What Changed
Global ransomware activity surged dramatically, with August recording the highest incident count of the year. According to findings from Cyble Research and Intelligence Labs (CRIL), 1,034 organisations were publicly named as victims worldwide during the month. This represents a 25% increase from July levels and is nearly double the volume recorded in June.
During August, attacks were attributed to 88 distinct ransomware gangs, averaging roughly 33 claimed victims every single day. CRIL noted that 96 different groups posted claims throughout the month, with the top five most active gangs accounting for 38% of all recorded activity. Rather than relying on breakthrough encryption capabilities, this monthly surge was driven primarily by aggressive affiliate recruitment and the continued exploitation of internet-facing infrastructure.
Context
The sharp escalation in August follows a quieter first half of the year, which led some observers to prematurely assume threat actor momentum was slowing. According to CRIL, that earlier lull was not a sign that ransomware was fading. Instead, gangs were regrouping, and August demonstrated the operational scale of what they regrouped into.
Industry analysts noted that threat actors increasingly relied on operational tactics such as data theft without encryption—exemplified by campaigns like Cl0p’s PTC Windchill campaign—while also reportedly leveraging artificial intelligence to accelerate the speed of their intrusions, though specific performance metrics regarding AI integration remain subject to observation rather than rigorous quantification.
Sector Impact and Regional Distribution
Geographically, the United States bore the brunt of the activity, accounting for 484 victims, or 48% of the worldwide total. Italy followed a distant second with 50 listed victims.
In the Asia-Pacific region, CRIL recorded 143 victims, representing 13% of the global total. India emerged as the most targeted country in the region with 24 claimed victims, placing it seventh globally. Thailand and Taiwan followed closely behind with 17 and 16 victims respectively, while Japan recorded 11. Australia and New Zealand, which are tracked separately by security researchers, recorded a combined 22 victims.
Specific threat groups dominated regional tallies. For instance, The Gentlemen claimed 20 victims in Asia-Pacific, Qilin recorded 16, Krybit logged 13, and orova claimed 12. Notably, Asia-Pacific was identified as the region where Qilin did not lead overall activity.
Industries facing the highest concentration of targeting included manufacturing, professional services, IT and ITES (Information Technology Enabled Services), and healthcare.
Business Implications and Sector Targeting
Attacker pressure points reflect deliberate sector targeting. Manufacturing, professional services, IT and ITES, and healthcare face intense targeting due to the severe risks of operational disruption and the sensitive nature of client data they handle.
Commenting on regional risks, cybersecurity researchers emphasized that organisations should shift their defensive postures away from chasing headlines. Analysts observed that the groups most active in regions like India often maintain little global profile, meaning generic threat intelligence is less effective than rigorous foundational hygiene.
Risks, Limitations, and Recommended Controls
Security researchers have outlined several critical technical limitations and defensive controls to mitigate these risks. Because the August surge was propelled by internet-facing infrastructure vulnerabilities and affiliate recruitment, traditional perimeter security is no longer sufficient.
Recommended technical mitigations include:
- Risk-prioritised patching of all internet-facing systems.
- Phishing-resistant multi-factor authentication for third-party vendors and partners.
- Strict network segmentation to limit lateral movement.
- Tested offline backups to guarantee recoverability without paying ransoms.
- Continuous exposure monitoring.
As threat actors continue to diversify their tactics through extortion-only campaigns and faster intrusion workflows, maintaining visibility over exposed assets remains a core requirement for enterprise security teams.
What to Watch Next
Security analysts will monitor whether the high volumes seen in August persist through the final quarters of the year or represent an aggressive, campaign-specific spike. Organisations are advised to audit their internet-facing assets and verify third-party access controls as global ransomware groups continue to refine their affiliate models.
