---
title: "Ransomware Attacks Spike 20% in July While AI S… | Firevault"
description: "Ransomware attacks jumped nearly 20 per cent in July, with 799 incidents logged globally. While AI dominates security headlines, finance, technology,…"
lang: en-GB
json-ld: |
  [
    {
      "@context": "https://schema.org",
      "@type": "Organization",
      "@id": "https://fire-vault.com/#organization",
      "name": "Firevault",
      "legalName": "Firevault Limited",
      "url": "https://fire-vault.com",
      "logo": {
        "@type": "ImageObject",
        "url": "https://fire-vault.com/logo.png",
        "width": 200,
        "height": 60
      },
      "foundingDate": "2025-03",
      "description": "Protect what matters with Offline Secure Storage and control what moves with Control by Firevault. Physically disconnected, always reachable by you.",
      "address": {
        "@type": "PostalAddress",
        "addressCountry": "GB",
        "addressLocality": "United Kingdom"
      },
      "contactPoint": [
        {
          "@type": "ContactPoint",
          "contactType": "customer service",
          "email": "hello@fire-vault.com",
          "availableLanguage": "English",
          "areaServed": [
            "GB",
            "EU",
            "US",
            "AE"
          ]
        }
      ],
      "sameAs": [
        "https://www.linkedin.com/company/firevault",
        "https://x.com/firevaultuk"
      ],
      "slogan": "Disconnect to Protect",
      "knowsAbout": [
        "Offline Secure Storage",
        "Physical Air Gap Data Protection",
        "Ransomware Protection",
        "Data Sovereignty",
        "GDPR Compliance",
        "NIS2 Compliance"
      ]
    },
    {
      "@context": "https://schema.org",
      "@type": "WebSite",
      "@id": "https://fire-vault.com/#website",
      "name": "Firevault",
      "alternateName": [
        "Firevault",
        "Firevault UK",
        "Firevault Limited"
      ],
      "url": "https://fire-vault.com",
      "publisher": {
        "@id": "https://fire-vault.com/#organization"
      },
      "inLanguage": "en-GB",
      "description": "Protect what matters with Offline Secure Storage and control what moves with Control by Firevault. Physically disconnected, always reachable by you.",
      "potentialAction": {
        "@type": "SearchAction",
        "target": {
          "@type": "EntryPoint",
          "urlTemplate": "https://fire-vault.com/learn?q={search_term_string}"
        },
        "query-input": "required name=search_term_string"
      }
    },
    {
      "@context": "https://schema.org",
      "@type": "WebPage",
      "@id": "https://fire-vault.com/news/ransomware-attacks-spike-july-2026-ai-distraction#webpage",
      "url": "https://fire-vault.com/news/ransomware-attacks-spike-july-2026-ai-distraction",
      "name": "Ransomware Attacks Spike 20% in July While AI S…",
      "description": "Ransomware attacks jumped nearly 20 per cent in July, with 799 incidents logged globally. While AI dominates security headlines, finance, technology,…",
      "isPartOf": {
        "@id": "https://fire-vault.com/#website"
      },
      "about": {
        "@id": "https://fire-vault.com/#organization"
      },
      "primaryImageOfPage": {
        "@type": "ImageObject",
        "url": "https://zomvctmqpgirvjnvawlz.supabase.co/storage/v1/object/public/article-images/news%2Fransomware-spike-ai-distraction.jpg"
      },
      "inLanguage": "en-GB",
      "breadcrumb": {
        "@id": "https://fire-vault.com/news/ransomware-attacks-spike-july-2026-ai-distraction#breadcrumb"
      }
    },
    {
      "@context": "https://schema.org",
      "@type": "BreadcrumbList",
      "@id": "https://fire-vault.com/news/ransomware-attacks-spike-july-2026-ai-distraction#breadcrumb",
      "itemListElement": [
        {
          "@type": "ListItem",
          "position": 1,
          "name": "Home",
          "item": "https://fire-vault.com"
        },
        {
          "@type": "ListItem",
          "position": 2,
          "name": "Learn",
          "item": "https://fire-vault.com/learn"
        },
        {
          "@type": "ListItem",
          "position": 3,
          "name": "Knowledge Vault",
          "item": "https://fire-vault.com/learn/knowledge"
        },
        {
          "@type": "ListItem",
          "position": 4,
          "name": "Ransomware Attacks Spike 20% in July While AI Steals the Headlines",
          "item": "https://fire-vault.com/news/ransomware-attacks-spike-july-2026-ai-distraction"
        }
      ]
    },
    {
      "@context": "https://schema.org",
      "@type": "NewsArticle",
      "headline": "Ransomware Attacks Spike 20% in July While AI Steals the Headlines",
      "description": "Ransomware attacks jumped nearly 20 per cent in July, with 799 incidents logged globally. While AI dominates security headlines, finance, technology, pharmaceutical, medical billing and education organisations absorbed the sharpest increases.",
      "url": "https://fire-vault.com/news/ransomware-attacks-spike-july-2026-ai-distraction",
      "image": [
        {
          "@type": "ImageObject",
          "url": "https://zomvctmqpgirvjnvawlz.supabase.co/storage/v1/object/public/article-images/news%2Fransomware-spike-ai-distraction.jpg",
          "width": 1200,
          "height": 1200
        },
        {
          "@type": "ImageObject",
          "url": "https://zomvctmqpgirvjnvawlz.supabase.co/storage/v1/object/public/article-images/news%2Fransomware-spike-ai-distraction.jpg",
          "width": 1200,
          "height": 900
        },
        {
          "@type": "ImageObject",
          "url": "https://zomvctmqpgirvjnvawlz.supabase.co/storage/v1/object/public/article-images/news%2Fransomware-spike-ai-distraction.jpg",
          "width": 1200,
          "height": 675
        }
      ],
      "thumbnailUrl": "https://zomvctmqpgirvjnvawlz.supabase.co/storage/v1/object/public/article-images/news%2Fransomware-spike-ai-distraction.jpg",
      "author": {
        "@type": "Person",
        "name": "Mark Fermor",
        "jobTitle": "Director & Co-Founder",
        "worksFor": {
          "@id": "https://fire-vault.com/#organization"
        },
        "url": "https://fire-vault.com/why-oss/about"
      },
      "publisher": {
        "@type": "NewsMediaOrganization",
        "name": "Firevault",
        "url": "https://fire-vault.com",
        "logo": {
          "@type": "ImageObject",
          "url": "https://fire-vault.com/logo.png",
          "width": 600,
          "height": 60
        }
      },
      "datePublished": "2026-08-12T17:52:00+00:00",
      "dateModified": "2026-08-28T08:03:22.256672+00:00",
      "mainEntityOfPage": {
        "@type": "WebPage",
        "@id": "https://fire-vault.com/news/ransomware-attacks-spike-july-2026-ai-distraction"
      },
      "inLanguage": "en-GB",
      "articleSection": "Breach Analysis",
      "wordCount": 731,
      "keywords": "Ransomware, Breach Analysis, data breach, cyber security, offline secure storage, data protection, physical air gap, ransomware attacks July 2026, Comparitech ransomware statistics, The Gentlemen ransomware group, Qilin ransomware, AI distraction cybersecurity, finance sector ransomware, education ransomware, pharmaceutical ransomware, medical billing ransomware, ransomware resilience, offline secure storage ransomware protection, physical air gap backup",
      "articleBody": "Ransomware attacks jumped nearly 20 per cent in July while the security industry’s attention was fixed on artificial intelligence. UK research firm Comparitech counted 799 ransomware incidents during the month, up from 668 in June. Of those, 51 had been confirmed by victims. The tally makes July the second busiest month of 2026 for ransomware, just behind March, when the firm recorded 805 attacks.",
      "dateline": "United Kingdom",
      "speakable": {
        "@type": "SpeakableSpecification",
        "cssSelector": [
          "h1",
          ".article-summary",
          "h2"
        ]
      },
      "isAccessibleForFree": true,
      "copyrightHolder": {
        "@id": "https://fire-vault.com/#organization"
      },
      "copyrightYear": 2026
    }
  ]
---

Recent Breaches 

Breaches 

[2026 PowerSchool 62.4M records ](/learn/breaches)[2026 DISA Global Solutions 3.3M records ](/learn/breaches)[2026 Globe Life 850K records ](/learn/breaches)[2026 Lidl GB Customer contact data ](/learn/breaches)[2026 Asahi Group Production systems disrupted ](/learn/breaches)[2026 Kido International 8K records ](/learn/breaches)[2026 Collins Aerospace (RTX) Check-in and boarding disruptio... ](/learn/breaches)[2026 Jaguar Land Rover Production and IT systems disru... ](/learn/breaches)[2026 Peter Green Chilled Order and logistics data ](/learn/breaches)[2026 Adidas UK Customer contact details ](/learn/breaches)[2026 PowerSchool 62.4M records ](/learn/breaches)[2026 DISA Global Solutions 3.3M records ](/learn/breaches)[2026 Globe Life 850K records ](/learn/breaches)[2026 Lidl GB Customer contact data ](/learn/breaches)[2026 Asahi Group Production systems disrupted ](/learn/breaches)[2026 Kido International 8K records ](/learn/breaches)[2026 Collins Aerospace (RTX) Check-in and boarding disruptio... ](/learn/breaches)[2026 Jaguar Land Rover Production and IT systems disru... ](/learn/breaches)[2026 Peter Green Chilled Order and logistics data ](/learn/breaches)[2026 Adidas UK Customer contact details ](/learn/breaches)

[View All →](/learn/breaches)

[![Firevault - offline secure storage, physically disconnected from the internet](/assets/logo-color-DBVl0KCg.png)](/)

Products

Solutions

[Why OSS](/why-oss)

More

[Help](/help)[Get started](/get-started)

Overview

What the Data ShowsWhy These Sectors PayThe Gangs Behind the SpikeThe AI DistractionThe Firevault ViewConclusionMore Resources

[Knowledge Vault](/learn/knowledge)/ [News](/learn/knowledge?filter=news)

News · Breach Analysis · 12 August 2026 

# Ransomware Attacks Spike 20% in July While AI Steals the Headlines

Ransomware attacks jumped nearly 20 per cent in July, with 799 incidents logged globally. While AI dominates security headlines, finance, technology, pharmaceutical, medical billing and education organisations absorbed the sharpest increases.

![Mark Fermor](/assets/mark-fermor-aWtKNSv7.jpg)

Mark Fermor Director & Co-Founder, Firevault 

4 min read 

Share 

[](https://www.linkedin.com/sharing/share-offsite/?url=https%3A%2F%2Ffire-vault.com%2Fnews%2Fransomware-attacks-spike-july-2026-ai-distraction)[](https://twitter.com/intent/tweet?url=https%3A%2F%2Ffire-vault.com%2Fnews%2Fransomware-attacks-spike-july-2026-ai-distraction&text=Ransomware%20Attacks%20Spike%2020%25%20in%20July%20While%20AI%20Steals%20the%20Headlines%0A%0ARansomware%20attacks%20jumped%20nearly%2020%20per%20cent%20in%20July%2C%20with%20799%20incidents%20logged%20globally.%20While%20AI%20dominates%20security%20headlines%2C%20finance%2C%20technology%2C%20pharmaceutical%2C%20medical%20billing%20and%20education%20organisations%20absorbed%20the%20sharpest%20increases.)[](https://www.facebook.com/sharer/sharer.php?u=https%3A%2F%2Ffire-vault.com%2Fnews%2Fransomware-attacks-spike-july-2026-ai-distraction)[](mailto:?subject=Ransomware%20Attacks%20Spike%2020%25%20in%20July%20While%20AI%20Steals%20the%20Headlines&body=Ransomware%20attacks%20jumped%20nearly%2020%20per%20cent%20in%20July%2C%20with%20799%20incidents%20logged%20globally.%20While%20AI%20dominates%20security%20headlines%2C%20finance%2C%20technology%2C%20pharmaceutical%2C%20medical%20billing%20and%20education%20organisations%20absorbed%20the%20sharpest%20increases.%0A%0Ahttps%3A%2F%2Ffire-vault.com%2Fnews%2Fransomware-attacks-spike-july-2026-ai-distraction)

![Abstract illustration showing a ransomware lock symbol and AI neural network separated by a physical gap, in navy, magenta and cyan](https://zomvctmqpgirvjnvawlz.supabase.co/storage/v1/object/public/article-images/news%2Fransomware-spike-ai-distraction.jpg)

Abstract illustration showing a ransomware lock symbol and AI neural network separated by a physical gap, in navy, magenta and cyan

Why it matters

## What this means for organisations holding critical data

Ransomware attacks jumped nearly 20 per cent in July, with 799 incidents logged globally. While AI dominates security headlines, finance, technology, pharmaceutical, medical billing and education organisations absorbed the sharpest increases.

In this analysis

1.  01 [What the Data Shows](#section-0)
2.  02 [Why These Sectors Pay](#section-1)
3.  03 [The Gangs Behind the Spike](#section-2)
4.  04 [The AI Distraction](#section-3)
5.  05 [The Firevault View](#section-4)

**On this page**[What the Data Shows](#section-0)[Why These Sectors Pay](#section-1)[The Gangs Behind the Spike](#section-2)[The AI Distraction](#section-3)[The Firevault View](#section-4)

**Ransomware attacks jumped nearly 20 per cent in July while the security industry’s attention was fixed on artificial intelligence.** UK research firm Comparitech counted [799 ransomware incidents](https://www.comparitech.com/blog/security/ransomware-statistics/) during the month, up from 668 in June. Of those, 51 had been confirmed by victims. The tally makes July the second busiest month of 2026 for ransomware, just behind March, when the firm recorded 805 attacks.

## What the Data Shows

The headline figure is only part of the story. The distribution of attacks changed sharply in July. Ransomware incidents against utility companies fell 44 per cent, and attacks on legal firms and government agencies dropped 31 per cent and 11 per cent respectively. Those sectors were not the ones that suffered.

The sectors that saw the steepest increases were:

-   Finance companies, up 71 per cent
-   Technology firms, up 62 per cent
-   Pharmaceutical companies and medical billers, up 46 per cent
-   Education, up 44 per cent

The United States remained the most targeted country, absorbing 322 of the 799 attacks. Germany was second with just 40.

## Why These Sectors Pay

The pattern is not random. Penetration testing firm DeepStrike [reported](https://deepstrike.io/blog/ransomware-payout-statistics-2025) that manufacturing, education, healthcare and financial services firms are the most likely to pay a ransom. Even the least likely of those groups, finance, still pays in 51 per cent of cases. For an attacker optimising for return on effort, that is a powerful incentive.

These organisations share a common pressure: downtime is expensive, data is sensitive, and regulatory or operational consequences make restoration urgent. That urgency is what ransomware crews monetise.

## The Gangs Behind the Spike

Two groups dominated July. The Gentlemen, a relatively new operation that earlier this year claimed an attack on UK software consultancy Adaptavist Group, led the month with 135 claimed victims. Qilin, the crew behind the [2024 Synnovis breach](https://www.theregister.com/cyber-crime/2026/06/09/qilin-nhs-breach-tally-grows-as-essex-trust-confirms-stolen-records/5252663) that disrupted NHS services, claimed 125. Between them they accounted for nearly 33 per cent of logged attacks.

Their methods are familiar. Trend Micro has [described](https://www.trendmicro.com/en_us/research/25/i/unmasking-the-gentlemen-ransomware.html) The Gentlemen using stolen credentials. Qilin has [told](https://www.theregister.com/security/2024/06/20/qilin-has-no-regrets-over-the-healthcare-crisis-it-caused/304556) The Register it abused zero-day vulnerabilities to break into Synnovis. Both routes, credential abuse and unpatched software, exploit the same underlying condition: data and systems that remain continuously connected.

## The AI Distraction

The timing matters. July was the month security headlines were dominated by agentic AI, model escapes and speculation about autonomous malware. The Register’s report frames the spike as a reminder that while attention drifts toward emerging threats, the old ones do not pause.

Boards and security teams are right to think about AI risk. But AI-enabled attacks are not yet the main source of damage. Ransomware is. And ransomware’s success still depends on the same controls it always has: exposed credentials, missing patches, flat networks and backups that live online.

## The Firevault View

There is a structural reason ransomware keeps working. Most organisations defend the connection rather than questioning whether the connection should exist at all. Every live copy of critical data is a target that can be encrypted, exfiltrated or held hostage. Every always-on system is a beachhead waiting for the right credential or exploit.

[Offline Secure Storage](/offline-secure-storage)® changes the equation. By holding verified gold copies of critical data on hardware that is physically disconnected when not in active use, it removes the attack surface rather than merely hardening it. A ransomware operator cannot encrypt a copy that is not connected. They cannot exfiltrate data that has no network interface. Recovery starts from a known-good physical state, not from a negotiation.

For the sectors hit hardest in July, finance, technology, pharmaceuticals, medical billing and education, the principle is the same. Crown jewel records, research archives, patient data, regulatory files and financial ledgers do not need to be online twenty-four hours a day to be valuable. They need to be available when required and unreachable the rest of the time.

## Conclusion

The July spike is a correction. It reminds us that ransomware remains the most immediate, measurable and financially motivated cyber threat facing organisations today. AI may reshape the threat landscape, but the present landscape is still dominated by crews who break in, encrypt data and demand payment.

The practical response has not changed: multi-factor authentication, timely patching, tested backups and a deliberate decision about which data must remain connected. For the data that does not need to be connected, Offline Secure Storage® offers a way to take it permanently off the board.

Sources

## Where this reporting comes from

01 

**Original report**Primary coverage referenced in this analysis [View original article](https://www.theregister.com/security/2026/08/07/ransomware-attacks-spike-as-world-distracted-by-ai/5284934)

About the author

![Mark Fermor](/assets/mark-fermor-aWtKNSv7.jpg)

### Mark Fermor

[](https://www.linkedin.com/in/mfermor)

Director & Co-Founder

Co-founder of Firevault, focused on offline secure storage and protecting individuals and businesses from fraud, fines, loss and damage. Speaker, owner and advisor.

[![Firevault Bunker, the protected physical location for Offline Secure Storage hardware](/__l5e/assets-v1/75208f4e-fc6f-46d8-80b9-606c43dfef28/firevault-bunker-building.webp)](/why-oss)

The Firevault view**Offline Secure Storage® keeps a clean copy beyond the reach of an attacker.**[Why #OSS →](/why-oss)

[![The nine Control modules arranged around the Firevault platform](/__l5e/assets-v1/829a8768-a871-41d0-8a79-3645ca7f5e83/platform-wheel.jpg)](/solutions/control)

Control systems and access**Cut the physical paths attackers and third parties depend on.**[Explore Control →](/solutions/control)

[![Firevault 2TB Vault hardware](/__l5e/assets-v1/ed09bfc1-2f0f-491d-b1aa-861542a5fb33/hero-vault-2tb.png)](/get-started)

Get started**Get started, or talk to a member of the team.**[Get started →](/get-started)

How Firevault would handle this

## A recovery copy an attacker cannot reach

Offline Secure Storage® keeps a clean copy of your data on hardware that is physically disconnected, so backup and recovery do not depend on systems an intruder can touch.

[Get started](/get-started)[Talk to the team](/demo)

**Hardware**Your copy sits on dedicated encrypted hardware 

**Disconnect**Offline by default, connected only when you say so 

**Recovery**A known-clean copy to rebuild from, on your timetable 

**Location**Held in a secure Firevault Bunker 

Related Reading

## You may also find these useful

[

![Trezor breach reaches 81,000 customers because a supplier never deleted the data](/images/news/trezor-shipmonk-data-breach-81000-customers-2026.jpg)

Breach Analysis 

### Trezor breach reaches 81,000 customers because a supplier never deleted the data

A further 67,000 US customers who ordered between 2019 and 2021 were exposed, because Trezor's logistics provider kept data it had confirmed in writing it had deleted.

8 Sept 2026 3 min 







](/news/trezor-shipmonk-data-breach-81000-customers-2026)[

![Quinn Emanuel and McDermott breached as law firms become the soft route to client data](/images/news/law-firms-quinn-emanuel-mcdermott-data-breaches-2026.jpg)

Breach Analysis 

### Quinn Emanuel and McDermott breached as law firms become the soft route to client data

Two more major US law firms have disclosed social engineering breaches, joining Herbert Smith Freehills Kramer, Goodwin Procter and WilmerHale. One compromised user account was enough.

8 Sept 2026 4 min 







](/news/law-firms-quinn-emanuel-mcdermott-data-breaches-2026)[

![Mathspace breach exposes more than one million students, staff and parents](/images/news/mathspace-data-breach-one-million-students-2026.jpg)

Breach Analysis 

### Mathspace breach exposes more than one million students, staff and parents

An unpatched self-hosted reporting system gave attackers seventeen days inside Mathspace, exposing names and email addresses for 1,079,819 people across Australia and New Zealand.

8 Sept 2026 4 min 







](/news/mathspace-data-breach-one-million-students-2026)[

![AnMed Closes Facilities Following Ransomware Attack and Data Claims](https://zomvctmqpgirvjnvawlz.supabase.co/storage/v1/object/public/article-images/anmed-facility-closures-following-ransomware-cyberattack-1786723492583.png)

Breach Analysis 

### AnMed Closes Facilities Following Ransomware Attack and Data Claims

South Carolina health system AnMed was forced to close 83 facilities following a cyberattack. Threat actors subsequently claimed to hold 6 terabytes of sensitive patient records.

14 Aug 2026 4 min 







](/news/anmed-facility-closures-following-ransomware-cyberattack)[

![US directive allows private firms to conduct offensive cyber operations](https://zomvctmqpgirvjnvawlz.supabase.co/storage/v1/object/public/article-images/us-directive-private-firms-offensive-cyber-operations-1786723418300.png)

Breach Analysis 

### US directive allows private firms to conduct offensive cyber operations

US President Donald Trump has signed a memorandum permitting private firms to execute offensive cyber operations. The move raises new risks of retaliatory attacks and collateral system disruptions.

14 Aug 2026 3 min 







](/news/us-directive-private-firms-offensive-cyber-operations)[

![Adobe Commerce attacked immediately after session breach vulnerability](https://zomvctmqpgirvjnvawlz.supabase.co/storage/v1/object/public/article-images/adobe-commerce-session-vulnerability-exploited-after-disclosure-1786684691416.png)

Breach Analysis 

### Adobe Commerce attacked immediately after session breach vulnerability

Security firm Sansec blocked attacks targeting Adobe Commerce immediately after disclosure. The flaw allows unauthenticated attackers to hijack sessions and customer data.

14 Aug 2026 4 min 







](/news/adobe-commerce-session-vulnerability-exploited-after-disclosure)

## Suggested Reading

-   [What is Offline Secure Storage The foundation of physical disconnection ](/how-it-works/offline-secure-storage)
-   [Why Offline Secure Storage The case for physical control ](/why-oss)
-   [Ransomware Defence Hold gold copies offline ](/oss-for-ransomware-recovery)
-   [Control Physical path control for IT and OT ](/solutions/control)
-   [Knowledge Vault All articles, guides and whitepapers ](/learn/knowledge)
-   [Book a Demo See Firevault in action ](/demo)

[Back to Knowledge Vault](/learn/knowledge)