started · updated
Ransomware attacks hit 2026 peak amid rise in autonomous AI threats
Ransomware activity reached a 2026 peak in July, with NCC Group recording 894 victim organization listings, a 22% increase from June. The industrials sector was the most targeted, accounting for 28% of attacks. Geographically, North America and Europe combined represented 70% of the global volume.
A significant escalation in threat sophistication was noted with the emergence of JADEPUFFER, described as the first known fully autonomous AI-driven attack agent capable of executing entire attack chains from initial compromise to extortion without human intervention. The threat group The Gentlemen was responsible for approximately 15% of the recorded attacks.
Separately, the Cl0p ransomware group has targeted more than 40 major organizations by exploiting a critical vulnerability (CVE-2026-12569) in PTC’s Windchill and FlexPLM platforms. This vulnerability, which was added to CISA’s Known Exploited Vulnerabilities catalog in June 2026, allows for remote, unauthenticated arbitrary code execution.
Entities
CISA · Cl0p · JADEPUFFER · NCC Group · PTC
Claims
What the coverage asserts, and how many sources carry each claim.
- [○ 1 SOURCE] CISA added vulnerability CVE-2026-12569 to its Known Exploited Vulnerabilities catalog in June 2026. que.com
- [○ 1 SOURCE] The Cl0p ransomware group has targeted more than 40 major organizations by exploiting a vulnerability in PTC’s Windchill platform. que.com
- [● 3 SOURCES] The industrials sector was the most targeted industry, accounting for 28% of all ransomware attacks. futurumgroup.com · nationalcybersecurity.com · www.zdnet.com
- [● 3 SOURCES] NCC Group recorded 894 ransomware cases in July 2026, representing a 22% month-on-month increase. futurumgroup.com · nationalcybersecurity.com · www.zdnet.com
- [● 3 SOURCES] North America and Europe combined accounted for 70% of global ransomware volume. futurumgroup.com · nationalcybersecurity.com · www.zdnet.com
- [● 3 SOURCES] The JADEPUFFER agent is the first known fully autonomous AI-driven attack agent capable of executing attacks from compromise to extortion without human instruction. futurumgroup.com · nationalcybersecurity.com · www.zdnet.com