P.K. SHARMA

Cyber security intelligence, AI governance, practitioner analysis

Q3's record 2,627 ransomware attacks: 247 confirmed by the victim, 2,380 only claimed

Comparitech counts 2,627 ransomware attacks for July to September 2026, a record in its series, and the victim has confirmed 247 (9.4%, derived). Its own page says the rise on Q2 is 29%, not the 27% in news coverage, and its earlier quarters were later revised upward.

By Parminder Kumar Sharma · · 23 min read

A dark pinboard covered in rows of pinned paper index cards, nearly all turned face-down and blank, with a few turned face-up to show blank white faces with empty grey bars. Text on the left reads: 2,627 ransomware claims, 247 confirmed by victims. 9.4% of Q3's claims are confirmed by the victim (247 of 2,627, derived).

2,627 attacks counted, 247 confirmed: the record is mostly claims

Comparitech's Q3 2026 ransomware roundup counts 2,627 attacks for July to September 2026 and calls it the highest quarterly figure to date. Of those, 247 are confirmed by the organisation involved. That is 9.4% (derived: 247 of 2,627). The other 2,380, 90.6%, are attacks that a ransomware group says it carried out and that the organisation has not acknowledged. The headline is a count of claims posted by criminals, with a confirmed minority inside it. Infosecurity Magazine's report of 9 October carries the 2,627 and the 247 and calls the quarter a record for ransomware attacks.

That does not make 90% of the claims false. Comparitech says an attack stays unconfirmed either because the group making the claim is lying or because the organisation chose not to disclose it, and it does not say how many are which. Confirmation also arrives late. Comparitech's 2025 year-end report counted 1,173 confirmed attacks out of 7,419 (15.8%, derived) and said it expected the 2025 confirmed figure to rise. Read the 9.4% as a first count, and the 2,380 as claims of unknown quality: not a list of lies, and not a list of breaches.

Two panels on one scale, from Comparitech chart data. Panel A: 2,627 claims, 247 confirmed (9.4%); business 2,234 claims, 138 confirmed (6.2%); healthcare 188, 36 (19.1%); government 124, 53 (42.7%); education 75, 20 (26.7%). Panel B: Q2 2,030 claims, minus 79 from strains silent in Q3, plus 159 from 68 continuing strains, plus 517 from 37 strains with no Q2 claims (27 confirmed, 5.2%), giving Q3 2,627.
Drawn to scale from the sector and strain chart data on Comparitech's Q3 2026 report page. Panel B is our subtraction from its strain table, not a figure Comparitech prints.

The confirmed share is uneven. In Comparitech's own sector counts, 42.7% of government claims are confirmed (53 of 124), 26.7% of education (20 of 75), 19.1% of healthcare (36 of 188) and 6.2% of business (138 of 2,234). Business is 85.0% of all claims and 88.1% of the unconfirmed ones (all derived from the chart data on the report page). By country the spread is wider, from 59.5% in Japan (22 of 37) to 8.0% in the United Kingdom (6 of 75) and 6.2% in the United States (66 of 1,066). The report does not explain the spread. A low confirmed share in a country probably says how much its organisations disclose, and how fast, rather than how many claims are true (our inference).

A record of what? The friendly name "attacks"

"Attacks" reads as incidents. In Comparitech's method, an attack enters the count when a ransomware group posts a claim on its own site, or when an organisation discloses ransomware. Its tracker page says its researchers search country cyber security reports, news articles and databases, that it has logged unconfirmed claims from 1 April 2023, and that the full source list is available on request. Its quarterly chart starts at Q1 2024. So "record" means the highest number of claims and disclosures this one tracker has logged in a quarter since that chart begins. It does not mean the most successful attacks, or the most damage, or the most victims.

The accurate sentence is "a record number of ransomware claims logged by one tracker". Two other trackers, set out below, say the same about their own series, which is a better basis for repeating it as a fact about claims than one tracker alone. None of them can say the claims are true.

29%, not 27%, and a Q2 that was a dip

Infosecurity prints a 27% rise on Q2 2026. Comparitech's page says 29%: 2,627 against 2,030 is +29.4% (derived). The 27% is on the page too, but it is the rise in business-sector claims, 1,753 to 2,234 (+27.4%, derived). Working back from the printed percentages gives an implied Q2 of 2,036 at 29% and 2,069 at 27%, against the 2,030 on the page: the 29% reconciles and the 27% does not. The same article also lists finance, technology and utilities beside education, healthcare and government as "sectors". In Comparitech's classification the four sectors are business, education, government and healthcare, and finance, technology and utilities are sub-industries of business.

The Q2 base matters. In Comparitech's own series, Q2 2026 was a low quarter: 2,029 claims against 2,240 in Q1, a fall of 9.4% (derived from the chart data, which counts the four sectors only). Measured against Q1, the Q3 figure of 2,621 on the same basis is up 17.0%. The other counts do not show the dip: NCC Group has Q1 at 2,165 and Q2 at 2,229 (+3%), ransomware.live 2,330 and 2,373 (+1.8%, derived), and GuidePoint's figures imply 2,135 and 2,279 (+6.7%, derived). The 29% is measured from a trough that only one of four counts shows.

The 61% on Q3 2025 has its own wrinkle. Comparitech published Q3 2025 on 1 October 2025 with 1,517 attacks, 158 of them confirmed (10.4%). The Q3 2026 page now gives 1,636 for that quarter: 119 more, +7.8% (derived). The page does not say when or why the figure moved; it does say that claims often arrive a month or more after an attack and that a confirmed attack can move into an earlier quarter. Against the figure first printed, the year-on-year rise would be 73.2%. The comparison also sets a one-week-old count against a one-year-old one. If Q3 2026 were revised upward by the same 7.8% it would reach about 2,833 (an illustration, not a forecast). Late claims make a fresh quarter look smaller than it will end up; new groups, covered below, may make it look larger than the underlying activity.

Comparitech counts, first printed against later (derived). The Q1 and H1 "now" figures come from the chart on the Q3 2026 page, which counts the four sectors only and omits claims with no sector, so the true change is at least as large. June 2026 has no monthly roundup on the site: its 668 is quoted in the July roundup of 5 August.

Period (first print date)First printedNowChange
Q3 2025 (1 Oct 2025)1,5171,636+119 (+7.8%)
Q1 2026 (8 Apr 2026)2,2002,240 or more+40 or more (+1.8%)
H1 2026 (2 Jul 2026)4,2174,269 or more+52 or more (+1.2%)
Q2 2026: no quarterly report; April 628, May 661, June 6681,9572,030+73 (+3.7%)
March 2026 (roundup updated 1 Apr 2026)780805+25 (+3.2%)

There is no Q2 2026 roundup to quote. Comparitech went from monthly reports for April and May to a half-year report on 2 July, which gives no Q2 figure of its own. The nearest first prints are its three months, which sum to 1,957, and the half-year figure of 4,217 less the Q1 first print of 2,200, which leaves at most 2,017 for Q2 on 2 July (derived; Q1 may already have been revised by then). Both sit below the 2,030 the Q3 report now gives for Q2. Counts in this series rise after first print, by 1% to 8% in the periods above, and the 2025 sector figures rose 2.0% between the January year-end report and the chart on the Q3 2026 page (derived). The page does not say when any change was made. The dated evidence is month by month: April was 628 on 5 May and 640 on 4 June, and July was 799 on 5 August and 809 on 8 September, so a month's count had grown 1.3% to 1.9% within a month. The only safe reading is that a period's count was higher, by up to 8%, when the next report came out, and that the Q3 2026 count will probably be restated upward too (our inference).

Stated and not stated in the method

Comparitech's report page has no methodology section beyond one paragraph on "confirmed" and "unconfirmed". Its tracker page and earlier reports add a little. The table sets what they say against what a reader needs.

What Comparitech states, and what it does not, from its Q3 2026 report page, its worldwide tracker page and its H1 2026 and 2025 year-end reports.

QuestionStatedNot stated
What is "confirmed"?The organisation discloses an attack involving ransomware, or acknowledges a cyber attack that coincides with a group's claim.How many of the 247 are the second kind, a match by timing. Whether any was ever posted on a leak site: the strain table has 59 "Unknown" attacks, all confirmed.
What is a claim?A group posts that it attacked an organisation, on its own site.Whether duplicates and re-posts are removed. The page does not mention duplicates.
Where do claims come from?Country reports, news and security databases; unconfirmed claims logged since 1 April 2023.Which leak sites, and when any were added. The source list is available on request.
Is the count final?Late claims arrive a month or more after an attack; a confirmed attack can move to an earlier quarter.When a quarter is frozen. Our revision table shows prior quarters rising by 1% to 8%.
How are sectors assigned?Four sectors, and eleven business sub-industries.How an attack is assigned. The eleven sub-industries sum to 2,010 of 2,234 business claims (derived); 224 are not placed.
What is the $602,400 average?Average $602,400 and median $150,000 for the quarter.How many attacks have a known demand, and whether the average covers all attacks or only confirmed ones.
Is AI or triple extortion measured?Nothing on either in the published page.Any count. Infosecurity attributes the triple extortion line to the report and a quoted comment, and adds the AI line itself.

The demand figure deserves its own paragraph. The page gives a median of $150,000 and an average of $602,400: the average is 4.0 times the median (derived), which means a few very large demands pull it up. The five largest demands total $16.5 million, led by $12.3 million made to a Swiss rail manufacturer that refused to pay. For those five to fit inside an average of $602,400, at least 28 attacks must have a known demand (derived), but the page does not say how many. Comparitech notes that most organisations and groups do not disclose demands, and that one group dominates its top five largely because it is one of few that publish them. So the average mostly describes the groups that publish demands. It is not an estimate of what a typical victim is asked, and a demand is not a payment. GuidePoint's own negotiation sample for Q3 had 29 engagements, a payment rate that fell to just under 21% (6 of 29, derived) and an average payment of $321,000, in a sample it says leans toward organisations more willing to consider paying.

How much of the rise is new groups, and how small are the bases

Comparitech's strain table (its term for a group or variant) is embedded in the report as a chart. It lets us split the net rise of 597 claims, and the figures in this paragraph are our derivation from it. Thirty-seven strains with no claims in Q2 supply 517 of Q3's claims (19.7%), and 27 of those are confirmed (5.2%). The 68 rows present in both quarters (67 named strains plus the table's "Unknown" row) went from 1,951 to 2,110 claims, +159 or +8.1%, with 10.4% confirmed. The remaining 79 of Q2's 2,030 claims belong, by our inference, to strains that do not appear in the Q3 table at all (2,030 less the table's Q2 column of 1,951; the table lists only strains with a Q3 claim). So 2,030, less 79, plus 159, plus 517 is 2,627, and 86.6% of the net rise comes from strains with no Q2 history in this table. The established strains together grew 8.1%.

A strain with no Q2 claims is not necessarily a new group. It could be a rebrand, a group Comparitech began tracking in Q3, or a group that was quiet. The cross-check is partial. For 24 of the 37 (436 of the 517 claims) the name matches a group that ransomware.live lists as first seen in 2026: 23 of them in July to September, one on 9 June (ransomware.live statistics page; the name match is ours). NCC Group's July review warned that one new group's 36 claimed victims were not yet credible, and that new groups commonly exaggerate their activity to look threatening. The claims from the 37 strains are confirmed at about half the rate of the rest, 5.2% against 10.4%. Newer claims have had less time to be confirmed, so that is not evidence of falsehood either. It is a reason to count them separately.

Two strains alone went from 1 and 4 claims in Q2 to 48 and 62 in Q3: 105 claims, 17.6% of the net rise. GuidePoint's Q3 report ties the strain that went from 1 to 48 to a campaign against a single enterprise software product, with about 71 postings by late September. One flaw in one product, posted as many victims, is a single cause moving a whole quarter.

Sector rises as printed, with the claims behind them (Comparitech chart data; the Q2 to Q3 percentages are Comparitech's, the added claims are derived). Finance, technology and utilities are sub-industries of business.

GroupQ2 to Q3 claimsRiseClaims added
Finance116 to 199+72%83
Technology154 to 262+70%108
Education50 to 75+50%25
Healthcare providers135 to 188+39%53
Government91 to 124+36%33
Utilities22 to 29+32%7

Finance and technology together add 191 claims, 32.0% of the net rise, and both sit inside business, where only 6.2% of Q3 claims are confirmed (in the H1 2026 report, technology was 9.3% confirmed and finance 8.6%). Their Q2 bases were low: finance's 116 was below its 139 in Q3 2025, so its rise on a year earlier is 43.2%, against 71.6% on the quarter. The utilities "32%" is seven more claims over a quarter. Legal fell 25.6% (31 fewer claims) and construction 2.2%. None of this says the sectors are not being targeted. It says a percentage on a base of 22 to 154 can move on a handful of postings, and that the confirmed record behind the biggest rises is thin.

Three other counts of the same quarter

Comparitech is one tracker. We read GuidePoint's GRIT Q3 2026 report, ransomware.live's statistics page and NCC Group's monthly reports for the same quarter. They read the same public postings by criminals, so agreement shows the trackers see the same sites, not that the claims are true. They are independent in method, coverage and how they remove duplicates: GuidePoint says it reviews its data for duplicates and inaccuracies and adjusts it, excludes groups that call themselves hacktivists and compromised data brokers, and includes data-extortion groups that never encrypt.

Each tracker's latest count of its own series, read on 9 October 2026. GuidePoint's percentages are as printed; the others are derived. NCC Group has no Q3 report yet; its Q2 and monthly figures are shown.

Tracker and what it countsQ2 and Q3 2026Rise on Q2Rise on Q3 2025
Comparitech: claims by groups plus attacks disclosed by victims2,030 and 2,627+29.4%+60.6% (from 1,636)
GuidePoint GRIT: victims claimed by 112 groups, reviewed for duplicates2,279 and 2,760+21.1%+75.3% (from 1,574)
ransomware.live: victims posted on monitored leak sites2,373 and 2,969+25.1%+77.4% (from 1,674)
NCC Group: recorded ransomware attacks, monthlyQ2 2,229; August 1,073not publishednot published

On direction they agree: Comparitech calls Q3 2026 its highest quarter, GuidePoint describes record-setting victim volumes, and ransomware.live's quarterly series shows 2,969 against a previous high of 2,436 in Q4 2025. That is two counts besides Comparitech's, enough to repeat "record claim volume" as a fact about claims. On size they do not agree: the highest Q3 count is 13.0% above the lowest, the rise on Q2 runs from 21.1% to 29.4% and the rise on Q3 2025 from 60.6% to 77.4%. On the month they split. NCC Group's own record month is 1,099 in February 2025, above its 1,073 for August 2026, so NCC does not call August a record, while Comparitech's 997 for August passes its own February 2025 record of 988.

Each source sells something, and each is treated the same here. Comparitech's pages say it may earn a commission when readers buy through its links, and its ransomware research sits on a site that reviews VPN and antivirus products. GuidePoint sells incident response, negotiation support and threat intelligence, and its report counts 29 negotiation engagements of its own in Q3. NCC Group sells managed security, threat intelligence and incident response services, and its monthly report carries a subscription link. ransomware.live is a free service that asks readers for support and carries a sponsor banner from an infostealer intelligence vendor. Sysdig, whose July research the AI line rests on, sells cloud security. None of that makes a number wrong. It is why no one of them should be the only count in a board paper.

The AI line and the triple extortion line

Infosecurity offers AI as a possible explanation for the surge and cites a July campaign. Comparitech's published page does not mention AI, so the link between the two is the news article's, not the tracker's. The July campaign rests on research by Sysdig, a cloud security vendor, posted on 1 July 2026 and reported by Infosecurity on 6 July as what Sysdig claims is the first ransomware campaign driven entirely by a large language model. GuidePoint's Q3 report says the first end-to-end agentic ransomware cases have appeared on a small scale, and also that AI is not yet running the underlying business: targets, negotiation and payment stay human. NCC Group's July review says part of July's rise was driven by AI advances, calls the same campaign the first known fully autonomous end-to-end AI-driven agent, and adds that such attacks so far appear motivated less by money than by showing what the technology can do. None of the three trackers publishes a count of AI-assisted claims, and one campaign cannot account for a rise of 597 claims. This briefing prints no technical detail of that campaign.

Triple extortion, where the attacker also presses the victim's customers, is described by Infosecurity as a trend the report highlighted. The published roundup page does not contain the term. The evidence in hand is one example, a South African technology company whose clients were added to a leak site after it paid, quoted in the article from a Comparitech comment. There is no count. The risk itself is well attested: the NCSC's guidance on ransom payments, written with three insurance trade bodies in May 2024, warns that after paying, a victim may find the attacker lied about deleting the data and may repeat the threat months or years later. A supplier's incident can put your customers' data on a criminal's site, and your first notice may come from a post rather than from the supplier.

What a UK board does with a quarterly claim count

Start with the UK's own figures. Comparitech's country chart gives the United Kingdom 75 claims in Q3, 2.9% of the total, 6 of them confirmed (8.0%). That compares with 74 in Q2 (+1.4%) and 82 in Q1 2026, so the UK did not follow the headline: 75 claims over 92 days is under one a day (derived). The NCSC counts something different, incidents it handled: 429 in the 12 months to August 2025, 204 of them nationally significant, up from 89 (Annual Review 2025, 14 October 2025). We did not find a 2026 edition on 9 October.

The prevalence check is the government's own survey. The Cyber security breaches survey 2025/2026 (published 30 April 2026, fieldwork August to December 2025, 2,112 businesses) found 1% of businesses reporting devices targeted with ransomware in the last 12 months, down from 3% in each of the previous two surveys, with 7% of large and 3% of medium businesses. A survey of UK organisations that noticed an attack and a worldwide tracker of criminals' postings answer different questions, and neither measures a particular organisation's exposure. That is set by what faces the internet, how identity is protected and which suppliers hold your data. On those suppliers the survey is blunt: 15% of businesses reviewed the risks of their immediate suppliers and 6% looked at their wider supply chain. And on payment: 49% of businesses had a rule or policy not to pay ransomware demands, while 24% did not know what their policy was.

The NCSC's position is plain. It says it and UK law enforcement "do not encourage, endorse nor condone the payment of ransom demands", and that organisations should keep a recent offline backup. Its payment guidance, written with the ABI, BIBA and the IUA in May 2024, says to review alternatives including not paying, to record decisions offline, to check the legal position, including sanctions, and notes that the ICO does not treat paying criminals as risk mitigation or as reducing a penalty. The ICO's breach guide requires a notifiable personal data breach to reach it within 72 hours of the organisation becoming aware, where feasible, and requires a processor to tell its controller without undue delay, with the reporting terms set in the contract. If a supplier that holds your customers' data is named on a leak site, the questions are whether the contract makes the supplier tell you, in how many hours, and what counts as awareness for you when the first sign is a criminal's post. That is a question for your data protection officer or a lawyer, and the ICO page does not answer it.

The payment proposals are still proposals on the gov.uk page. The Home Office consultation page (first published 14 January 2025, government response published 22 July 2025) still showed its last update as 2 September 2025 when read on 9 October 2026. It sets out three proposals and nothing the page calls law. We also searched the text of the Cyber Security and Resilience Bill as amended in Grand Committee (7 September 2026, Lords report stage scheduled for 26 October on Parliament's tracker): the word ransomware does not appear in it. It has its own incident notification clock, 24 hours for an initial notification and 72 hours for a full one, for the operators it covers. A private member's bill on reporting ransomware attacks was last updated on 1 May 2026, at Commons second reading.

The three ransomware proposals as set out in the Home Office consultation outcome of 22 July 2025, and what each would and would not change (our reading). Proposals, not law, as read on 9 October 2026.

ProposalWould changeWould not change
Ban on payments by public sector bodies, including local government, and by regulated critical national infrastructure owners and operatorsRemoves the decision to pay for those bodies. Scope, penalties and supply chains are still to be settled.Does not stop groups posting claims or verify them. Whether suppliers are covered is open.
Payment prevention regime: report an intent to pay, government reviews, may block on sanctions or terrorist finance groundsGives government sight of intended payments and a power to stop some. It does not approve payments.Leaves the decision with the victim if not blocked. The response says government does not advise paying.
Mandatory reporting: initial report within 72 hours, fuller report within 28 days (as consulted); 72 hours kept as the suggested timeframeWould build official data on ransomware incidents, a count of the kind this briefing lacks (our inference).Would not tell you of a supplier being claimed against. The response text does not mention leak sites.

The Early Warning service is free to UK organisations and sends alerts on malicious activity tied to the public IP addresses and domains you register. The page we read does not say it alerts you when your name, or a supplier's, appears on a criminal's site, so it is not a substitute for leak-site monitoring.

What to do, in order

Take this with you

Actions in the order worth doing

  • Use the claim count as a prompt for a conversation and not as a risk estimate. Your exposure is set by your edge devices, identity controls and suppliers, not by the quarter total.
  • Never put one tracker's total in a board paper. Quote two counts and the confirmed share beside them, and say "claims" and not "attacks".
  • Ask every critical supplier whether it has ever been named on a leak site, how you would hear of it, and in how many hours it commits to tell you.
  • Read your contracts for notification terms when a supplier is claimed against. Check they cover an unverified claim by a criminal and not only a confirmed breach, and that they state hours, not "promptly".
  • Set up monitoring for your own name and your suppliers' names on leak sites through a legitimate monitoring service or your incident response provider. Name who reads the alert out of hours.
  • Write down who decides a claim is credible, who may speak publicly, and when the ICO 72 hour clock is treated as started. Do not contact the group and do not download leaked data to check it.
  • Rehearse the decision on paying with the board before it is needed, including the sanctions position and whether the proposed public sector and infrastructure ban would apply to you.
  • Check backups are offline, separate from the network and tested by restoring, as the NCSC advises.
  • Register your public IP addresses and domains with NCSC Early Warning, and agree an NCSC-assured incident response provider before an incident.
  • Re-run the supplier question every quarter. Put the answers in the risk register next to the count that prompted them.

The question that exposes the gap

If a criminal group listed one of your suppliers tomorrow with a claim about your customers' data, how would you find out, who in your organisation would be allowed to decide the claim was true, and how many of your 72 hours would be gone by then?

That is the gap a record count cannot show: a tracker can say how many claims were posted, but not whether yours is among them or whether anyone has told you. The earlier briefings on how victims are told after a leak site is seized, a rail operator that confirmed an attack hours after its forms went unreadable and what a ransomware recovery firm is alleged to have charged show the same gap from three sides.

Sources

  1. PrimaryRansomware roundup: Q3 2026, read in full and as HTML with its seven embedded chart datasets: 2,627 attacks, 247 confirmed, 2,030 for Q2, 1,636 for Q3 2025, sector, strain and country tables, definition of confirmed. Published 6 October 2026, updated 7 October. Comparitech is the tracker and may earn commissions from reader purchases.Comparitechaccessed 2026-10-09
  2. PrimaryWorldwide ransomware tracker page: methodology paragraph (sources searched, unconfirmed claims logged from 1 April 2023, source list on request).Comparitechaccessed 2026-10-09
  3. PrimaryRansomware roundup: Q3 2025, published 1 October 2025: 1,517 attacks, 158 confirmed, 1,434 for Q2 2025. Used for the first-print comparison.Comparitechaccessed 2026-10-09
  4. PrimaryRansomware roundup: Q1 2026, published 8 April 2026: 2,200 attacks, 193 confirmed, United Kingdom 82.Comparitechaccessed 2026-10-09
  5. PrimaryRansomware roundup: H1 2026, published 2 July 2026: 4,217 attacks, 484 confirmed, technology and finance counts with confirmed numbers.Comparitechaccessed 2026-10-09
  6. PrimaryWorldwide ransomware roundup: 2025 end-of-year report, published 12 January 2026: 7,419 attacks, 1,173 confirmed, expectation that confirmed figures rise.Comparitechaccessed 2026-10-09
  7. PrimaryRansomware roundup: April 2026, published 5 May 2026: 628 attacks. The May roundup restates April as 640.Comparitechaccessed 2026-10-09
  8. PrimaryRansomware roundup: May 2026, published 4 June 2026: 661 attacks; April restated as 640.Comparitechaccessed 2026-10-09
  9. PrimaryRansomware roundup: July 2026, published 5 August 2026: 799 attacks in July, 668 in June, 805 for March.Comparitechaccessed 2026-10-09
  10. PrimaryRansomware roundup: August 2026, published 8 September 2026: 997 attacks in August, July restated as 809, February 2025 record of 988.Comparitechaccessed 2026-10-09
  11. PrimaryGRIT Q3 2026 Ransomware and Cyber Threat Insights report, read in full with pypdf: 2,760 victims, 112 groups, Q2 2,279, Q3 2025 1,574, methodology, negotiation data (29 engagements), the agentic ransomware section. GuidePoint sells incident response, negotiation and threat intelligence.GuidePoint Securityaccessed 2026-10-09
  12. PrimaryStatistics page, updated 9 October 2026 17:20 UTC: victims per month and per quarter 2023 to 2026, new groups in 2026 with first-seen dates. A free tracker with paid API tiers and a vendor sponsor banner.ransomware.liveaccessed 2026-10-09
  13. PrimaryMonthly Threat Pulse, review of June 2026, published 22 July 2026: Q1 2,165 to Q2 2,229, June 665. NCC Group sells security services.NCC Groupaccessed 2026-10-09
  14. PrimaryMonthly Threat Pulse, review of July 2026: 894 cases in July, record month 1,099 in February 2025, warning about a new group's claims, AI statement.NCC Groupaccessed 2026-10-09
  15. PrimaryCyber Threat Intelligence reports page, August 2026 key insights: 1,073 attacks, +12% on July.NCC Groupaccessed 2026-10-09
  16. PrimaryConsultation outcome page: published 14 January 2025, response 22 July 2025, last updated 2 September 2025, unchanged when read on 9 October 2026.Home Office, GOV.UKaccessed 2026-10-09
  17. PrimaryGovernment response to the ransomware legislative proposals, read in full as HTML: the ban, the payment prevention regime, mandatory reporting at 72 hours and 28 days, scope and supply chain questions.Home Office, GOV.UKaccessed 2026-10-09
  18. PrimaryCyber security breaches survey 2025/2026, published 30 April 2026: 2,112 businesses, ransomware 1%, ransomware payment policy, supplier reviews.DSIT, GOV.UKaccessed 2026-10-09
  19. PrimaryCyber Security and Resilience (Network and Information Systems) Bill, read through the Parliament Bills API on 9 October 2026: Lords report stage scheduled 26 October 2026; HL Bill 49 text searched for ransomware and notification periods.UK Parliamentaccessed 2026-10-09
  20. PrimaryCyber Extortion and Ransomware (Reporting) Bill, a private member's bill at Commons second reading, last updated 1 May 2026, read through the Bills API.UK Parliamentaccessed 2026-10-09
  21. PrimaryWhat you need to know about ransomware: do-not-pay position, offline backup, assured incident response, Early Warning.NCSCaccessed 2026-10-09
  22. PrimaryGuidance for organisations considering payment in ransomware incidents, version 1.0 of 14 May 2024, written with ABI, BIBA and IUA, read in full.NCSCaccessed 2026-10-09
  23. PrimaryMitigating malware and ransomware attacks: offline backup advice.NCSCaccessed 2026-10-09
  24. PrimaryEarly Warning service page: free alerts tied to registered IP addresses and domains.NCSCaccessed 2026-10-09
  25. PrimaryAnnual Review 2025 news release, 14 October 2025: 429 incidents handled, 204 nationally significant, up from 89.NCSCaccessed 2026-10-09
  26. PrimaryPersonal data breaches: a guide: 72 hours of becoming aware, processor duty to inform the controller without undue delay.ICOaccessed 2026-10-09
  27. PrimarySysdig Threat Research Team post of 1 July 2026 (modified 30 July), opened to attribute the claim of a first LLM-driven ransomware campaign: publisher and date only, no technical detail reproduced. Sysdig sells cloud security.Sysdigaccessed 2026-10-09
  28. Reported byNews report of 9 October 2026 that the briefing starts from: 2,627, 247, a 27% rise on Q2, sector percentages, AI and triple extortion lines. Secondary; checked against the Comparitech page.Infosecurity Magazineaccessed 2026-10-09
  29. Reported byNews report of 6 July 2026 on a cloud security vendor's claim of the first ransomware campaign driven entirely by a language model. Used only to attribute the claim.Infosecurity Magazineaccessed 2026-10-09
  30. Reported byNews report on NCC Group's August 2026 figure of 1,073, which prints a July base that does not match the 12% rise on the NCC page. Secondary.Infosecurity Magazineaccessed 2026-10-09
  31. Reported byEarlier briefing on how victims are told after a leak site is seized; linked rather than restated.pk-sharma.comaccessed 2026-10-09
  32. Reported byEarlier briefing on the gap between an attack and its confirmation; linked rather than restated.pk-sharma.comaccessed 2026-10-09
  33. Reported byEarlier briefing on ransomware recovery fees; linked rather than restated.pk-sharma.comaccessed 2026-10-09

Share this briefing

Know someone who owns this problem? Send it to them.

Related briefings

The briefing, in your inbox

Practitioner analysis of cyber and AI security news. No vendor noise.

How often

Every new briefing in one email, at 7am, or at 7am, 12:30pm and 6pm. Nothing is sent when nothing is new. Unsubscribe any time.