< Back to situation

[REVISION HISTORY]

Escalating global ransomware and AI-driven cyber threats

Updated 12 times since CLSTR started tracking revisions of this situation.

What changed

2026-09-06 04:21 UTC → 2026-09-20 16:15 UTC · added removed

Cyber activity and ransomware attacks saw significant acceleration through mid-2026. While earlier reports noted a rise in malicious domain registrations and AI-assisted exploitation, new data from Q2 2026 highlights a 40% year-on-year increase in undisclosed ransomware attacks. This period saw 93 active groups, including 28 newly formed entities, with the group Settra emerging as a new actor. Data exfiltration reached a record 97% of disclosed cases, averaging 508 GB stolen per undisclosed incident. Leading threat actors such as Qilin, The Gentlemen, and DragonForce continue to dominate the landscape. In July 2026, ransomware activity reached a peak, with NCC Group recording 894 victim organization listings, a 22% increase from June. The industrials sector was the most targeted, accounting for 28% of attacks. A significant escalation in sophistication occurred with the emergence of JADEPUFFER, described as the “first known fully autonomous AI-driven attack agent” capable of executing entire attack chains without human intervention. The group The Gentlemen was responsible for approximately 15% of recorded attacks. During this peak, North America and Europe collectively represented 70% By September 2026, regional volatility continued to expand. Canada reported ransomware rates of global volume. Additionally, 18.2% over a new group named CRPxO claimed responsibility for 36 victims, though NCC Group has cautioned that the group’s credibility six-month period, which is currently unverified due to inconsistent evidence. Germany has seen a sharp escalation in risk, rising to the second most targeted country globally behind more than double the United States. global average of 9.0%. Canadian organizations averaged 1,664 weekly attacks, peaking at 2,196 in late August. In June and July 2026 alone, Germany recorded 107 victims, a threefold increase from this region, Consumer Goods & Services faced the previous year. The SafePay ransomware group has become particularly active in Germany. Concurrently, highest volumes. Web-based delivery served as the Cl0p group has targeted over 40 major organizations by exploiting a critical vulnerability (CVE-2026-12569) in PTC’s Windchill and FlexPLM platforms. Technological trends show that 62% primary vector for nearly 60% of newly exploited vulnerabilities are zero-click exploits, allowing network-based access without user interaction. malicious files, while email accounted for approximately 40%, with PDFs identified as the most common malicious file type.

Versions

  1. 2026-09-20 16:15 UTC Escalating global ransomware and AI-driven cyber threats
  2. 2026-09-06 04:21 UTC Escalating global ransomware and AI-driven cyber threats
  3. 2026-08-28 01:57 UTC Escalating global ransomware and AI-driven cyber threats
  4. 2026-08-26 21:23 UTC Escalating global ransomware and AI-driven cyber threats
  5. 2026-08-25 08:43 UTC Escalating global ransomware and cyber threats in 2026
  6. 2026-08-25 04:44 UTC Escalating global ransomware and cyber threats in 2026
  7. 2026-08-22 10:38 UTC Escalating global ransomware and cyber threats in 2026
  8. 2026-08-21 16:39 UTC Escalating global ransomware and cyber threats in 2026
  9. 2026-08-17 07:22 UTC Escalating global ransomware and cyber threats in 2026
  10. 2026-08-11 17:12 UTC Cyber threats and ransomware attacks escalate in 2026
  11. 2026-08-03 14:34 UTC Cyber threats surge, ransomware attacks rise Q2 2026
  12. 2026-07-30 15:34 UTC Cyber threats surge, ransomware attacks rise Q2 2026
  13. 2026-07-26 03:22 UTC Cyber threats surge, ransomware attacks climb in Q2 2026

Only revisions since CLSTR began indexing content versions appear here. Select a version to see what changed compared to the one before it.