ervik.as
August 2026

August 2026 Ransomware Report: 1,461 Victims Tracked, The Gentlemen Overtakes Qilin as the Month's Most Active Group

A data-driven analysis of August 2026's ransomware activity — built from our own live leak-site tracking, cross-referenced against Japan's official police statistics, BlackFog's monthly incident tracker, and CYFIRMA's threat intelligence. The month's single biggest story in our own data: two inconsistently-recorded name variants for the same group, once combined, reveal The Gentlemen as August's most active operation, not Qilin.

By Alexander Ervik Johnsen · September 14, 2026
1,461
Victims Tracked
112
Active Groups
32%
Country-Attributed

Most Active Groups

Most Targeted Sectors

Most-Attributed Countries(of the 465 victims with a known country, out of 1,461 total)

A Note on Methodology Before the Numbers

Start with the honest caveat that shapes everything below, because a report that hides its own limitations isn't worth trusting. This analysis is built primarily from our own accumulated leak-site tracking — 1,461 ransomware victim disclosures discovered between August 1 and August 31, 2026, across a genuinely complete month of data (our tracking began July 30, so there's no partial-month gap at the start). That data comes with real gaps of its own: country attribution was available for only 465 of the 1,461 victims (about 32%), and a usable, specific sector was available for even fewer — roughly 265 (about 18%), with the remainder split across null values, and generic "Not Found" or "Other" placeholders that aren't genuine industry categories. Wherever this report presents a country or sector breakdown, it's describing the attributed subset specifically, not the full 1,461 — and that distinction matters, because a group's or sector's true share of total activity could look meaningfully different if the unattributed two-thirds were evenly distributed versus concentrated somewhere specific, which there's currently no way to know from this data alone.

One specific data-quality catch is worth walking through in detail, because it changes the single most important finding in this report. Our raw group-level tally showed "the gentlemen" with 136 victims and a separately-recorded "thegentlemen" with 81 — two different spellings of the exact same ransomware operation, split across our tracking by inconsistent formatting at the source. Combined, that's 217 victims for The Gentlemen in August alone, comfortably ahead of Qilin's 168. Left uncorrected, this exact kind of naming inconsistency would have reported the wrong group as August's most active — a useful, concrete reminder of why raw leak-site aggregation needs a normalization pass before its numbers mean anything, and why this report cross-references independent sources rather than presenting our own tracking as the final word.

The Gentlemen's August: From Rapid Riser to Most Active

The correction isn't just a data-cleanup footnote — it lines up with real, independently-documented growth. Threat intelligence firm GuidePoint Security has tracked The Gentlemen's trajectory since the group first appeared in August 2025, expanding from 35 victims in the fourth quarter of that year to 182 in the first quarter of 2026 alone, already making it the second-most-active group industry-wide by that point. Our own August numbers are consistent with a group that kept accelerating past that milestone rather than plateauing.

What The Gentlemen actually hit in August, cross-referenced against BlackFog's independently-sourced monthly incident tracker, spans a genuinely global and sector-agnostic range: Oleoductos del Valle, operator of Argentina's primary oil pipeline network carrying crude from the Vaca Muerta formation; the Kenaitze Indian Tribe in Alaska, where the attack disrupted internet, phone, and email access to health care, education, and social services; Hong Kong Baptist University, affecting nearly 1,800 user accounts; and smaller, more opportunistic hits — an Australian children's kidswear retailer, a Greek coffee chain, an Australian vitamin manufacturer. That range — critical energy infrastructure and a tribal government's essential services sitting alongside a coffee chain and a kidswear brand — is itself the notable pattern: The Gentlemen isn't specializing by sector or by target sophistication, it's running at genuine volume across whatever access its affiliates can get.

Qilin's August: Government and Critical Infrastructure, Deliberately

Qilin's own August activity, while landing second in our normalized count, included the month's single most consequential incident by official designation. The group claimed responsibility for a cyberattack on the US Bureau of Alcohol, Tobacco, Firearms and Explosives, which the Department of Justice formally designated a "major incident" — the breach reportedly reached a standalone system tied to the Communications Assistance for Law Enforcement Act, though the ATF maintains its wider network and operational systems were unaffected. Qilin's other August targets skew toward education and mid-size organizations specifically: Brazosport College in Texas (disrupting registration and financial aid mid-semester), the University of the West Indies, French rugby club Stade Français Paris, and Australian flooring and app-development firms. Where The Gentlemen reads as volume-driven and largely opportunistic, Qilin's August activity reads as more willing to claim credit for hitting government and institutional targets specifically — a distinction worth tracking into September, since it suggests two different operating philosophies converging on similar victim counts through different targeting logic.

Clop's Quieter, Industrially-Focused Wave

Clop's 90 tracked August victims undersell what the group was actually doing that month. Independent reporting from BleepingComputer confirmed Clop named Royal Philips, General Electric, and Shell in the same wave of claims — Philips confirmed a genuine breach of an enterprise server while stressing customer environments were unaffected; Shell and GE were both still investigating their own claimed exposure as of early September. Add Mindray, the Chinese medical device giant whose equipment sits in hospitals worldwide, and Midland, an Australian truck and trailer manufacturer named among "dozens" of organizations in the same campaign per CyberDaily's reporting — and Clop's August reads less like scattered individual attacks and more like a single, coordinated data-theft campaign running in parallel across major industrial and healthcare-adjacent targets simultaneously, consistent with Clop's well-established pattern of favoring mass, coordinated exploitation waves over one-off intrusions.

The Incidents That Defined the Month

A handful of August's disclosures deserve attention beyond their group attribution, either for scale or for what they reveal about the current threat environment. Berlin's state government refused to pay a ransom after Rhysida claimed responsibility for exfiltrating 5.79 terabytes of government data — tens of thousands of contracts, emails, and potentially classified material — which the group is attempting to auction for at least 30 Bitcoin; officials confirmed sensitive data was compromised without verifying Rhysida's full claims. McKesson, the healthcare and pharmaceutical distribution giant, confirmed ShinyHunters gained access through voice-phishing employee accounts before exfiltrating roughly 1 terabyte of data spanning 284 million records, with a reported $55 million demand attached. DireWolf claimed the National Kidney Registry, a nonprofit coordinating living-donor kidney transplants across the US, alleging theft of 253GB including donor suitability records — a target whose disruption risk extends directly to people waiting on organ matches, regardless of whether the group's full claims hold up. And Orova's claimed breach of Cardiology Associates of Port Huron, a Michigan practice, allegedly exposed records for more than 150,000 patients — one of the largest single healthcare claims of the month by patient count, though as with several entries here, the practice itself had not publicly confirmed the breach as of this report.

Sectors and Countries: What the Attributed Data Shows

Among the roughly 265 August victims with a specific, non-generic sector recorded, Technology led with 65, followed by Manufacturing (57), Professional Services (50), Retail & E-Commerce (38), Healthcare (38), Financial Services (19), and Transportation (18). Worth reading against that: BlackFog's named-incident list for the same month skews visibly more healthcare-heavy than our own attributed sector breakdown suggests — cardiology practices, dental clinics, addiction treatment centers, genetic testing labs, and medical device manufacturers appear repeatedly through the month. The likely explanation is a genuine measurement difference rather than a contradiction: healthcare breaches are disproportionately likely to trigger public HIPAA-driven disclosure requirements in the US specifically, making them more likely to surface in named-incident tracking even when the underlying leak-site posting itself didn't include an attributable sector tag in our own data. Geographically, among the roughly 465 country-attributed August victims, the US led decisively with 153, followed by Germany (35), a combined Italy total of 25 once "IT" and "Italy" entries are merged, the UK (21), India (14), Canada (12), Brazil (11), and Mexico (10).

The Wider Picture: A Documented, Accelerating Global Surge

Our own 1,461-victim count sits inside a broader trend independently confirmed by multiple sources this month. Italian threat intelligence firm Cyberoo, citing public data from Ransomfeed, reported that global ransomware attacks rose from 512 in August 2025 to 1,165 in August 2026 — a 128% year-over-year increase using a narrower "claimed attack" methodology than our own broader leak-site victim count, but pointing in the same clear direction. Japan's National Police Agency, in a September 10 disclosure, confirmed a related but separate data point: 123 ransomware cases in the first half of 2026 nationally, the highest half-year total since comparable tracking began in 2020, with manufacturing absorbing the largest single share at 37 cases and small and medium-sized enterprises accounting for 60% of all victims. Different measurement methods, different scopes, same underlying story: ransomware activity kept climbing through the summer of 2026, not slowing down.

Looking Ahead to September

The corrected group rankings from this report — The Gentlemen ahead of Qilin, not behind it — are worth carrying into how September's data gets read from day one, rather than discovering the same naming inconsistency a month from now. Clop's parallel industrial campaign against Philips, GE, and Shell was still under investigation at several of those companies as August closed, meaning September's report will likely be where the actual scope of that wave becomes clearer. And given roughly two-thirds of our own August victims carry no country attribution and over three-quarters carry no specific sector, closing that data gap — through better upstream source normalization, not just larger raw victim counts — is the single highest-value improvement we can make before the next report, not a secondary concern.

RansomwareMonthly Report
Share Share
Advertisement