Ransomware surges while AI dominates the conversation
Ransomware attacks rose 20 per cent in July 2026 to 799 confirmed incidents, according to Comparitech data reported by The Register. Finance, technology, pharmaceuticals and education absorbed the sharpest increases while attention stayed fixed on artificial intelligence.
Article record
Why it matters
What this means for organisations holding critical data
Ransomware attacks rose 20 per cent in July 2026 to 799 confirmed incidents, according to Comparitech data reported by The Register. Finance, technology, pharmaceuticals and education absorbed the sharpest increases while attention stayed fixed on artificial intelligence.
The Register has published figures that deserve a careful read. Ransomware groups are not slowing down. They are changing targets, and they are doing so while the board level conversation is dominated by artificial intelligence.
What the data shows
New data from Comparitech for July 2026 records 799 ransomware attacks, up 20 per cent from 668 in June. That makes July the second busiest month of the year so far, just behind March with 805 attacks. Only 51 of those victims were confirmed publicly, which tells you how much of this activity never reaches a headline.
Where the pressure moved
The sector movements are the most revealing part of the picture:
- Finance, up 71 per cent
- Technology, up 62 per cent
- Pharmaceuticals and medical billing, up 46 per cent
- Education, up 44 per cent
This is not random. Groups are measuring the probability of getting paid. They are going after organisations with healthy margins, sensitive records and low tolerance for downtime, in industries the rest of us depend upon.
Who is behind the surge
Two names account for roughly a third of all claimed attacks in the month. The Gentlemen claimed 135 victims. Qilin claimed 125 victims. A small number of well organised operations continue to carry a disproportionate share of the harm.
The artificial intelligence distraction
Artificial intelligence is not the threat story here, but it is the reason the threat story is being missed. While strategy time is spent on model adoption and governance, ransomware crews are running the same playbook they have always run, only more efficiently, with artificial intelligence assisting reconnaissance, phishing quality and negotiation pressure. The tactics have not changed. The throughput has.
The Firevault view
Every one of these incidents depends on the same assumption: that the attacker can reach the data. Connected backup platforms, replicated cloud copies and always on file shares are all reachable, which is exactly why they are encrypted or deleted before the ransom note lands.
Offline Secure Storage® (#OSS) removes that assumption. Data held in a Firevault Vault sits on physically disconnected storage inside a secure bunker. It is not on a network path, so it cannot be enumerated, encrypted or exfiltrated during an intrusion. Access is enabled deliberately by the customer, then removed again. When a finance firm, a technology business, a pharmaceutical supplier or a university is hit, the question that decides the outcome is simple: is there a clean copy the attacker could never touch?
Boards should keep the artificial intelligence agenda. They should also confirm, this quarter, that a recovery position exists which does not rely on anything being online.
Source: The Register, Ransomware attacks spike as world distracted by AI, drawing on the Comparitech ransomware roundup for July 2026.
How Firevault would handle this
Physical disconnection removes the path an attacker needs
Offline Secure Storage® holds a clean copy of your data on hardware that is physically disconnected, so an intrusion cannot reach it, encrypt it or delete it.






