What changed
2026-08-03 14:34 UTC → 2026-08-11 17:12 UTC ·
added
removed
Cyber threats surge, and ransomware attacks rise Q2 escalate in 2026
Check Point’s mid‑2026 reports confirm a broad acceleration of cyber activity. Weekly global attack attempts topped 2,200, with travel‑related firms seeing more than double the incidents of three years ago – about 2,291 attacks per company per week – Cyber activity and ransomware attacks saw significant acceleration through mid-2026. While earlier reports noted a 33 % month‑on‑month rise in malicious domain registrations, many using AI‑generated phishing sites that mimic major brands. Critical vulnerability exposures also more than doubled year‑on‑year, now accounting for 42.6 % of all critical exposures. AI‑assisted tools are shortening the gap between disclosure registrations and AI-assisted exploitation, while supply‑chain attacks on firewalls, VPNs and management portals increase. Ransomware activity continued its upward trend. The Gentlemen overtook Qilin as the most active gang in June, claiming 94 victims and contributing to a 9 % month‑over‑month rise to 707 compromised organisations worldwide. Overall new data from Q2 2026 highlights a 40% year-on-year increase in undisclosed ransomware incidents reached 1,885, attacks. This period saw 93 active groups, including 28 newly formed entities, with the “four‑headed monster” group Settra emerging as a new actor. Data exfiltration reached a record 97% of disclosed cases, averaging 508 GB stolen per undisclosed incident. Leading threat actors such as Qilin, The Gentlemen, Akira and DragonForce responsible for over 40 % of attacks. The United States and Germany remain continue to dominate the hardest‑hit nations. Regionally, Italian organisations faced 2,602 weekly attacks in landscape. In July 2026, global cyberattacks rose to 83,456, a 16.5% increase from June, an 11.5 % increase, with education leading the target list. Gen’s first‑half 2026 threat report warned that attackers now treat trust—such as hotel‑booking platforms, WhatsApp session approvals and AI‑agent workflows—as a primary attack surface, blocking 114.2 million attempts. The first half ransomware accounting for 61.4% of 2026 saw a 16.5 % global rise in ransomware, driven all incidents. Concurrently, DDoS threats escalated, with hyper-volumetric attacks exceeding 1 Tbps growing by 519% between the professionalisation first and second quarters of RaaS. Notably, 2026. Geographically, the United States remains the most targeted nation, followed by Germany, France, and Italy. In Latin America, Colombia’s Ministry of Justice suffered confirmed a ransomware breach that disrupted services, underscoring IT infrastructure, highlighting the expanding risk to vulnerability of public institutions. The professionalization of the ransomware-as-a-service (RaaS) model remains a primary driver of this global surge, impacting sectors such as manufacturing, technology, and business services.