< Back to situation

[REVISION HISTORY]

AI‑enhanced ransomware surge and policy response

Updated 1 time since CLSTR started tracking revisions of this situation.

What changed

2026-07-29 05:17 UTC → 2026-08-01 14:47 UTC · added removed

AI‑driven ransomware campaigns now fuse combine rapid credential theft, AI‑generated phishing and impersonation, phishing, and encryption within minutes. Sophos data (July 2026) shows reports 79 % of incidents begin start with compromised identities, and Proofpoint’s 2026 AI‑Era Ransomware Report confirms that Proofpoint finds 65 % of hit organisations victims say AI increased boosted attack success. In the second quarter of Q2 2026 global ransomware incidents rose 3 % from the previous quarter, reaching to 2,229 attacks. The Qilin group led the market attacks, with 301 victims, followed by Qilin, The Gentlemen Gentlemen, DragonForce and DragonForce. Akira accounting for a third of activity. A new “agentic ransomware” variant embeds autonomous AI agents that conduct internal reconnaissance, reconnoitre, adapt to defenses and encrypt assets without external command‑and‑control. C2. Latin America remains a hotspot. Brazil experienced led the sharpest regional increase, with ransomware attacks up 17.8 % region in 2025 – the highest in Latin America. Attackers are targeting hypervisor platforms and destroying backups before encryption in 93 with 17.8 % of incidents. year‑on‑year growth; Mexico reported recorded a 38 % year‑over‑year rise and a 90 % jump in ransomware attacks on businesses, with AI use climbing almost 90 %; use, averaging $1.35 million in recovery costs per breach and 70 % of ransom demands exceed above $1 million and six‑in‑ten affected million. Six‑in‑ten Mexican firms cease operations within six months. Phishing remains the dominant initial‑access technique, now featuring QR‑code campaigns that compromised Microsoft 365 accounts FortiGuard logged 843.3 billion attack attempts across Latin America in Australia. Ransomware accounted for 2025, Brazil the most affected, followed by Mexico and Colombia. Human error drives 67 % of successful breaches, while a shortage of over 20 77,000 qualified cybersecurity professionals hampers response; only 27 % of engagements, often delivered via legitimate remote‑monitoring Mexican companies have specialised protection services. Defensive tactics are also evolving. AI‑enhanced tools such as MeshAgent now automate threat detection, patching and Zoho Assist. attack prediction. Pay‑per‑use models in Spain are democratizing next‑generation firewalls, and insurers pair cyber‑insurance with AI risk assessments. Experts warn that AI‑accelerated vulnerability discovery may make patch‑management the next bottleneck. Policy responses continue: moves include the United Kingdom is UK drafting a ban on ransomware payments by public‑sector bodies, bodies and Brazil’s Army Intelligence Center warns of a strategic Centre flagging an AI‑enabled threat environment, and strategic threat. SMEs are urged to adopt zero‑trust, multi‑factor authentication MFA and offline immutable backups as AI‑augmented ransomware becomes increasingly identity‑driven.

Versions

  1. 2026-08-01 14:47 UTC AI‑enhanced ransomware surge and policy response
  2. 2026-07-29 05:17 UTC AI‑enhanced ransomware surge and policy response

Only revisions since CLSTR began indexing content versions appear here. Select a version to see what changed compared to the one before it.