantages for defenders as well. NCC Group noted that security teams can use it to process large volumes of telemetry, identify suspicious activity, and prioritise investigations. However, context is critical. Automated tools may surface an anomaly, but experienced analysts must still determine whether it represents ordinary business activity, a policy issue, or a genuine intrusion.

For technology providers and channel partners, the July increase creates a practical opening to move customer conversations beyond individual products. Identity, patching, monitoring, recovery, and employee reporting work as connected disciplines. While AI accelerates capabilities on both sides, the organisations that combine automation with sound controls and human judgement present much harder targets for cybercriminals.