Skip to main content

Executive Summary

During the 30-day period from 2026-07-06 to 2026-08-05, a total of 2,863 cyber incidents were recorded globally across all tracked sources. This represents a +4.6% increase over the prior 30-day window (2,736 incidents), confirming a continued, steady upward trajectory in global threat activity. The threat landscape remained broadly distributed, with no single region monopolising incident volume, though the United States, France, and Germany collectively accounted for over one-third of all recorded events. 

Stephen Green
Stephen Green

Threat Intelligence Lead | Cyber Risk

sgreen@thomasmurray.com

The attack mix was dominated by three primary categories: Data Leak / Exfiltration (1,226 incidents, 42.8% of total), Ransomware (840 incidents, 29.3%), and DDoS (729 incidents, 25.5%). This split reflects a dual-track threat environment in which financially motivated ransomware operators continue to deploy encryption-and-extortion tactics while hacktivist and nation-state-aligned collectives sustain disruptive DDoS campaigns. The most active threat actor this period was NoName057(16), responsible for 207 recorded incidents, followed by ransomware groups Qilin (123) and The Gentlemen (119), and hacktivist collective Dark Storm Team (117). 

The Financial Services sector recorded 120 attacks this period, representing a notable target set. Dark Storm Team (10 attacks), Exchange Markets (9), and NoName057(16) (6) led activity against financial institutions. High-profile financial organisations appearing in the underlying incident data include Bank of America, Binance, Mercer Advisors, and Cartes Bancaires, underlining persistent adversary interest in banking infrastructure, payment systems, and investment advisory services. 

Strategic Context

Total ransomware volume across the world rose roughly 20% year over year through the first half of 2026, alongside a 74% quarter-over-quarter jump in attacks against billion-dollar companies. This structural escalation provides essential backdrop for the activity observed in this reporting window. The concentration of DDoS attacks against Romania, Germany, France, and Israel aligns with ongoing geopolitical friction: pro-Russian hacktivist groups such as NoName057(16) and Dark Storm Team continue to target NATO-aligned states and institutions with perceived links to Western foreign policy. A rash of cyberattacks across Europe targeting civilian energy and water supplies has set a troubling trend, with several hacks attributed at least in part to Russia risking real-world harm to communities. 

For the financial sector specifically, after a brief reprieve driven by law enforcement pressure on dominant groups, direct ransomware attacks on financial institutions rebounded sharply, incidents climbed from 156 in 2024 to 202 in 2025, reversing the prior year's decline. Both direct attacks and supply chain risk are now rising together, and the gap between heavily regulated financial institutions and the vendors that serve them, who face no comparable compliance pressure, has become the most exploitable seam in the threat landscape. Concurrently, Storm-2945, a sub-cluster of the Russian threat actor Midnight Blizzard, has been observed compromising the sign-in portals of hospitality-related organisations since May 2026 to deliver malware to travellers, and has conducted AI-augmented operations including targeted device code and OAuth phishing campaigns since February 2026. The emergence of AI-assisted intrusion techniques adds a new dimension of scalability to campaigns that previously relied on manual exploitation.

Recent Headlines

July 2026 Attack Statistics 

MetricValue
Total Incidents (Period)2,863
Prior Period Incidents2,736
Week-on-Week Change+4.6% 
Top Threat ActorNoName057(16), 207 attacks 
Top Targeted CountryUnited States, 567 attacks
Top Targeted SectorEducation, 651 attacks 
Top Attack CategoryData Leak / Exfiltration, 1,226 incidents
Finance Sector Incidents120 
Ransomware Incidents 840 
DDoS Incidents 729 
 

Cyber Attacks by Country

United States

Total Incidents: 567 | Share of Global Total: 19.8%

CategoryCount
Ransomware334
Data Leak / Exfiltration195
DDoS25

Top Industries: Arts/Entertainment/Recreation (R: 73), Professional/Scientific (B: 71), Public Admin (G: 68), Legal (L: 62), Construction (C: 50) 

 

Top Threat Actors:

Threat ActorIncidents
Qilin56
The Gentlemen43
CRPx033
Affected Entities28
INC RANSOM18

Notable Targeted Organisations: US Dept. of Defense, CIA, GitHub, Bank of America, Binance, Mercer Advisors 

The United States remained the single most attacked nation globally, accounting for nearly one in five incidents worldwide. Ransomware was the dominant category, more than half of all US incidents were ransomware events, with Qilin and The Gentlemen competing aggressively for victim volume. The appearance of high-value financial targets such as Bank of America and Binance, alongside sensitive government entities including the Department of Defense and CIA, underscores the breadth and ambition of adversary targeting this period. 

 
France

Total Incidents: 231 | Share of Global Total: 8.1%

CategoryCount
Data Leak / Exfiltration132
DDoS72
Ransomware22

Top Industries: Education (P: 41), Construction (C: 29), Public Admin (G: 25), Legal (L: 20), Health (Q: 18

 

Top Threat Actors:

Threat ActorIncidents
NoName057(16)40
Dark Storm Team14
ChimeraZ11
Sophia9
misere9

Notable Targeted Organisations: GEODIS, Cartes Bancaires, France Travail, CEVA Logistics, Renault Trucks, Préfecture de la Vienne, Préfecture du Gers 

France was the second-most targeted country globally, with a notably high proportion of DDoS attacks driven by NoName057(16) and Dark Storm Team, both groups with documented pro-Russian hacktivist orientations. The targeting of Cartes Bancaires, France's national interbank card network, represents a significant threat to the domestic payment infrastructure and warrants continued monitoring from a financial sector resilience perspective. 

 
Germany 

Total Incidents: 171 | Share of Global Total: 6.0%

CategoryCount
DDoS101
Data Leak / Exfiltration33
Ransomware31

Top Industries: Construction (C: 47), Education (P: 45), Professional/Scientific (B: 15), Public Admin (G: 12), Legal (L: 7) 

 

Top Threat Actors:

Threat ActorIncidents
NoName057(16)77
Dark Storm Team 18
SAFEPAY14
Sophia0111
Sophia 9

Notable Targeted Organisations: Port of Kiel, Transdev Hannover GmbH, ELSTER (tax portal), M-Net Telekommunikations GmbH, Bundesvereinigung Logistik 

Germany experienced the highest absolute DDoS count of any country in this report, with NoName057(16) alone responsible for 77 of 171 recorded incidents, a striking concentration of activity from a single actor. The targeting of critical logistics, transport, and tax infrastructure (Port of Kiel, ELSTER) suggests deliberate efforts to maximise societal disruption rather than purely financial gain. 

 
Romania 

Total Incidents: 121 | Share of Global Total: 4.2%

CategoryCount
DDoS102
Data Leak / Exfiltration12
Ransomware3

Top Industries: Education (P: 50), Construction (C: 29), Legal (L: 9), Transport (H: 7), Professional/Scientific (B: 6) 

 

Top Threat Actors:

Threat ActorIncidents
NoName057(16)64
Dark Storm Team31
Meta Yadro Legion7
Server Killers4
BD Anonymous 3

Notable Targeted Organisations: Ministry of Justice of Romania, Romanian Auto Registry, Senate of Romania, Presidential Administration of Romania, Supreme Court of Romania, MetroRex 

Romania's profile was almost entirely shaped by DDoS activity (84% of incidents), making it the country with the highest relative DDoS concentration in this dataset. The systematic targeting of judicial and executive government institutions, including the Supreme Court, Senate, and Presidential Administration, indicates an orchestrated hacktivist effort aimed at delegitimising Romanian state institutions. 

 
Israel 

Total Incidents: 107 | Share of Global Total: 3.7%

CategoryCount
DDoS91
Data Leak / Exfiltration13
Ransomware3

Top Industries: Education (P: 42), Legal (L: 11), Health (Q: 11), Professional/Scientific (B: 7), Construction (C: 6) 

 

Top Threat Actors:

Threat ActorIncidents
Hider_Nex 24
BD Anonymous19
Dark Storm Team15
RipperSec7
PHCS6

Notable Targeted Organisations: Israel Defense Forces (IDF), Israeli Ministry of Education, Herzliya Medical Center, University of Haifa, Israel Innovation Authority 

Israel's incident profile was overwhelmingly DDoS-driven (85% of incidents), reflecting ongoing hacktivist pressure aligned with regional geopolitical tensions. The targeting of the IDF alongside civilian targets including universities and a medical centre illustrates the indiscriminate breadth of these campaigns. Hider_Nex emerged as the leading actor against Israeli targets this period, a group not appearing in the global top-10, suggesting Israel-specific campaign specialisation. 

 
Mexico 

Total Incidents: 106 | Share of Global Total: 3.7%

CategoryCount
Data Leak / Exfiltration99
Ransomware7

Top Industries: Education (P: 61), Health (Q: 14), Arts/Entertainment/Recreation (R: 8), Legal (L: 6), Construction (C: 4) 

 

Top Threat Actors:

Threat ActorIncidents
Hackero$19
Arcepahs channel14
Chronus Leaks7
homercracker5
cenfecracked5

Notable Targeted Organisations: Hospital México Americano, Municipal Government of Ciudad Juárez, Municipality of Culiacán, Government of Sinaloa State, Government of Mexico City, Partido Acción Nacional, Chevrolet Mexico

Mexico's threat landscape was almost exclusively data-leak oriented, 93% of all incidents were data exfiltration events, driven by a diffuse set of Spanish-language threat actors not appearing in the global top-10. The breadth of municipal and state government targeting, alongside a major political party and a corporate automotive brand, reflects opportunistic rather than coordinated campaigns, likely exploiting misconfigured public-facing assets. 

 
India 

Total Incidents: 99 | Share of Global Total: 3.5%

CategoryCount
Data Leak / Exfiltration59
Ransomware27
DDoS12

Top Industries: Health (Q: 18), Education (P: 12), Construction (C: 12), Arts/Entertainment/Recreation (R: 10), Legal (L: 10) 

 

Top Threat Actors:

Threat ActorIncidents
The Gentlemen8
CYBER TEAM INDONESIA6
God's Gladiators5
JundAlNabi Official4
BD Anonymous4

Notable Targeted Organisations: Bank of Baroda (5 incidents), Defence Research and Development Organisation (DRDO), Tamil Nadu Fisheries University, Narayana Health 

India recorded a diversified attack mix spanning data leaks, ransomware, and DDoS. Bank of Baroda was the most targeted single organisation in the country with five recorded incidents, reinforcing the financial sector's exposure in the Indian market. The presence of BD Anonymous and JundAlNabi Official, both actors with observed Islamist hacktivist motivations, alongside the targeting of the DRDO suggests both ideologically and financially motivated adversaries are active against Indian assets simultaneously. 

 
Indonesia 

Total Incidents: 82 | Share of Global Total: 2.9%

CategoryCount
Data Leak / Exfiltration61
DDoS13
Ransomware8

Top Industries: Education (P: 39), Health (Q: 15), Finance/Insurance (K: 7), Professional/Scientific (B: 5), Construction (C: 5)

 

Top Threat Actors:

Threat ActorIncidents
KNOK666X9
GARUDA KERNEL ERROR SYSTEM 7
DR4K7H CYBER TEAM7
KNOK666X5
ChuckXzn_1014

Notable Targeted Organisations: Pertamina Retail, Indonesian National Police (POLRI), Directorate General of Civil Registration and Population, Indonesian House of Representatives 

Indonesia's incident set was dominated by domestic-origin or regionally-proximate threat actors, many bearing Indonesian-language identifiers, suggesting a significant domestic hacktivist and cybercriminal ecosystem. The compromise of civil registration and population data systems presents a long-term identity fraud risk at scale. The Finance and Insurance sector (NACE K) recorded 7 incidents, with continued targeting warranting attention from Indonesian financial regulators. 

 

Threat Actor Activity

Global Threat Actor Rankings, Top 10
RankThreat ActorIncidentsPrimary ModalityNotes 
1NoName057(16)207DDoS Pro-Russian hacktivist; heavy focus on EU/NATO states 
2Qilin 123 Ransomware Russian-speaking RaaS group; active globally 
3The Gentlemen 119 Ransomware Competing with Qilin for top ransomware volume 
4Dark Storm Team 117 DDoS Hacktivist collective; active in EU, Israel, Romania 
5Meta Yadro Legion 68 DDoS/Data Leak Significant activity in Romania 
6Exchange Markets 53 Data Leak Active in financial sector targeting 
7BD Anonymous 52 DDoS/Data Leak Multi-region hacktivist; Israel, India, Romania 
8Affected Entities 50 Data Leak US-focused; primarily exfiltration activity 
9CRPx0 45 Ransomware US-dominant targeting; healthcare and finance 
10DragonForce 44Ransomware RaaS operator; diverse sector targeting 
 
Top Threat Actor Profile, NoName057(16)

NoName057(16) was the single most prolific threat actor observed during this reporting window, recording 207 attacks, more than 7.2% of the entire global incident count. The group operated predominantly through high-volume DDoS campaigns concentrated against NATO-aligned European states: Germany (77 incidents), Romania (64), and France (40) were their primary targets, with further activity across other Western European nations. NoName057(16) is a well-documented pro-Russian hacktivist collective that has been operationally active since early 2022, characteristically deploying its DDoSia volunteer botnet tool to maximise attack throughput. Their continued focus on government portals, legal institutions, judicial systems, and logistics infrastructure reflects a persistent intent to generate operational disruption and reputational damage against Western governmental and economic targets, consistent with broader Russian information warfare objectives. 

Analyst Notes

  • Hacktivist DDoS campaigns remain the defining volume driver in Europe. NoName057(16) and Dark Storm Team together accounted for the overwhelming majority of DDoS incidents across Germany, Romania, France, and Israel. These campaigns show no sign of abating and are likely to intensify around upcoming EU electoral, legislative, or foreign policy events. 
  • Ransomware double-extortion targeting of the United States intensified. With 334 ransomware incidents, the highest single-country ransomware count by a wide margin, the US continued to absorb disproportionate ransomware pressure. Qilin and The Gentlemen are competing for dominance in this space; both groups are neck-and-neck for the top ransomware position in 2026, with each claiming nearly 300 victims in Q2 alone. Organisations in the Arts/Entertainment/Recreation, Professional Services, and Legal sectors were most exposed. 

  • Financial services face a compounding threat from both ransomware and DDoS actors. With 120 incidents recorded against the financial sector globally this period, and high-profile institutions including Bank of America, Binance, Cartes Bancaires, and Bank of Baroda appearing in incident data, the sector remains a high-priority target. The convergence of hacktivist DDoS (disrupting customer-facing services) and ransomware/data-leak activity (targeting sensitive financial data) creates a multi-vector exposure that DORA, NIS2, and equivalent frameworks must address operationally, not merely in documentation. 

  • Data exfiltration now eclipses ransomware by volume globally. At 1,226 incidents versus 840 ransomware events, data leaks represented the largest single attack category this period. Mexico (93% of incidents were exfiltration), Indonesia (74%), and India (60%) show particularly acute exfiltration exposure. This trend is consistent with financially motivated actors preferring low-friction, high-yield data monetisation over operationally complex ransomware deployment. 

  • AI-augmented offensive capabilities are moving from theoretical to operational. The emergence of JadePuffer, the first ransomware operation documented as carried out end-to-end by an LLM agent, and the broader concept of "agentic threat actors" signals a qualitative shift in adversary capability. Combined with AI-augmented phishing operations already observed from Midnight Blizzard sub-clusters since February 2026, defenders should anticipate increasing campaign velocity, personalisation, and evasion sophistication across all attack categories in the next reporting window. Thomas Murray has also investigated a recent AI assisted intrusion where the threat actor clearly used AI provided scripts for reconnaissance and privilege execution attempts. 

Cyber Risk

Threat Intelligence Reports

Our custom cyber threat intelligence reporting delivers strategic, operational, and tactical insights tailored to your organisation's unique needs. We help organisations understand and address specific threat landscapes across industries and geographies through detailed, actionable reports, enabling informed decisions to safeguard operations at all levels.

Learn more