< Back to situations

We’ll email you as it develops, and you can follow the whole thread from day one.

[SITUATION] · [ACTIVE]

2 clusters · 20 sources · 2 days · First seen · Last updated

Categories: CRIME

Global ransomware activity surge

Overview

Since late July 2026, ransomware activity has continued to expand both in scale and persistence. The Qilin group reported 1,358 victims across more than 50 countries, while the Royal campaign combined Qbot and Cobalt Strike to breach Windows domains. A Proofpoint AI‑Era Ransomware Report surveyed 953 security professionals in 12 countries and found that 54 % of organisations paid a ransom, and among those, 37 % were hit with a second extortion demand; 2 % paid but never recovered their files. AI‑driven tools were credited by 65 % of respondents for making attacks—especially phishing, impersonation and credential theft—more effective. The report reiterated the Change Healthcare case, where a $22 million payment was followed by an additional demand, and a UK‑focused analysis showed similar patterns. Simultaneously, the Clop group began exploiting a critical CVE‑2026‑12569 flaw in PTC’s product‑life‑cycle software.

Later in July, Proofpoint and Sophos confirmed that repeat‑extortion remained common, with 37 % of ransom‑paying victims receiving a second demand and average recovery costs rising 11 % to $1.7 million. In the Netherlands, health‑invoice processor Infomedics reported a surge of AI‑generated fake care‑bill emails, logging over 20 000 fraudulent invoices created by criminal networks in India, Romania and Peru. This highlights the expanding role of AI‑enhanced phishing in the healthcare sector, reinforcing the broader shift toward sustained, AI‑augmented ransomware campaigns that exploit newly disclosed software vulnerabilities.

Timeline

  1. 2 days ago

    [CRIME] 17 sources
    Ransomware extortion spikes and AI‑generated phishing invoices target Dutch healthcare

    Ransomware attacks are increasingly using AI‑driven repeat extortion, raising recovery costs, while Infomedics reports a record rise in AI‑generated phishing invoices targeting Dutch healthcare patients.

  2. 4 days ago

    [CRIME] 3 sources
    Qilin ransomware reports 1,358 victims amid global ransomware surge

    Qilin ransomware claimed 1,358 victims in over 50 countries, a 443% rise, while Royal ransomware used Qbot and Cobalt Strike to swiftly hijack Windows domains, affecting dozens of organizations.

Sources

beveiligingnieuws.nl · businesstechweekly.com · cinemagia.wordpress.com · cybersecuritynews.com · dagelijksestandaard.nl · digitalmarketreports.com · estadodiario.com · fighthistory.com · hackread.com · nationalezorggids.nl · pcquest.com · redactie24.be · saferworld.org.uk · security.nl · sf-encyclopedia.com · silicon.es · techradarpro.com · thecyberexpress.com · theedadvocate.org · welingelichtekringen.nl