August's ransomware activity hit new high for the year

NCC Group identified 83 ransomware groups active last month, but it said AI wasn't necessarily what drove the increase in the number of bad actors.

Ransomware activity reached its highest monthly level of 2026 in August, but the underlying security problem extends beyond attackers developing new capabilities.

The latest figures from the security firm NCC Group indicate that organizations are still struggling to restrict access across interconnected systems, update infrastructure without disrupting operations and contain intrusions before stolen credentials become a business-wide crisis.

NCC Group recorded 1,073 publicly reported ransomware attacks in August, up approximately 12% from July's 960 attacks. Industrials accounted for 31% of recorded attacks, while North America and Europe represented 44% and 26% of global attacks, respectively. Qilin, a ransomware cybercrime operation formed in 2022, led the August rankings with 15% of recorded attacks.

The figures do not establish that security investments are ineffective. Rather, they reveal ongoing opportunities for attackers across an unevenly protected market. While defenders struggle to maintain controls across legacy infrastructure, cloud services and identities, an attacker simply needs to find an opening and secure enough access to exploit it.

What the increase measures

Alex Pembrey, senior manager of operational threat intelligence at NCC Group, emphasized the figures cover publicly reported attacks. Incidents kept off criminal leak sites through payment or other circumstances remain outside that view.

Nevertheless, he said he considers August's increase as evidence of a more active threat landscape, with 83 ransomware groups publicly claiming victims during the month, up from the previous 2026 peak of 70 recorded in June.

"This suggests more actors were conducting operations simultaneously, with both established groups and newer entrants contributing to the overall volume," Pembrey said.

He pointed to the professionalization of ransomware-as-a-service (RaaS), including readily available encryption capabilities and support for negotiations  as factors that lower entry barriers.

Why patching remains difficult

Pembrey said that for industrial organizations, labeling the problem simply as a patching failure overlooks operational constraints. For example, equipment may depend on older software. Maintenance requires coordination, testing and confidence that production can resume safely after an update.

"Downtime to patch, update operating systems, make changes, and, importantly, check everything works as intended is expensive and often planned out months or years in advance," he said.

That mismatch creates a window of opportunity for attackers.

Pembrey also identified shared IT and operational technology accounts, as well as insufficient network separation, as recurring weaknesses. An intrusion into corporate systems can serve as a route to operational assets with inadequate.

His recommendation is to engineer critical industrial systems to operate safely when disconnected from corporate networks or the internet. This means organizations must understand dependencies and rehearse how isolation affects production.

The identity problem behind remote access

In a more advanced threat landscape, fixing a vulnerable VPN doesn't eliminate the danger if an attacker already possesses usable credentials or retains access elsewhere.

Shane Barney, CISO at Keeper Security, a cloud-based cybersecurity platform, said that broad remote access and persistent administrative privileges provide intruders with avenues for disruption.

"Organizations need to eliminate standing privileges through just-in-time access, segment IT and OT networks, and deploy phishing-resistant authentication on all remote access points," Barney said.

James Maude, field CTO at BeyondTrust, an enterprise access management company, similarly argues that ransomware prevention depends on reducing the permissions an attacker can acquire.

"Ransomware and other threats are only as effective as the privileges and access they manage to acquire, so if we can implement better hygiene and focus on least privilege, then the threat actors are far less likely to ransomware us in the first place," he said.

Security teams need to know which accounts can access critical systems, whether that access is necessary and how quickly compromised privileges can be revoked.

AI accelerates existing workflows

The continued evolution of AI adds pressure to defenders, but NCC's evidence does not explicitly attribute August's increase primarily to autonomous attacks.

Ben Ellis, a threat intelligence analyst at NCC Group, cited reporting that indicated that the Aurora ransomware group used Cursor Agent, running a Claude model, to assist with network scanning, privilege enumeration, New Technology LAN Manager, or NTLM, relay attempts and certificate-related attacks. Those activities suggest assistance with established intrusion workflows rather than the replacement of skilled operators.

"AI is best viewed as an efficiency multiplier rather than a proven primary driver of the month's increase," he said.

That distinction matters for spending decisions. AI-assisted exploitation can increase the urgency of closing exposed entry points, but it does not diminish the importance of authentication, segmentation and monitoring.

When setting patch priorities, Ellis said he recommends combining vulnerability severity with evidence of active exploitation and the importance of affected assets. A numerical severity score alone does not indicate which exposed weakness an attacker is most likely to exploit, he said.

Nathan Eddy covers IT trends and technologies across multiple industries. Eddy is a graduate of Northwestern University's Medill School of Journalism.