ZeroFox Intelligence Assessment - August 2026 Ransomware Wrap-Up
|by Alpha Team

ZeroFox Intelligence Assessment - August 2026 Ransomware Wrap-up
TLP:Clear
Standing Intelligence Requirements

For the most up-to-date list of ZeroFox’s Intelligence Requirements, please visit:
https://cloud.zerofox.com/intelligence/advisories/14956
Link to Download
View the full report here.
Key Findings
- ZeroFox observed at least 863 separate ransomware and digital extortion (R&DE) incidents in August 2026, an increase of approximately 11 percent from the 776 incidents recorded in July 2026. Additionally, August 2026 marked an approximate 98 percent increase year-over-year from the 436 incidents recorded in 2025 and an approximate 121 percent increase from the 390 incidents recorded in 2024.
- North American targets saw a 50 percent increase in year-over-year incidents from August 2025; however, this was a decrease in global share from the approximate 61 percent observed in August 2025 to an approximate 46 percent observed in August 2026.
- In August 2026, ZeroFox observed that the manufacturing industry remained the most targeted sector, with at least 175 recorded R&DE incidents (an increase from the 159 observed in July 2026).
- ZeroFox observed that the five most active R&DE collectives in August 2026 were almost certainly Qilin, The Gentlemen, Cl0p, Orova, and Dire Wolf. This is a change from July 2026, with only The Gentlemen and Qilin remaining in the top five from the previous month.
Tags: tlp:clear, dark web, data breach