zerofox logo
Advisories

ZeroFox Intelligence Assessment - August 2026 Ransomware Wrap-Up

|by Alpha Team

banner image

ZeroFox Intelligence Assessment - August 2026 Ransomware Wrap-up

TLP:Clear

Standing Intelligence Requirements

DDW

For the most up-to-date list of ZeroFox’s Intelligence Requirements, please visit:

https://cloud.zerofox.com/intelligence/advisories/14956

Link to Download

View the full report here.

Key Findings

  • ZeroFox observed at least 863 separate ransomware and digital extortion (R&DE) incidents in August 2026, an increase of approximately 11 percent from the 776 incidents recorded in July 2026. Additionally, August 2026 marked an approximate 98 percent increase year-over-year from the 436 incidents recorded in 2025 and an approximate 121 percent increase from the 390 incidents recorded in 2024.
  • North American targets saw a 50 percent increase in year-over-year incidents from August 2025; however, this was a decrease in global share from the approximate 61 percent observed in August 2025 to an approximate 46 percent observed in August 2026.
  • In August 2026, ZeroFox observed that the manufacturing industry remained the most targeted sector, with at least 175 recorded R&DE incidents (an increase from the 159 observed in July 2026).
  • ZeroFox observed that the five most active R&DE collectives in August 2026 were almost certainly Qilin, The Gentlemen, Cl0p, Orova, and Dire Wolf. This is a change from July 2026, with only The Gentlemen and Qilin remaining in the top five from the previous month.

Tags: tlp:clear dark web data breach