Security

Ransomware Hit a Record 2,627 Attacks in Q3, and Fewer Than 1 in 10 Victims Ever Confirmed It

Comparitech's quarterly tally puts ransomware claims up 29% on the previous quarter and 61% on a year earlier, but only 247 of the 2,627 were acknowledged by the organizations named. The rest of what defenders know about this quarter comes from the attackers themselves.

October 7, 2026 · Security
A large security operations centre with analysts at rows of monitors in front of a wall of blue video screens

Key Takeaways

  • Comparitech recorded 2,627 ransomware attacks in Q3 2026, about 29 a day, up 29% on Q2 and 61% on Q3 2025, the highest quarterly total it has logged.
  • Only 247 of those attacks were confirmed by the organization named. Among businesses, 138 confirmed against 2,096 that never acknowledged a claim, roughly 1 in 16.
  • Finance claims rose 72% to 199 and technology claims rose 70% to 262, while the median ransom demand in confirmed attacks was $150,000 and the average $602,400.
  • NCC Group counted 1,073 attacks in August alone, up 12% on July, from 83 active groups, with industrials taking 31% of victims and Qilin leading with 15%.

Ransomware statistics have always had a sourcing problem, and the third quarter of 2026 made it impossible to ignore. Attack volume reached a new high by every count published in the past week. But almost everything known about those attacks comes from the leak sites of the gangs that carried them out, because the organizations on the receiving end overwhelmingly chose to say nothing. For security leaders benchmarking their own risk, that silence is a data point in its own right.

A Record Quarter Built Mostly on Unverified Claims

Comparitech's Q3 2026 ransomware roundup logged 2,627 attacks between July and September, against 2,030 in the second quarter and 1,636 in the same quarter of 2025. Every sector it tracks grew. Attacks on businesses rose 27% quarter over quarter to 2,234, government rose 36% to 124, healthcare rose 39% to 188, and education rose 50% to 75. Healthcare's year-over-year rise was 102%. Rebecca Moody, Comparitech's head of data research, said the firm was "seeing significant increases across all key sectors."

The split behind those totals is the more revealing figure. Comparitech labels an attack unconfirmed when a ransomware group claims it but the named organization never acknowledges it, and 2,380 of the quarter's 2,627 attacks fall into that bucket. Government bodies confirmed 53 of their 124, which is closer to half, but businesses confirmed just 138 of 2,234. The researchers note two explanations: gangs sometimes inflate or fabricate claims, and many victims simply decide not to disclose. U.S. breach notification rules force some of those disclosures, but many countries have no equivalent, and the United States alone accounted for 1,066 attacks, 41% of the total.

The confirmation rate tracks how much pressure each sector is under to disclose. Healthcare organizations confirmed 36 of the 188 attacks claimed against them and schools confirmed 20 of 75, both well ahead of private business but still a minority. Even among the two most prolific gangs the pattern holds: Qilin's and The Gentlemen's combined 699 claims produced just 53 confirmations, which means a security team reading the leak sites sees far more of this quarter than one reading breach notices.

That gap distorts more than headlines. The confirmed attacks exposed 1,611,971 records, and Comparitech estimates more than 641 terabytes were stolen across the quarter, yet the incident detail that would help other teams harden their own environments (initial access, dwell time, what failed) is published for only a small fraction of cases.

Finance and Technology Absorbed the Fastest Growth

Within business, manufacturing remained the largest target at 478 attacks, up 22%. The sharper increases came elsewhere: technology firms took 262 attacks, up 70%, and finance took 199, up 72%. Legal and construction were the only sub-sectors to decline. Ransom demands in confirmed cases had a median of $150,000 and an average of $602,400, with the gap driven by outliers such as the $12.3 million demand made of Swiss train maker Stadler Rail.

The gang league table also shifted. Qilin claimed 357 attacks and The Gentlemen 342, but only 27 and 26 of those were confirmed respectively. Clop went from one attack in Q2 to 48 in Q3, while Akira fell 23% and LockBit 51%. Comparitech highlights The Gentlemen's attack on MIP Holdings, where the gang began naming the company's clients on its leak site after the initial ransom was paid, a reminder that payment does not end exposure.

Monthly data points the same way. TechTarget reports NCC Group's August figures: 1,073 publicly reported attacks, up 12% on July's 960, and 83 groups actively claiming victims, against a previous 2026 peak of 70 in June. Industrials accounted for 31% of victims and North America 44%. Alex Pembrey, a senior manager of operational threat intelligence at NCC Group, said it suggested "more actors were conducting operations simultaneously." His colleague Ben Ellis cautioned that AI is "best viewed as an efficiency multiplier rather than a proven primary driver" of the rise.

What the Disclosed Cases Show About How Attacks Land

The few attacks documented in detail are consistent about technique. Check Point Research's October 5 threat intelligence report describes Warlock ransomware operators exploiting SharePoint ToolShell vulnerabilities against utilities, telecom, government, and education organizations, disabling endpoint protection, and then deploying ransomware across more than 33 systems. The same report notes a ransomware attack on South Africa's air navigation provider that reached operational technology supporting aviation weather services.

None of that requires novel tooling. It requires an unpatched public-facing server and an endpoint agent that an intruder with administrative rights can switch off. When nine in ten victims never publish what happened, organizations lose the evidence that would tell them which of those gaps is being used this quarter. The practical response is to build that evidence internally and to plan for a disclosure decision before one is needed.

Ransomware volume set a record this quarter, but the more important number may be the 2,380 attacks nobody confirmed. Until that ratio changes, most defenders are planning against the attacker's version of events.

Share

More in Security

All Resources →