July 2026 Threat Trend Report on Ransomware
Purpose and Scope
The July 2026 Threat Trend Report on Ransomware summarizes major Korean & global ransomware issues based on statistics regarding the quantity of new ransomware samples, the number of compromised systems, and statistics on targeted businesses. Statistics on targeted businesses were compiled based on information published on DLS (Dedicated Leak Sites, also referred to as ransomware PR sites or PR pages) operated by ransomware groups.
Key Statistics
Damage Status by Industry
In July 2026, the Manufacturing sector (85 incidents) had the highest number of incidents. This was followed by the Information and communication sector (59 incidents), the Wholesale and distribution sector (40 incidents), the Health and social welfare services sector (27 incidents), and the Professional, scientific, and technical services sector (22 incidents). Incidents were also confirmed in the Finance and insurance sector (11 cases), education services (10 cases), public administration and defense (10 cases), accommodation and food services (8 cases), and Construction (7 cases).
Damage Status by Country
By country, the US (us) had the highest number of cases (247). France (fr) (60 cases), Germany (de) (54 cases), Thailand (th) (43 cases), India (in) (36 cases), Canada (ca) (33 cases), Brazil (br) (28 cases), Italy (it) (25 cases), Spain (es) (19 cases), and the United Kingdom (gb) (19 cases).
Changes in the Top 10 Ransomware Groups
Based on the number of affected companies, Gentlemen ranked first with approximately 159 incidents, followed by the Qilin group in second place with 126 incidents. DragonForce and WorldLeaks each had 44 incidents, IncRansom had 41, Nova had 35, SafePay had 33, and Akira had 30. Settra (28 cases) and KryBit (27 cases) newly entered the Top 10. Gentlemen’s top ranking was attributed to corrections for data collection omissions and cross-referencing with external statistics.
DLS and Detection Statistics
Over the past three years, the number of DLS damage incidents increased from January to March 2025, then showed a gradual downward trend before rising again in the last month. The number of ransomware detections showed a gradual decline since March 2025 but has been on the rise since November 2025.
Major Issues
In July 2026, attacks were observed across all regions, including Asia, Europe, North America, the Middle East, South America, and Oceania. Existing groups such as The Gentlemen, DragonForce, Nova, Gunra, Everest, krybit, LockBit (LockBit 5.0), Qilin, Chaos, ShinyHunters, Morpheus, INC Ransom, and Coinbase Cartel continued their activities, while new data-stealing and ransomware groups—including Gammax, SECTION9, ExfilSquad, Shiba, GLOBAL SECRET GROUP, D1R, The Crypt Apados, CRPx0, and Doommageddon also emerged as new data theft and ransomware groups.
The Gentlemen claimed responsibility for attacks targeting multiple regions, including Saudi Arabia, Indonesia, Malaysia, Japan, the US, and Norway; in South Korea, Line Up Korea was listed as a victim. DragonForce claimed responsibility for attacks that targeted One Community Federal Credit Union, NewNet S.A., Momenta, Al Saidi Chemical Industries Company, and STEP Oiltools. Nova targeted Indonesian public and healthcare institutions such as RSUI and Dephub. Everest announced that it had leaked 201 GB of data from Stadler Rail AG.
Among the new groups, ExfilSquad rapidly expanded its activities, claiming attacks on Microsoft and 15 companies worldwide, following its attack on Zenith Bank. Gammax, SECTION9, and GLOBAL SECRET GROUP also claimed to have attacked numerous companies. The NightSpire data leak site revealed server information and error pages, and exposures on the Clearnet were also identified. Additionally, a SOCKS5 proxy disguised as Nezha RMM (a remote management tool) and vmtools.Exe was identified.
Conclusion
Ransomware threats in July expanded in a complex manner due to ongoing attacks by established major groups and the continuous emergence of new groups. The manufacturing, healthcare, government and public sectors, finance, and IT sectors were the primary targets, with incidents confirmed across various regions worldwide. The report highlighted the need for prompt Vulnerability Patches, auditing third-party and supply chain access privileges, network segmentation, strengthening data backup systems, and proactive responses and continuous monitoring based on threat intelligence.