A US federal law enforcement agency. A $10 billion wealth management firm. A children’s school system. A Turkish hospital. In August 2026 alone, ThreatMon tracked 1,067 ransomware victims worldwide and dug into 11 of the most damaging cases by hand. The data provides a clearer view of ransomware activity during August, including the sectors, regions, and groups most represented in the observed incidents.
The analysis covers two layers of ransomware activity: 1,067 confirmed victims tracked globally across leak sites, dark web sources, and direct incident monitoring, alongside 11 incidents selected for deeper case-level analysis based on the profile of the affected organizations and the impact of the attacks. 1,067 confirmed ransomware victims worldwide, tracked across leak sites, dark web forums, and direct incident monitoring. The second is the close-up: 11 specific attacks ThreatMon dug into case by case, because of who they hit or how badly.
The 11 incidents were selected based on the profile of the affected organizations and the impact of the attacks. They include a US federal agency (the ATF), a Brazilian government intranet, a Houston wealth management firm managing $10.3 billion, a 2,000-employee Japanese manufacturer, and a Turkish hospital. Nine separate ransomware groups were behind them some brand new, some approaching their fourth year of operation.
The victims cluster into a few recognizable buckets. Manufacturing took the heaviest hits Hayward Holdings (US, pool and spa equipment, NYSE-listed), Corona Corporation (Japan, heating and cooling systems since 1937), and Latoplast (Latvia). Government and critical infrastructure showed up more than once: the ATF, the City of Winchester in Kentucky, and Brazil’s federal intranet all made the list. Finance had two heavyweight cases US Bank and CAZ Investments, a Houston-based firm serving high-net-worth clients. Healthcare (Erdem Hospital, Turkey) and telecom (Zayo Group) rounded things out, alongside PCL Holding, a Thai medical-diagnostics distributor.
The groups varied significantly in operational history and activity levels:
North America and Western Europe absorbed most of the impact. The US alone accounted for 415 of the 1,067 tracked victims more than the next nine countries combined. Germany, Italy, the UK, and Canada followed at a distance, together adding another 18% or so.
The incidents were distributed throughout August, with confirmed cases affecting organizations across government, finance, manufacturing, healthcare, and other sectors. Intranet Gov Brasil on August 6, PCL Holding discovered August 3 (attacked back in mid-July), the City of Winchester on August 10, CAZ Investments on August 21, Corona Corporation on August 23, Erdem Hospital on August 30, and Hayward Holdings on the very last day of the month.
The observed targeting patterns reflect a combination of financial incentive, operational disruption, and access to sensitive data. Manufacturing, technology, and professional services companies depend on constant uptime and sit on valuable intellectual property that combination makes them likely to pay rather than absorb weeks of downtime. Wealthy, developed economies simply have more of these companies, which is the simplest explanation for why the US, Germany, Italy, the UK, and Canada dominate the victim list.
But a few cases go beyond opportunism. Hitting the ATF or a national government intranet isn’t really about the ransom it’s about proving that even hardened, high-profile targets are reachable, which becomes its own kind of leverage and reputation for the attacker.
Nearly every group in this report runs the same playbook: get in, sit quietly, steal data, then encrypt and threaten to leak it if the ransom isn’t paid.
Some intrusions moved fast Hayward Holdings, Corona Corporation, and City of Winchester were all discovered the same day they were attacked. Others sat for weeks. Zayo Group’s compromise went undetected for 11 days, US Bank’s for 19, and PCL Holding’s for over two weeks after the initial breach in mid-July. Longer dwell times provide attackers with additional opportunities for network reconnaissance, lateral movement, data discovery, and exfiltration before detection.
On the technical side, a handful of tools show up again and again across otherwise unrelated groups:
Cobalt Strike — post-exploitation framework, lateral movement
Mimikatz — credential theft from memory
AnyDesk — legitimate remote-access tool, abused for persistence
Rclone — legitimate sync tool, abused for bulk data exfiltrationNewer groups like Qilin, Direwolf, and TheGentlemen have also standardized on Golang for their ransomware payloads. It compiles to a single cross-platform binary and makes reverse engineering noticeably harder, which is part of why groups keep adopting it.
The Hayward Holdings incident illustrates the impact of double extortion beyond file encryption. Falcon’s leak-site post didn’t just claim encrypted files it listed Salesforce records, over a million customer records with PII, distributor pricing lists, IT infrastructure blueprints, and privileged account credentials. Even a full recovery from backups doesn’t undo that kind of exposure; the stolen credentials alone create risk for months afterward.
LockBit5’s return is worth watching closely too. Law enforcement dismantled the original LockBit infrastructure in February 2024, and the brand was effectively silent for over a year. Its re-emergence with cross-platform payloads that specifically target VMware ESXi the hypervisor software running much of the world’s virtualized infrastructure demonstrates how ransomware operations can resume activity with updated tooling following disruption.
The difference between TheGentlemen’s publicly claimed victim count and the number identified through its compromised command-and-control infrastructure highlights a limitation of relying on leak-site monitoring alone. While 837 victims were publicly confirmed, infrastructure-level visibility revealed more than 1,570 linked victims.
This discrepancy demonstrates the value of combining leak-site intelligence with continuous C2 and infrastructure monitoring to gain broader visibility into ransomware operations.
The dwell-time data also reinforces the importance of early detection. Several incidents remained undetected for 11 to more than 20 days, providing attackers with additional time for lateral movement, asset discovery, and data exfiltration. MFA, tested immutable backups, timely patching, and network segmentation remain important controls for reducing the potential impact of these intrusions.