1,067 Victims in 30 Days: Inside August 2026's Global Ransomware Wave

A US federal law enforcement agency. A $10 billion wealth management firm. A children’s school system. A Turkish hospital. In August 2026 alone, ThreatMon tracked 1,067 ransomware victims worldwide and dug into 11 of the most damaging cases by hand. The data provides a clearer view of ransomware activity during August, including the sectors, regions, and groups most represented in the observed incidents.

Key Findings

  • 1,067 ransomware victims were tracked globally in August 2026, with the US alone accounting for 415, nearly 39% of the total.
  • The top 5 countries (US, Germany, Italy, UK, Canada) made up over 57% of all victims.
  • Manufacturing (17.6%), Technology (14.8%), and Professional Services (12.9%) were the hardest-hit sectors, with Healthcare close behind at 11.2%.
  • 9 different ransomware groups were behind the 11 marquee incidents ThreatMon profiled in depth, spanning the US, Turkey, Japan, Latvia, Brazil, Thailand, and Belize.
  • Qilin is currently the most active group by volume (2,268 victims since 2022); Play is the largest historically (1,312 since 2022).
  • LockBit5 resurfaced in September 2025 a year after law enforcement dismantled its predecessor and has already hit 359 organizations, now with VMware ESXi environments in its crosshairs.
  • Dwell times told their own story: Zayo Group’s breach sat undetected for 11 days, US Bank’s for 19 days, and PCL Holding’s for over two weeks.

August 2026 Ransomware Activity at a Glance

The analysis covers two layers of ransomware activity: 1,067 confirmed victims tracked globally across leak sites, dark web sources, and direct incident monitoring, alongside 11 incidents selected for deeper case-level analysis based on the profile of the affected organizations and the impact of the attacks. 1,067 confirmed ransomware victims worldwide, tracked across leak sites, dark web forums, and direct incident monitoring. The second is the close-up: 11 specific attacks ThreatMon dug into case by case, because of who they hit or how badly.

The 11 incidents were selected based on the profile of the affected organizations and the impact of the attacks. They include a US federal agency (the ATF), a Brazilian government intranet, a Houston wealth management firm managing $10.3 billion, a 2,000-employee Japanese manufacturer, and a Turkish hospital. Nine separate ransomware groups were behind them some brand new, some approaching their fourth year of operation.

Victims and Ransomware Groups Behind the Activity

The victims cluster into a few recognizable buckets. Manufacturing took the heaviest hits Hayward Holdings (US, pool and spa equipment, NYSE-listed), Corona Corporation (Japan, heating and cooling systems since 1937), and Latoplast (Latvia). Government and critical infrastructure showed up more than once: the ATF, the City of Winchester in Kentucky, and Brazil’s federal intranet all made the list. Finance had two heavyweight cases US Bank and CAZ Investments, a Houston-based firm serving high-net-worth clients. Healthcare (Erdem Hospital, Turkey) and telecom (Zayo Group) rounded things out, alongside PCL Holding, a Thai medical-diagnostics distributor.

The groups varied significantly in operational history and activity levels:

  • Qilin 2,268 victims since October 2022, Russian-speaking, Golang-based ransomware with operator-controlled encryption modes.
  • Play (PlayCrypt) 1,312 victims since 2022, historically the most prolific, with a heavy concentration in Latin America and a custom .NET infostealer for network reconnaissance.
  • TheGentlemen 837 publicly confirmed victims, but a compromised command-and-control server in 2026 revealed over 1,570 linked victims nearly double what was publicly known. Runs a RaaS model with a striking 90% revenue cut for affiliates.
  • LockBit5 359 victims since resurfacing in September 2025, targeting Windows, Linux, and VMware ESXi environments with cross-platform payloads.
  • RansomHouse 207 victims since 2021, now using a multi-layered dual-key encryption scheme.
  • Direwolf 134 victims since April 2025, a small human-operated crew demanding up to $500,000 per target.
  • Settra and Falcon two newcomers. Settra racked up 64 victims in just three months (June–August 2026) before activity dropped off; Falcon has only 3 confirmed victims so far and looks like it’s still in a testing phase.

Geographic and Sector Distribution

North America and Western Europe absorbed most of the impact. The US alone accounted for 415 of the 1,067 tracked victims more than the next nine countries combined. Germany, Italy, the UK, and Canada followed at a distance, together adding another 18% or so.

The incidents were distributed throughout August, with confirmed cases affecting organizations across government, finance, manufacturing, healthcare, and other sectors. Intranet Gov Brasil on August 6, PCL Holding discovered August 3 (attacked back in mid-July), the City of Winchester on August 10, CAZ Investments on August 21, Corona Corporation on August 23, Erdem Hospital on August 30, and Hayward Holdings on the very last day of the month. 

Targeting Patterns Across Sectors

The observed targeting patterns reflect a combination of financial incentive, operational disruption, and access to sensitive data. Manufacturing, technology, and professional services companies depend on constant uptime and sit on valuable intellectual property that combination makes them likely to pay rather than absorb weeks of downtime. Wealthy, developed economies simply have more of these companies, which is the simplest explanation for why the US, Germany, Italy, the UK, and Canada dominate the victim list.

But a few cases go beyond opportunism. Hitting the ATF or a national government intranet isn’t really about the ransom it’s about proving that even hardened, high-profile targets are reachable, which becomes its own kind of leverage and reputation for the attacker.

Observed Attack Patterns and Tooling

Nearly every group in this report runs the same playbook: get in, sit quietly, steal data, then encrypt and threaten to leak it if the ransom isn’t paid. 

Some intrusions moved fast Hayward Holdings, Corona Corporation, and City of Winchester were all discovered the same day they were attacked. Others sat for weeks. Zayo Group’s compromise went undetected for 11 days, US Bank’s for 19, and PCL Holding’s for over two weeks after the initial breach in mid-July. Longer dwell times provide attackers with additional opportunities for network reconnaissance, lateral movement, data discovery, and exfiltration before detection.

On the technical side, a handful of tools show up again and again across otherwise unrelated groups:

Cobalt Strike     — post-exploitation framework, lateral movement
Mimikatz          — credential theft from memory
AnyDesk           — legitimate remote-access tool, abused for persistence
Rclone            — legitimate sync tool, abused for bulk data exfiltration

Newer groups like Qilin, Direwolf, and TheGentlemen have also standardized on Golang for their ransomware payloads. It compiles to a single cross-platform binary and makes reverse engineering noticeably harder, which is part of why groups keep adopting it.

Key Risk Implications

The Hayward Holdings incident illustrates the impact of double extortion beyond file encryption. Falcon’s leak-site post didn’t just claim encrypted files it listed Salesforce records, over a million customer records with PII, distributor pricing lists, IT infrastructure blueprints, and privileged account credentials. Even a full recovery from backups doesn’t undo that kind of exposure; the stolen credentials alone create risk for months afterward.

LockBit5’s return is worth watching closely too. Law enforcement dismantled the original LockBit infrastructure in February 2024, and the brand was effectively silent for over a year. Its re-emergence with cross-platform payloads that specifically target VMware ESXi the hypervisor software running much of the world’s virtualized infrastructure demonstrates how ransomware operations can resume activity with updated tooling following disruption.

ThreatMon Analysis

The difference between TheGentlemen’s publicly claimed victim count and the number identified through its compromised command-and-control infrastructure highlights a limitation of relying on leak-site monitoring alone. While 837 victims were publicly confirmed, infrastructure-level visibility revealed more than 1,570 linked victims.

This discrepancy demonstrates the value of combining leak-site intelligence with continuous C2 and infrastructure monitoring to gain broader visibility into ransomware operations.

The dwell-time data also reinforces the importance of early detection. Several incidents remained undetected for 11 to more than 20 days, providing attackers with additional time for lateral movement, asset discovery, and data exfiltration. MFA, tested immutable backups, timely patching, and network segmentation remain important controls for reducing the potential impact of these intrusions.

Table of Contents
advanced divider

More posts

This image is about multiple Nginx vulnerabilities.
This image is about multiple Microsoft IIS vulnerabilities.
This image is about SMTP open mail relay vulnerability.
advanced divider

Share this article

Found it interesting? Don’t hesitate to share it to wow your friends or colleagues

advanced divider

Subscribe to our blog newsletter to follow the latest posts