September 25, 2026

Ransomware Attacks Have Hit a Record High

Ransomware attacks are reaching record levels. Here’s what businesses can do to stay protected

Blog Image

Ransomware isn't slowing down.

In fact, the latest figures suggest that we are actually heading in the opposite direction. According to new analysis from NCC Group, 1,073 organisations were hit by ransomware attacks globally in August 2026. This is the highest monthly figure recorded so far this year.

That's a 12% increase from July, when 973 organisations were affected.

For businesses, the takeaway isn't simply that ransomware is becoming more common. It's that having a plan for what happens if your organisation is attacked is becoming increasingly important.

Ransomware isn't just an IT problem

It's easy to think of ransomware as something that only happens to large organisations with dedicated cybersecurity teams. But that's just not true.

Businesses of all sizes can be targeted, and attackers don't necessarily need to find a sophisticated way into your systems. A compromised account, phishing email, stolen credentials or vulnerable device can provide the perfect opportunity for hackers to get started.

And once attackers are inside, it can already be too late. Files and systems become unavailable, employees may be unable to work, customers could be affected and sensitive information could be stolen. In some cases, attackers don't even need to encrypt your data.

Ransomware is changing

Traditional ransomware attacks involved criminals encrypting a victim's files and demanding payment in exchange for the decryption key. And although that is still happening, the threat has evolved.

Some cybercriminal groups are increasingly focused on stealing data and using it as leverage. Rather than simply locking your systems, attackers can threaten to publish or sell sensitive information if their demands aren't met. This means that having backups is still essential, but backups alone aren't enough. You also need to think about how an attacker could gain access to your systems in the first place, how quickly you could detect suspicious activity and what you would do if sensitive data was stolen.

Which businesses are being targeted?

According to the latest NCC Group figures, the industrial sector accounted for almost a third of reported ransomware incidents in August, at 31%.

Other heavily targeted sectors included consumer goods and services (18%), healthcare (12%), IT (11%) and financial services (6%). It is important to remember that nobody is safe.

So, what can businesses do?

There's no single product that can make you completely ransomware-proof. Businesses need multiple layers of protection that make it harder for attackers to get in, limit what they can do if they do get in, and help you recover if an incident occurs.

Here are a few areas we think are worth checking:

1. Make sure your backups actually work

Backups are one of your most important tools when dealing with ransomware but only if you can recover from them. Don't just assume that your backups are working. Test them regularly and make sure critical data can actually be restored.

2. Keep systems and devices up to date

Unpatched software and outdated devices can leave vulnerabilities that attackers may be able to exploit. Make sure that your operating systems, applications, security software and network devices are being patched and maintained.

3. Protect your accounts

Compromised credentials are an increasingly common route for hackers. Strong passwords, MFA and appropriate access controls can all help reduce the risk of an attacker gaining access to your systems.

It's also worth regularly reviewing who has access to what.

‍

Don't wait for an attack to test your plan

The record levels of ransomware activity are another reminder that cybersecurity isn't something businesses can look at once a year and forget about. Your security needs to evolve alongside the threats you're facing.

The good news is that you don't need to completely overhaul everything overnight. Start by understanding where your biggest risks are, make sure your essential controls are in place and have a clear plan for responding if something does happen because when an attack happens, the worst time to start working out what to do is in the middle of it.

Want to know what a cyberattack actually looks like?

We're taking you behind the scenes in our upcoming webinar, Hacked! What does it actually look like?

We'll demonstrate a cyberattack live, showing how an attacker can move through an environment and what businesses can do to stop them.

Register here!

‍

Recent blogs

DecorationDecoration