When ransomware reports are published, attention usually goes straight to the total victim count. For June 2026, that figure stands at 625. However, the more meaningful insights lie beneath the headline number in the geographic distribution, the targeted industries, and several notable incidents that reveal how ransomware operations continue to evolve.
The United States accounts for 199 victims, representing 31.8% of the month’s total. While this is consistent with long-term trends, the countries that follow deserve closer attention. Germany ranks second with 49 victims, followed by Brazil (23), the United Kingdom (21), and India (20).
Brazil’s position ahead of several Western European countries reinforces an important trend: ransomware operators are increasingly prioritizing organizations based on opportunity rather than geography. India, Mexico (14), and Thailand (13) further illustrate that emerging economies are no longer secondary targets. Organizations with valuable data and the ability to pay are attractive regardless of location.
It is also important to recognize that these figures only represent organizations publicly listed on ransomware leak sites. Victims that quietly negotiate or pay without public disclosure are absent from the dataset, meaning the actual impact is likely higher.
Business Services accounts for 21.3% of all observed victims, followed by Manufacturing at 14.6%. Technology, Consumer Services, and Healthcare each represent roughly 9% of the total.
Business Services leading the list is far from coincidental. Accounting firms, certification bodies, auditors, and consultancies routinely store extensive client information alongside their own operational data. Compromising a single organization in this sector can expose contracts, financial records, audit findings, and sensitive documentation belonging to dozens of customers, significantly increasing the value of a successful intrusion.
One case highlighted in the report demonstrates this dynamic particularly well.
The German certification company orion4value.com was claimed by the Settra ransomware group, whose leak site described the incident with the phrase “The certificate as a vulnerability.”
The organization conducts certification against standards including ISO 9001, AS9100, and ISO 14001, maintaining audit documentation, operational assessments, and client compliance records. Sample data released by the attackers referenced contracts with defense contractors, facility information, and employee records.
Perhaps the most significant aspect of this incident is that the exposed information largely belonged to the organization’s customers rather than the certification body itself. It illustrates a classic supply chain risk scenario: an organization’s security posture ultimately depends not only on its own defenses but also on those of trusted third parties.
The intrusion involving touredge.com, a U.S. golf equipment manufacturer, reportedly began on 2 June and was not discovered until 30 June, resulting in a dwell time of 28 days.
This represents the longest confirmed gap within the June dataset. By comparison, several other victims including gov.br, Vienna Airport, AYA Bank, and Ford de Mexico appear to have attack and discovery dates that coincide. In many cases, however, this reflects public disclosure on a ransomware leak site rather than rapid internal detection.
A 28-day window provides ample time for attackers to conduct reconnaissance, escalate privileges, identify and disable backups, and quietly exfiltrate sensitive data. Encryption is typically the final stage of a ransomware campaign, long after the most damaging activities have already occurred.
Flughafen Wien AG, the operator of Vienna Airport, was listed by APT73 with an unusual note: “sold to a third party, no data available.”
Rather than following the traditional double-extortion model of publishing stolen information, the attackers claimed to have sold the data directly to another party.
From a defensive perspective, this may represent an even greater challenge. Publicly leaked data can at least be reviewed, assessed, and communicated to affected stakeholders. Data sold privately creates long-term uncertainty, leaving organizations without visibility into who possesses the information or how it may eventually be used.
For infrastructure operators such as airports, datasets involving cargo operations, technical documentation, or operational logistics may hold significant value beyond the original attack.
June also included attacks affecting critical public-sector organizations.
Brazil’s gov.br platform which provides access to more than 4,200 government services was reportedly compromised. In Myanmar, AYA Bank was claimed by Lapsus$, with the attackers alleging they had obtained a complete database from the institution’s primary platform.
Another notable case involved Cal Fresh, a nonprofit organization assisting low-income Californians with food assistance applications. The organization processes addresses, financial information, and household data belonging to particularly vulnerable individuals.
Unlike commercial enterprises, organizations of this type often have limited financial capacity to respond to ransomware demands. In such cases, the stolen personal information itself may represent the attacker’s primary objective, providing material for identity fraud and other criminal activities.
The six ransomware groups featured in the report represent very different stages of maturity.
Krybit, a ransomware-as-a-service operation first observed in late March 2026, offers affiliates an 80/20 revenue-sharing model while supporting Windows, Linux, ESXi, and NAS environments. Within approximately three months, the group has accumulated 76 claimed victims. It has also attracted attention through a public conflict with rival operation 0APT, during which both groups exposed each other’s internal data.
Settra, first observed on 2 June 2026, claimed 28 victims during its first month of activity. Such rapid growth suggests experienced operators or affiliates rather than a newly assembled team.
Brain Cipher continues to rely on the leaked LockBit Black source code and has reportedly exploited CVE-2023-28252, the Windows CLFS privilege escalation vulnerability. Likewise, much of the publicly available reporting surrounding APT73 points to operational links with the broader LockBit ecosystem.
These examples reinforce a broader reality: dismantling a ransomware brand does not eliminate its codebase, operational knowledge, or affiliate network. Those capabilities frequently reappear under new identities.
The reappearance of Lapsus$ in connection with the AYA Bank incident raises similar questions. Whether the name represents the original group, a successor organization, or actors leveraging a recognizable brand remains difficult to determine with confidence.
The defensive recommendations remain familiar: enforce multi-factor authentication, maintain tested backups, prioritize patch management, rehearse incident response procedures, and strengthen user awareness. The challenge has rarely been understanding these recommendations it has been implementing them consistently.
Three observations stand out from the June data:
Looking ahead, the growth of Settra and Krybit will be worth monitoring. The first few months of activity often provide valuable insight into which ransomware groups are likely to shape the threat landscape over the coming year.