The Story This Month
Critical infrastructure is firmly in the crosshairs: this period delivered a landmark Iranian cyberattack on British soil, a sustained hacktivist blitz that hammered Romanian government services, and 1,268 recorded incidents spanning ransomware, mass data theft, and relentless DDoS campaigns worldwide.

By the Numbers
- 1,268 total attacks recorded globally over the 30-day period
- 456 incidents categorised as data leak or exfiltration, making it the single largest attack category this period
- 421 ransomware incidents, confirming encryption-based extortion remains a dominant and growing threat
- 83 attacks attributed to NoName057(16), cementing its position as the most prolific threat actor for the second consecutive period
- 315 attacks targeted the United States, accounting for roughly one in four of all recorded incidents worldwide
- 54.1% period-on-period drop in total recorded attacks, reflecting a sharp contraction from the prior period's 2,761 incidents
What Changed
| Category | This Period | Prior Period | Change |
|---|---|---|---|
| Total Attacks | 1,268 | 2,761 | -54.1% |
| No. 1 Threat Actor | NoName057(16) (83 attacks) | NoName057(16) (195 attacks) | Volume down 57%, rank held |
| No. 1 Country | United States (315 attacks) | United States (506 attacks) | Volume down 37.7%, rank held |
| No. 1 Sector | Professional and Technical Services (263 attacks) | Professional and Technical Services (625 attacks) | Volume down 57.9%, rank held |
| No. 1 Attack Category | Data Leak / Exfiltration (456) | Data Leak / Exfiltration (1,272) | Volume down 64.1%, rank held |
The headline number demands context. A 54.1% drop in recorded attacks against the prior period does not signal a quieter threat environment. The top ranks held with striking consistency: the same leading threat actor, country, sector, and attack category occupied first place in both periods. What changed was volume, not composition. The threat landscape compressed rather than transformed.
The most meaningful shift sits at the category level. Data leak and exfiltration retained its top position, but ransomware's share of the total actually grew proportionally, climbing from roughly 26.5% of all prior-period attacks to 33.2% this period. DDoS activity also maintained a significant presence with 283 incidents, despite the overall volume drop. Hacktivist groups driving DDoS campaigns, particularly NoName057(16) and Dark Storm Team, kept up sustained pressure on European targets even as total incident counts fell.
Country-level shifts reveal an interesting reshaping of the target map. Romania surged to second place this period with 111 attacks, up from outside the prior period's top ten. France slipped from second to third, whilst Germany and Thailand, which ranked third and fifth previously, dropped entirely out of the top ten. Romania's rise is almost entirely DDoS-driven, with 104 of its 111 incidents in that category, reflecting a focused hacktivist campaign against Romanian government and public services infrastructure. Meanwhile, the emergence of Niue in fifth position, driven largely by CL0P ransomware activity, is a statistical artefact of attackers using offshore-registered domains rather than a genuine geographic concentration of victims.
Notable Incidents
Ukraine: Asset Recovery and Management Agency (ARMA)
Ukraine's Asset Recovery and Management Agency was struck twice within 24 hours in mid-August, with separate incidents recorded on 18 and 17 August. The second incident was classified as unauthorised access, suggesting attackers retained a foothold after initial intrusion. The targeting of a state agency responsible for managing seized assets carries clear geopolitical significance.
University of Texas at San Antonio
A data breach at one of the United States' largest public universities was confirmed on 16 August, placing sensitive personal data at risk. Higher education institutions continue to attract data-theft actors owing to the volume of research, financial, and student records held on-network. This incident fits a broader pattern of academic sector targeting visible across the period.
Douglas County Sheriff's Office
A cyber incident at the Douglas County Sheriff's Office, reported on 14 August, illustrates the growing pressure on US law enforcement agencies. Attacks on police and justice bodies carry unique risks, including exposure of sensitive case files, informant records, and personal data belonging to both staff and the public.
Administration de l'État de Berlin (Berlin State Administration)
Germany's Berlin state administration suffered an unauthorised access incident on 15 August, with attackers gaining entry to government systems. The incident highlights continued pressure on European public sector bodies and echoes a broader trend of nation-state and opportunistic actors probing government networks across the continent.
Ryomo Systems, Japan
Japanese IT systems integrator Ryomo Systems confirmed a data breach or exfiltration event on 14 August. Attacks on technology and systems integration firms are particularly consequential given the downstream access such companies hold into client networks, making them high-value targets for both espionage and ransomware-affiliated actors.
Recent Headlines
- Iran-Linked Hackers Force UK Power Plant Offline in Unprecedented Four-Day Cyberattack - Iranian-affiliated actors forced a British power facility offline for four days in what officials describe as the first successful attack of its kind against UK energy infrastructure, raising fresh alarm over critical infrastructure vulnerability.
- Concurrent US Water Infrastructure Attacks Hit 12 States - Alongside the UK power plant breach, a coordinated wave of intrusions struck water and wastewater systems across at least 12 US states, prompting concern at the White House.
- Suspected China-Nexus Actor Exploits VMware vCenter Flaw, Deploys Babuk-Derived Ransomware - A campaign assessed with moderate confidence as Chinese-speaking compromised 361 unique victim IP addresses across 47 countries by exploiting a VMware vCenter vulnerability, deploying ransomware as a potential smokescreen for deeper intrusion.
- Sandworm-Linked UAC-0145 Uses Fake Job Interviews to Push Malware-Laden VPN - Russia's Sandworm-linked group UAC-0145 ran a social engineering campaign targeting Ukrainian IT workers, posing as recruiters to trick victims into installing malware-laced software, according to CERT-UA.
- Large-Scale npm and Supply Chain Attacks Target Hundreds of Developer Packages - Microsoft Threat Intelligence and JFrog both identified major supply chain attacks in early August, with the npm campaign affecting more than 400 packages across multiple unrelated publishers.
- New Extortion Actor ExfilSquad Emerges with High-Profile Data Breach Campaign - ExfilSquad, a new threat actor that appeared in mid-2026, has claimed a string of high-profile breaches, relying purely on data-theft extortion via a dedicated leak site rather than ransomware deployment.
- Hugging Face Responds to Supply Chain Compromise Targeting AI Development Tools - AI platform Hugging Face confirmed a supply chain compromise affecting its development tooling in July, underscoring the rising risk to AI infrastructure as a vector for broader downstream attacks.
- DOUBLECUP: Russian Loader-as-a-Service Identified Powering ClickFix Campaigns - SOCRadar's threat research unit identified and analysed DOUBLECUP, a Russian-operated Loader-as-a-Service platform being used to drive ClickFix phishing and malware delivery campaigns at scale.
- Trezor Discloses Data Breach Affecting Customers Across Seven Countries - Hardware wallet maker Trezor disclosed a breach affecting customers who placed orders between May and August 2026 across the US, UK, Sweden, Colombia, Brazil, Italy, and Portugal.
- Threat Actors Spend Nearly $7 Million on Expired Domains to Redirect Traffic to Scams and Malware - Infoblox revealed a large-scale campaign in which threat actors acquired expired domains to inherit their traffic and reputation, redirecting victims to scam pages and malware delivery infrastructure.
Bottom Line
The consistency of the threat landscape, with the same actors, sectors, and attack types dominating period after period, tells its own story: attackers have found a formula that works and they are not changing it. Critical infrastructure attacks are escalating from aspiration to execution, as the UK power plant incident confirms. Organisations that treat cyber resilience as a compliance checkbox rather than an operational priority are already behind the curve; the question is not whether they will be targeted, but when.
Sector by Country
| Sector | United States | Romania | France | Israel | Mexico | Indonesia | India | Spain |
|---|---|---|---|---|---|---|---|---|
| Professional and Technical Services | 28 | 42 | 18 | 28 | 22 | 21 | 3 | 19 |
| Manufacturing | 30 | 29 | 7 | 3 | 2 | 2 | 6 | 3 |
| Real Estate Activities | 27 | 11 | 8 | 6 | 3 | 0 | 6 | 0 |
| Mining and Quarrying | 38 | 7 | 5 | 3 | 0 | 3 | 1 | 3 |
| Wholesale and Retail Trade | 30 | 1 | 12 | 6 | 0 | 0 | 1 | 2 |
| Arts, Entertainment and Recreation | 38 | 0 | 2 | 4 | 6 | 0 | 5 | 1 |
| Human Health and Social Work | 3 | 2 | 7 | 6 | 4 | 7 | 5 | 1 |
| Financial and Insurance Activities | 15 | 0 | 2 | 2 | 1 | 5 | 2 | 0 |
Romania's Professional and Technical Services sector recorded the highest single cell in the matrix with 42 attacks, driven almost entirely by the hacktivist DDoS campaigns of NoName057(16) and Dark Storm Team targeting Romanian professional and government-adjacent services.

Threat Intelligence Reports
Our custom cyber threat intelligence reporting delivers strategic, operational, and tactical insights tailored to your organisation's unique needs. We help organisations understand and address specific threat landscapes across industries and geographies through detailed, actionable reports, enabling informed decisions to safeguard operations at all levels.
Insights

Global Cyber Threat Briefing: August 2026
Stay ahead of the curve with Cyber Series, your essential update on the evolving threat landscape.

EU Cyber Resilience Act: Commission Publishes Implementation Guidance
Briefing for senior management and risk leadership | C(2026) 5252 final, Annex, 27 July 2026

Global Cyber Threat Briefing: July 2026 Attack Statistics and Trends
Stay ahead of the curve with Cyber Series, your essential update on the evolving threat landscape.

Thomas Murray Cyber Risk Launches CyberResponse+, a Warranty-Backed Cyber Risk Subscription
New offering unifies exposure monitoring, threat intelligence, and 24/7 incident response with an industry-leading cyber warranty in a single annual subscription.
