Ransomware activity reached a new global peak in the third quarter of 2026, with independent trackers logging record numbers of victims and steep growth across multiple critical sectors.[1][5][9]
Researchers at Comparitech recorded 2,627 claimed ransomware attacks between July and September 2026, the highest quarterly total since the firm began tracking incidents.[1][8][9] That figure represents a 29 percent increase on Q2 2026, when 2,030 attacks were logged, and a 61 percent jump compared with Q3 2025, which saw 1,636 attacks, averaging nearly 29 incidents per day.[1][9] Of these Q3 2026 attacks, 247 were confirmed by the affected organizations, including 138 businesses, 53 government entities, 36 healthcare providers and 20 educational institutions, with the remaining 2,380 attributed to victims that have not publicly verified an attack.[1][9]
The Q3 data shows that finance and technology organizations experienced the sharpest quarter-on-quarter rises, with attacks surging 72 percent and 70 percent respectively compared with Q2 2026.[1][9] Education saw a 50 percent uptick, while healthcare and government recorded increases of 39 percent and 36 percent, and utilities climbed 32 percent over the same period.[1][9] Manufacturing remained the most targeted industry overall, with 478 attacks in Q3—up 22 percent from 391 incidents in Q2 2026—while technology companies suffered 262 attacks and financial organizations 199.[1][9] The United States accounted for 1,066 attacks, around 41 percent of the global total, a 34 percent rise from the previous quarter, with Argentina and India among the countries experiencing the fastest growth in claimed attacks at 150 percent and 116 percent respectively.[9]
A separate analysis by GuidePoint’s GRIT unit pointed to even higher victim volumes, tracking 2,760 ransomware victims in Q3 2026, more than in any prior quarter in its dataset.[5] GRIT’s report found that victim counts rose 21 percent compared with Q2 2026 and 75 percent year-over-year versus Q3 2025, while the number of active ransomware groups expanded to 112, a 23 percent quarter-on-quarter increase and 47 percent growth over the previous year.[5] Manufacturing again emerged as the most heavily impacted industry, followed by technology and healthcare, with banking and finance re-entering the top 10 as threat actors pursued a sustained social-engineering campaign against private equity firms.[5] GRIT also observed that while payment rates fell by more than half year-over-year, the average payment among organizations that did pay climbed 34 percent.[5]
Across both datasets, a small number of ransomware operations accounted for a disproportionate share of victims, underscoring the consolidation of capabilities among leading groups.[5][9] Comparitech’s figures highlighted Qilin and The Gentlemen as the most prolific gangs in Q3, claiming 357 and 342 attacks respectively, which together represented roughly one quarter of all observed victims.[9] GRIT’s telemetry similarly identified The Gentlemen and Qilin at the top of its rankings, with The Gentlemen responsible for 12.9 percent of observed victims and Qilin for 12.6 percent.[5] Analysts noted growing use of so-called “triple extortion” tactics, in which intruders combine data theft, encryption and additional pressure such as distributed denial-of-service attacks or harassment of customers and partners to increase leverage over victims.[5][9]
The surge in Q3 ransomware activity builds on earlier warning signs from sector-specific studies, particularly in healthcare and government.[2][4][11] Comparitech’s healthcare-focused tracking found a 14 percent rise in attacks against healthcare organizations in the first half of 2026 compared with the second half of 2025, with Qilin and The Gentlemen among the most active strains targeting providers.[2][11][15] Separate research into public-sector incidents identified 187 attacks on government entities in H1 2026, with the US accounting for nearly a third of cases, while education-focused reporting has suggested that K-12 districts are seeing fewer successful intrusions even as ransomware pressure persists on higher-education institutions.[4][14] Taken together, the latest Q3 numbers suggest that ransomware actors are widening their reach rather than concentrating solely on traditional corporate targets.[1][5][9]
For defenders, the record-breaking Q3 underscores the need to treat ransomware as a systemic, cross-industry risk rather than a series of isolated incidents, with particular focus on sectors that showed the fastest growth this quarter.[1][5][9] Organizations in finance, technology, healthcare, government and manufacturing should prioritize patching exposed services, enforcing strong authentication on remote access, segmenting critical networks, and testing offline backups against realistic recovery scenarios, while preparing for extortion tactics that extend beyond simple data encryption.[5][9] As leading ransomware groups refine their playbooks and expand into new geographies and verticals, incident responders and executives alike will need to assume that disclosure, regulatory scrutiny and potential operational disruption are part of the baseline risk whenever attackers gain a foothold.
References
- Ransomware roundup: Q3 2026 stats on attacks, ransoms, and …
- www.comparitech.com · news · healthcare-ransomwareHealthcare Ransomware Roundup: H1 2026 stats on … – Comparitech
- www.comparitech.com › news › government-ransomwareGovernment Ransomware Roundup: H1 2026 stats on attacks …
- GuidePoint Security Reports Record-High Ransomware Activity as Victims Rise 75% Year Over Year
- All Ransomware Studies Guides – Comparitech
- Q3 2026 Sets New Record for Ransomware Attacks
- Healthcare ransomware attacks surge 14% amid growing cyberthreats | TechTarget
- Ransomware Attacks on K-12 Trend Down, Higher Ed …
- Healthcare ransomware roundup: Q1 2026 stats on attacks …
