ZeroFox Intelligence Assessment - July 2026 Ransomware Wrap-Up
|by Alpha Team

ZeroFox Intelligence Assessment - July 2026 Ransomware Wrap-up
TLP:Clear
Standing Intelligence Requirements

For the most up-to-date list of ZeroFox’s Intelligence Requirements, please visit:
https://cloud.zerofox.com/intelligence/advisories/14956
Link to Download
View the full report here.
Key Findings
- ZeroFox observed at least 776 separate ransomware and digital extortion (R&DE) incidents in July 2026, an increase of approximately 22 percent from June 2026. Additionally, July 2026 marked a 78 percent increase in R&DE incidents year-over-year from July 2025 and a 101 percent increase from July 2024.
- ZeroFox observed a decline in North America’s global share of R&DE incidents for Q2 2026, with European organizations increasing their share. Overall, this trend continued into July 2026; North American targets saw a 12 percent decrease in year-over-year incidents from July 2025, suggesting threat actors are very likely expanding targeting efforts in other regions at a faster rate.
- The Gentlemen remained the most prominent R&DE collective in July 2026, accounting for at least 125 incidents; Qilin was the second most prominent with at least 121 incidents over the course of the month.
- Thus far, 2026 has seen an average of at least one new threat actor per week, and CRPx0 is very likely the latest new group to establish itself as a serious threat.
Tags: tlp:clear, threat actor, MAL Ransomware