Executive Summary
During the 30-day period from 2026-07-06 to 2026-08-05, a total of 2,863 cyber incidents were recorded globally across all tracked sources. This represents a +4.6% increase over the prior 30-day window (2,736 incidents), confirming a continued, steady upward trajectory in global threat activity. The threat landscape remained broadly distributed, with no single region monopolising incident volume, though the United States, France, and Germany collectively accounted for over one-third of all recorded events.

The attack mix was dominated by three primary categories: Data Leak / Exfiltration (1,226 incidents, 42.8% of total), Ransomware (840 incidents, 29.3%), and DDoS (729 incidents, 25.5%). This split reflects a dual-track threat environment in which financially motivated ransomware operators continue to deploy encryption-and-extortion tactics while hacktivist and nation-state-aligned collectives sustain disruptive DDoS campaigns. The most active threat actor this period was NoName057(16), responsible for 207 recorded incidents, followed by ransomware groups Qilin (123) and The Gentlemen (119), and hacktivist collective Dark Storm Team (117).
The Financial Services sector recorded 120 attacks this period, representing a notable target set. Dark Storm Team (10 attacks), Exchange Markets (9), and NoName057(16) (6) led activity against financial institutions. High-profile financial organisations appearing in the underlying incident data include Bank of America, Binance, Mercer Advisors, and Cartes Bancaires, underlining persistent adversary interest in banking infrastructure, payment systems, and investment advisory services.
Strategic Context
Total ransomware volume across the world rose roughly 20% year over year through the first half of 2026, alongside a 74% quarter-over-quarter jump in attacks against billion-dollar companies. This structural escalation provides essential backdrop for the activity observed in this reporting window. The concentration of DDoS attacks against Romania, Germany, France, and Israel aligns with ongoing geopolitical friction: pro-Russian hacktivist groups such as NoName057(16) and Dark Storm Team continue to target NATO-aligned states and institutions with perceived links to Western foreign policy. A rash of cyberattacks across Europe targeting civilian energy and water supplies has set a troubling trend, with several hacks attributed at least in part to Russia risking real-world harm to communities.
For the financial sector specifically, after a brief reprieve driven by law enforcement pressure on dominant groups, direct ransomware attacks on financial institutions rebounded sharply, incidents climbed from 156 in 2024 to 202 in 2025, reversing the prior year's decline. Both direct attacks and supply chain risk are now rising together, and the gap between heavily regulated financial institutions and the vendors that serve them, who face no comparable compliance pressure, has become the most exploitable seam in the threat landscape. Concurrently, Storm-2945, a sub-cluster of the Russian threat actor Midnight Blizzard, has been observed compromising the sign-in portals of hospitality-related organisations since May 2026 to deliver malware to travellers, and has conducted AI-augmented operations including targeted device code and OAuth phishing campaigns since February 2026. The emergence of AI-assisted intrusion techniques adds a new dimension of scalability to campaigns that previously relied on manual exploitation.
Recent Headlines
- Major Cyber Attacks, Data Breaches, Ransomware Attacks in July 2026: A ransomware attack disrupted Coca-Cola Fairlife's operations; Hugging Face responded to a supply chain compromise targeting AI development tools; and financial institutions such as Bank of Baroda dealt with customer-facing cyber incidents.
- CaptiveCrunch: Midnight Blizzard Targets Travelers Worldwide for Malware Delivery and Credential Theft: Since early May 2026, Microsoft Threat Intelligence observed Storm-2945 manipulating DNS and HTTP traffic from networks served by captive portals to redirect user traffic through actor-controlled infrastructure.
- JadePuffer: First Autonomous AI-Driven Ransomware Operation Documented: Bleeping Computer reported on JadePuffer as the first ransomware operation carried out from start to finish by an LLM agent rather than a human operator; researchers now use the term "agentic threat actor" for this class of adversary.
- Bosch Hit by D1R Ransomware Group in July 2026: Bosch became a victim of a ransomware attack carried out by the D1R ransomware group, which claimed to have stolen sensitive engineering data.
- DHS Network Breached Ahead of 2026 FIFA World Cup: The U.S. Department of Homeland Security confirmed that hackers breached the Homeland Security Information Network, an unclassified information-sharing platform used to support security coordination during the 2026 FIFA World Cup, with suspicious activity first detected between mid-May and early June.
- Conduent Breach Expands to Over 62 Million Individuals by July 2026: The Conduent breach expanded sharply by July 2026, with healthcare breach reporting placing the affected population at more than 62.2 million individuals, with reports citing Social Security numbers, medical information, and health insurance data.
July 2026 Attack Statistics
| Metric | Value |
|---|---|
| Total Incidents (Period) | 2,863 |
| Prior Period Incidents | 2,736 |
| Week-on-Week Change | +4.6% |
| Top Threat Actor | NoName057(16), 207 attacks |
| Top Targeted Country | United States, 567 attacks |
| Top Targeted Sector | Education, 651 attacks |
| Top Attack Category | Data Leak / Exfiltration, 1,226 incidents |
| Finance Sector Incidents | 120 |
| Ransomware Incidents | 840 |
| DDoS Incidents | 729 |
Cyber Attacks by Country
United States
Total Incidents: 567 | Share of Global Total: 19.8%
| Category | Count |
|---|---|
| Ransomware | 334 |
| Data Leak / Exfiltration | 195 |
| DDoS | 25 |
Top Industries: Arts/Entertainment/Recreation (R: 73), Professional/Scientific (B: 71), Public Admin (G: 68), Legal (L: 62), Construction (C: 50)
Top Threat Actors:
| Threat Actor | Incidents |
|---|---|
| Qilin | 56 |
| The Gentlemen | 43 |
| CRPx0 | 33 |
| Affected Entities | 28 |
| INC RANSOM | 18 |
Notable Targeted Organisations: US Dept. of Defense, CIA, GitHub, Bank of America, Binance, Mercer Advisors
The United States remained the single most attacked nation globally, accounting for nearly one in five incidents worldwide. Ransomware was the dominant category, more than half of all US incidents were ransomware events, with Qilin and The Gentlemen competing aggressively for victim volume. The appearance of high-value financial targets such as Bank of America and Binance, alongside sensitive government entities including the Department of Defense and CIA, underscores the breadth and ambition of adversary targeting this period.
France
Total Incidents: 231 | Share of Global Total: 8.1%
| Category | Count |
|---|---|
| Data Leak / Exfiltration | 132 |
| DDoS | 72 |
| Ransomware | 22 |
Top Industries: Education (P: 41), Construction (C: 29), Public Admin (G: 25), Legal (L: 20), Health (Q: 18
Top Threat Actors:
| Threat Actor | Incidents |
|---|---|
| NoName057(16) | 40 |
| Dark Storm Team | 14 |
| ChimeraZ | 11 |
| Sophia | 9 |
| misere | 9 |
Notable Targeted Organisations: GEODIS, Cartes Bancaires, France Travail, CEVA Logistics, Renault Trucks, Préfecture de la Vienne, Préfecture du Gers
France was the second-most targeted country globally, with a notably high proportion of DDoS attacks driven by NoName057(16) and Dark Storm Team, both groups with documented pro-Russian hacktivist orientations. The targeting of Cartes Bancaires, France's national interbank card network, represents a significant threat to the domestic payment infrastructure and warrants continued monitoring from a financial sector resilience perspective.
Germany
Total Incidents: 171 | Share of Global Total: 6.0%
| Category | Count |
|---|---|
| DDoS | 101 |
| Data Leak / Exfiltration | 33 |
| Ransomware | 31 |
Top Industries: Construction (C: 47), Education (P: 45), Professional/Scientific (B: 15), Public Admin (G: 12), Legal (L: 7)
Top Threat Actors:
| Threat Actor | Incidents |
|---|---|
| NoName057(16) | 77 |
| Dark Storm Team | 18 |
| SAFEPAY | 14 |
| Sophia01 | 11 |
| Sophia | 9 |
Notable Targeted Organisations: Port of Kiel, Transdev Hannover GmbH, ELSTER (tax portal), M-Net Telekommunikations GmbH, Bundesvereinigung Logistik
Germany experienced the highest absolute DDoS count of any country in this report, with NoName057(16) alone responsible for 77 of 171 recorded incidents, a striking concentration of activity from a single actor. The targeting of critical logistics, transport, and tax infrastructure (Port of Kiel, ELSTER) suggests deliberate efforts to maximise societal disruption rather than purely financial gain.
Romania
Total Incidents: 121 | Share of Global Total: 4.2%
| Category | Count |
|---|---|
| DDoS | 102 |
| Data Leak / Exfiltration | 12 |
| Ransomware | 3 |
Top Industries: Education (P: 50), Construction (C: 29), Legal (L: 9), Transport (H: 7), Professional/Scientific (B: 6)
Top Threat Actors:
| Threat Actor | Incidents |
|---|---|
| NoName057(16) | 64 |
| Dark Storm Team | 31 |
| Meta Yadro Legion | 7 |
| Server Killers | 4 |
| BD Anonymous | 3 |
Notable Targeted Organisations: Ministry of Justice of Romania, Romanian Auto Registry, Senate of Romania, Presidential Administration of Romania, Supreme Court of Romania, MetroRex
Romania's profile was almost entirely shaped by DDoS activity (84% of incidents), making it the country with the highest relative DDoS concentration in this dataset. The systematic targeting of judicial and executive government institutions, including the Supreme Court, Senate, and Presidential Administration, indicates an orchestrated hacktivist effort aimed at delegitimising Romanian state institutions.
Israel
Total Incidents: 107 | Share of Global Total: 3.7%
| Category | Count |
|---|---|
| DDoS | 91 |
| Data Leak / Exfiltration | 13 |
| Ransomware | 3 |
Top Industries: Education (P: 42), Legal (L: 11), Health (Q: 11), Professional/Scientific (B: 7), Construction (C: 6)
Top Threat Actors:
| Threat Actor | Incidents |
|---|---|
| Hider_Nex | 24 |
| BD Anonymous | 19 |
| Dark Storm Team | 15 |
| RipperSec | 7 |
| PHCS | 6 |
Notable Targeted Organisations: Israel Defense Forces (IDF), Israeli Ministry of Education, Herzliya Medical Center, University of Haifa, Israel Innovation Authority
Israel's incident profile was overwhelmingly DDoS-driven (85% of incidents), reflecting ongoing hacktivist pressure aligned with regional geopolitical tensions. The targeting of the IDF alongside civilian targets including universities and a medical centre illustrates the indiscriminate breadth of these campaigns. Hider_Nex emerged as the leading actor against Israeli targets this period, a group not appearing in the global top-10, suggesting Israel-specific campaign specialisation.
Mexico
Total Incidents: 106 | Share of Global Total: 3.7%
| Category | Count |
|---|---|
| Data Leak / Exfiltration | 99 |
| Ransomware | 7 |
Top Industries: Education (P: 61), Health (Q: 14), Arts/Entertainment/Recreation (R: 8), Legal (L: 6), Construction (C: 4)
Top Threat Actors:
| Threat Actor | Incidents |
|---|---|
| Hackero$ | 19 |
| Arcepahs channel | 14 |
| Chronus Leaks | 7 |
| homercracker | 5 |
| cenfecracked | 5 |
Notable Targeted Organisations: Hospital México Americano, Municipal Government of Ciudad Juárez, Municipality of Culiacán, Government of Sinaloa State, Government of Mexico City, Partido Acción Nacional, Chevrolet Mexico
Mexico's threat landscape was almost exclusively data-leak oriented, 93% of all incidents were data exfiltration events, driven by a diffuse set of Spanish-language threat actors not appearing in the global top-10. The breadth of municipal and state government targeting, alongside a major political party and a corporate automotive brand, reflects opportunistic rather than coordinated campaigns, likely exploiting misconfigured public-facing assets.
India
Total Incidents: 99 | Share of Global Total: 3.5%
| Category | Count |
|---|---|
| Data Leak / Exfiltration | 59 |
| Ransomware | 27 |
| DDoS | 12 |
Top Industries: Health (Q: 18), Education (P: 12), Construction (C: 12), Arts/Entertainment/Recreation (R: 10), Legal (L: 10)
Top Threat Actors:
| Threat Actor | Incidents |
|---|---|
| The Gentlemen | 8 |
| CYBER TEAM INDONESIA | 6 |
| God's Gladiators | 5 |
| JundAlNabi Official | 4 |
| BD Anonymous | 4 |
Notable Targeted Organisations: Bank of Baroda (5 incidents), Defence Research and Development Organisation (DRDO), Tamil Nadu Fisheries University, Narayana Health
India recorded a diversified attack mix spanning data leaks, ransomware, and DDoS. Bank of Baroda was the most targeted single organisation in the country with five recorded incidents, reinforcing the financial sector's exposure in the Indian market. The presence of BD Anonymous and JundAlNabi Official, both actors with observed Islamist hacktivist motivations, alongside the targeting of the DRDO suggests both ideologically and financially motivated adversaries are active against Indian assets simultaneously.
Indonesia
Total Incidents: 82 | Share of Global Total: 2.9%
| Category | Count |
|---|---|
| Data Leak / Exfiltration | 61 |
| DDoS | 13 |
| Ransomware | 8 |
Top Industries: Education (P: 39), Health (Q: 15), Finance/Insurance (K: 7), Professional/Scientific (B: 5), Construction (C: 5)
Top Threat Actors:
| Threat Actor | Incidents |
|---|---|
| KNOK666X | 9 |
| GARUDA KERNEL ERROR SYSTEM | 7 |
| DR4K7H CYBER TEAM | 7 |
| KNOK666X | 5 |
| ChuckXzn_101 | 4 |
Notable Targeted Organisations: Pertamina Retail, Indonesian National Police (POLRI), Directorate General of Civil Registration and Population, Indonesian House of Representatives
Indonesia's incident set was dominated by domestic-origin or regionally-proximate threat actors, many bearing Indonesian-language identifiers, suggesting a significant domestic hacktivist and cybercriminal ecosystem. The compromise of civil registration and population data systems presents a long-term identity fraud risk at scale. The Finance and Insurance sector (NACE K) recorded 7 incidents, with continued targeting warranting attention from Indonesian financial regulators.
Threat Actor Activity
Global Threat Actor Rankings, Top 10
| Rank | Threat Actor | Incidents | Primary Modality | Notes |
|---|---|---|---|---|
| 1 | NoName057(16) | 207 | DDoS | Pro-Russian hacktivist; heavy focus on EU/NATO states |
| 2 | Qilin | 123 | Ransomware | Russian-speaking RaaS group; active globally |
| 3 | The Gentlemen | 119 | Ransomware | Competing with Qilin for top ransomware volume |
| 4 | Dark Storm Team | 117 | DDoS | Hacktivist collective; active in EU, Israel, Romania |
| 5 | Meta Yadro Legion | 68 | DDoS/Data Leak | Significant activity in Romania |
| 6 | Exchange Markets | 53 | Data Leak | Active in financial sector targeting |
| 7 | BD Anonymous | 52 | DDoS/Data Leak | Multi-region hacktivist; Israel, India, Romania |
| 8 | Affected Entities | 50 | Data Leak | US-focused; primarily exfiltration activity |
| 9 | CRPx0 | 45 | Ransomware | US-dominant targeting; healthcare and finance |
| 10 | DragonForce | 44 | Ransomware | RaaS operator; diverse sector targeting |
Top Threat Actor Profile, NoName057(16)
NoName057(16) was the single most prolific threat actor observed during this reporting window, recording 207 attacks, more than 7.2% of the entire global incident count. The group operated predominantly through high-volume DDoS campaigns concentrated against NATO-aligned European states: Germany (77 incidents), Romania (64), and France (40) were their primary targets, with further activity across other Western European nations. NoName057(16) is a well-documented pro-Russian hacktivist collective that has been operationally active since early 2022, characteristically deploying its DDoSia volunteer botnet tool to maximise attack throughput. Their continued focus on government portals, legal institutions, judicial systems, and logistics infrastructure reflects a persistent intent to generate operational disruption and reputational damage against Western governmental and economic targets, consistent with broader Russian information warfare objectives.
Analyst Notes
- Hacktivist DDoS campaigns remain the defining volume driver in Europe. NoName057(16) and Dark Storm Team together accounted for the overwhelming majority of DDoS incidents across Germany, Romania, France, and Israel. These campaigns show no sign of abating and are likely to intensify around upcoming EU electoral, legislative, or foreign policy events.
Ransomware double-extortion targeting of the United States intensified. With 334 ransomware incidents, the highest single-country ransomware count by a wide margin, the US continued to absorb disproportionate ransomware pressure. Qilin and The Gentlemen are competing for dominance in this space; both groups are neck-and-neck for the top ransomware position in 2026, with each claiming nearly 300 victims in Q2 alone. Organisations in the Arts/Entertainment/Recreation, Professional Services, and Legal sectors were most exposed.
Financial services face a compounding threat from both ransomware and DDoS actors. With 120 incidents recorded against the financial sector globally this period, and high-profile institutions including Bank of America, Binance, Cartes Bancaires, and Bank of Baroda appearing in incident data, the sector remains a high-priority target. The convergence of hacktivist DDoS (disrupting customer-facing services) and ransomware/data-leak activity (targeting sensitive financial data) creates a multi-vector exposure that DORA, NIS2, and equivalent frameworks must address operationally, not merely in documentation.
Data exfiltration now eclipses ransomware by volume globally. At 1,226 incidents versus 840 ransomware events, data leaks represented the largest single attack category this period. Mexico (93% of incidents were exfiltration), Indonesia (74%), and India (60%) show particularly acute exfiltration exposure. This trend is consistent with financially motivated actors preferring low-friction, high-yield data monetisation over operationally complex ransomware deployment.
AI-augmented offensive capabilities are moving from theoretical to operational. The emergence of JadePuffer, the first ransomware operation documented as carried out end-to-end by an LLM agent, and the broader concept of "agentic threat actors" signals a qualitative shift in adversary capability. Combined with AI-augmented phishing operations already observed from Midnight Blizzard sub-clusters since February 2026, defenders should anticipate increasing campaign velocity, personalisation, and evasion sophistication across all attack categories in the next reporting window. Thomas Murray has also investigated a recent AI assisted intrusion where the threat actor clearly used AI provided scripts for reconnaissance and privilege execution attempts.

Threat Intelligence Reports
Our custom cyber threat intelligence reporting delivers strategic, operational, and tactical insights tailored to your organisation's unique needs. We help organisations understand and address specific threat landscapes across industries and geographies through detailed, actionable reports, enabling informed decisions to safeguard operations at all levels.
Insights

Global Cyber Threat Briefing: July 2026 Attack Statistics and Trends
Stay ahead of the curve with Cyber Series, your essential update on the evolving threat landscape.

Thomas Murray Cyber Risk Launches CyberResponse+, a Warranty-Backed Cyber Risk Subscription
New offering unifies exposure monitoring, threat intelligence, and 24/7 incident response with an industry-leading cyber warranty in a single annual subscription.

The ECB Sounds the Alarm on AI-Enabled Cyber Threats
Stay ahead of the curve with Cyber Series, your essential update on the evolving threat landscape.

Global Cyber Threat Briefing: June 2026 Attack Statistics and Trends
Stay ahead of the curve with Cyber Series, your essential update on the evolving threat landscape.
