Comparitech's quarterly tally puts ransomware claims up 29% on the previous quarter and 61% on a year earlier, but only 247 of the 2,627 were acknowledged by the organizations named. The rest of what defenders know about this quarter comes from the attackers themselves.
Key Takeaways
Ransomware statistics have always had a sourcing problem, and the third quarter of 2026 made it impossible to ignore. Attack volume reached a new high by every count published in the past week. But almost everything known about those attacks comes from the leak sites of the gangs that carried them out, because the organizations on the receiving end overwhelmingly chose to say nothing. For security leaders benchmarking their own risk, that silence is a data point in its own right.
Comparitech's Q3 2026 ransomware roundup logged 2,627 attacks between July and September, against 2,030 in the second quarter and 1,636 in the same quarter of 2025. Every sector it tracks grew. Attacks on businesses rose 27% quarter over quarter to 2,234, government rose 36% to 124, healthcare rose 39% to 188, and education rose 50% to 75. Healthcare's year-over-year rise was 102%. Rebecca Moody, Comparitech's head of data research, said the firm was "seeing significant increases across all key sectors."
The split behind those totals is the more revealing figure. Comparitech labels an attack unconfirmed when a ransomware group claims it but the named organization never acknowledges it, and 2,380 of the quarter's 2,627 attacks fall into that bucket. Government bodies confirmed 53 of their 124, which is closer to half, but businesses confirmed just 138 of 2,234. The researchers note two explanations: gangs sometimes inflate or fabricate claims, and many victims simply decide not to disclose. U.S. breach notification rules force some of those disclosures, but many countries have no equivalent, and the United States alone accounted for 1,066 attacks, 41% of the total.
The confirmation rate tracks how much pressure each sector is under to disclose. Healthcare organizations confirmed 36 of the 188 attacks claimed against them and schools confirmed 20 of 75, both well ahead of private business but still a minority. Even among the two most prolific gangs the pattern holds: Qilin's and The Gentlemen's combined 699 claims produced just 53 confirmations, which means a security team reading the leak sites sees far more of this quarter than one reading breach notices.
That gap distorts more than headlines. The confirmed attacks exposed 1,611,971 records, and Comparitech estimates more than 641 terabytes were stolen across the quarter, yet the incident detail that would help other teams harden their own environments (initial access, dwell time, what failed) is published for only a small fraction of cases.
Within business, manufacturing remained the largest target at 478 attacks, up 22%. The sharper increases came elsewhere: technology firms took 262 attacks, up 70%, and finance took 199, up 72%. Legal and construction were the only sub-sectors to decline. Ransom demands in confirmed cases had a median of $150,000 and an average of $602,400, with the gap driven by outliers such as the $12.3 million demand made of Swiss train maker Stadler Rail.
The gang league table also shifted. Qilin claimed 357 attacks and The Gentlemen 342, but only 27 and 26 of those were confirmed respectively. Clop went from one attack in Q2 to 48 in Q3, while Akira fell 23% and LockBit 51%. Comparitech highlights The Gentlemen's attack on MIP Holdings, where the gang began naming the company's clients on its leak site after the initial ransom was paid, a reminder that payment does not end exposure.
Monthly data points the same way. TechTarget reports NCC Group's August figures: 1,073 publicly reported attacks, up 12% on July's 960, and 83 groups actively claiming victims, against a previous 2026 peak of 70 in June. Industrials accounted for 31% of victims and North America 44%. Alex Pembrey, a senior manager of operational threat intelligence at NCC Group, said it suggested "more actors were conducting operations simultaneously." His colleague Ben Ellis cautioned that AI is "best viewed as an efficiency multiplier rather than a proven primary driver" of the rise.
The few attacks documented in detail are consistent about technique. Check Point Research's October 5 threat intelligence report describes Warlock ransomware operators exploiting SharePoint ToolShell vulnerabilities against utilities, telecom, government, and education organizations, disabling endpoint protection, and then deploying ransomware across more than 33 systems. The same report notes a ransomware attack on South Africa's air navigation provider that reached operational technology supporting aviation weather services.
None of that requires novel tooling. It requires an unpatched public-facing server and an endpoint agent that an intruder with administrative rights can switch off. When nine in ten victims never publish what happened, organizations lose the evidence that would tell them which of those gaps is being used this quarter. The practical response is to build that evidence internally and to plan for a disclosure decision before one is needed.
Ransomware volume set a record this quarter, but the more important number may be the 2,380 attacks nobody confirmed. Until that ratio changes, most defenders are planning against the attacker's version of events.
Whitepaper
With only 247 of 2,627 Q3 attacks confirmed, the incident detail most victims never publish is exactly what is missing. These case studies trace initial access, lateral movement, and the detection failures that let each attack reach encryption.
Download
Report
Warlock's operators switched off endpoint protection before spreading ransomware across more than 33 systems. This report documents the hands-on-keyboard tradecraft and legitimate tool abuse that let intrusions like that move before a signature fires.
Download
Guide
Finance claims rose 72% in Q3 to 199, in a sector where regulators, not victims, set the disclosure clock. This playbook covers incident response timelines and the DORA, SOX, and PCI DSS controls that have to be ready before an attack is claimed.
Download
WatchGuard found endpoint ransomware detections down 68% year over year, even as public extortion claims neared 5,000, a record.
CrowdStrike puts the average eCrime breakout time at 29 minutes, while Mandiant puts median detection dwell time at 14 days.
Median ransom demands have fallen 65% in two years, yet average recovery costs reached $1.7 million.