< Back to all clusters
[TECHNOLOGY] · United States, United Kingdom · 4 sources

started · updated

Ransomware attacks hit 2026 peak amid rise in autonomous AI threats

Ransomware activity reached a 2026 peak in July, with NCC Group recording 894 victim organization listings, a 22% increase from June. The industrials sector was the most targeted, accounting for 28% of attacks. Geographically, North America and Europe combined represented 70% of the global volume.

A significant escalation in threat sophistication was noted with the emergence of JADEPUFFER, described as the first known fully autonomous AI-driven attack agent capable of executing entire attack chains from initial compromise to extortion without human intervention. The threat group The Gentlemen was responsible for approximately 15% of the recorded attacks.

Separately, the Cl0p ransomware group has targeted more than 40 major organizations by exploiting a critical vulnerability (CVE-2026-12569) in PTC’s Windchill and FlexPLM platforms. This vulnerability, which was added to CISA’s Known Exploited Vulnerabilities catalog in June 2026, allows for remote, unauthenticated arbitrary code execution.

Entities

CISA · Cl0p · JADEPUFFER · NCC Group · PTC

Claims

What the coverage asserts, and how many sources carry each claim.