Ransomware activity reached its highest level so far in 2026 in August, with 1,034 organizations publicly named as victims worldwide, according to The Ransomware Brief from Cyble Research and Intelligence Labs (CRIL).
The report tracked 88 ransomware gangs during the month, with activity rising 25% from July after a 60% increase the previous month. CRIL said the surge suggests a new baseline for ransomware activity rather than a temporary seasonal spike.
In the Philippines, 10 organizations were claimed as ransomware victims, tying the country with China for fifth place in Asia-Pacific. Half of the Philippine claims were attributed to Qilin, identified by CRIL as the world’s most active ransomware group during August.
Asia-Pacific recorded 143 victims, representing 13% of global activity. Qilin, however, was not the region’s leading group. The Gentlemen claimed 20 victims in Asia-Pacific, compared with Qilin’s 16. Regional groups Krybit and orova also recorded significant activity.
Globally, Qilin claimed 145 victims, while The Gentlemen claimed 110. The United States accounted for 484 victims, or 48% of the global total.
CRIL attributed the increase primarily to affiliate recruitment and exploitation of internet-facing infrastructure, rather than advances in ransomware encryption technology. Attackers are also increasingly using data theft as an extortion method without encrypting systems, while AI is being used to accelerate parts of the attack process.
For organizations, CRIL recommends prioritizing patching of internet-facing systems, phishing-resistant multi-factor authentication, network segmentation, tested offline backups, and monitoring for compromised credentials and exposed data.
The findings highlight the need for organizations to strengthen fundamental cybersecurity controls as ransomware groups expand their reach and increasingly use automation and AI to improve attack efficiency.


