Independent Reporting · Not Legal or Security Advice · Verify With the Breached Company · Editorial Policy

Ransomware Attacks August 2026 Update: What Changed, Why It Matters, and What to Watch Next

August 2026 brought a sharper ransomware warning: reported activity hit a year-to-date high while authorities flagged expanding affiliate operations and faster exploitation of exposed systems. Ransomware—malware used to lock data, often paired with threats to publish stolen files—now demands closer attention to firewalls, VPNs, backups, and criminal leak-site claims. The evidence does not establish a confirmed total for August attacks. Instead, it combines July activity data, August government advisories, a federal cybersecurity incident, and a major criminal sentence.

Table of Contents

How large was the reported surge?

NCC Group recorded 894 ransomware cases in July, a 22% increase from June and the highest monthly total of 2026 through July. Industrial organizations represented 28% of cases, while North America and Europe accounted for 70%, according to NCC Group's August threat review. Those numbers measure recorded cases, not a fully confirmed incident count.

NCC Group highlighted that distinction when CRPxO claimed 36 July victims but supplied inconsistent supporting evidence. Leak sites remain useful for spotting shifts in criminal activity, but their claims may be incomplete, duplicated, exaggerated, or unsupported. Readers should avoid treating every posted name as a verified breach.

Why Gunra changes the risk picture

An August 10 advisory described Gunra as an emerging ransomware-as-a-service operation that expanded its affiliate program in 2026. In this model, core operators provide ransomware tools to other criminals who conduct attacks and share the proceeds. Gunra uses double extortion: attackers steal data and encrypt systems, creating separate threats of disclosure and operational disruption. The joint U.S.

and South Korean government advisory says victims span major regions and sectors including healthcare, finance, manufacturing, transportation, government, utilities, academia, media, retail, and nonprofits. The group primarily enters through vulnerabilities in internet-facing firewalls and virtual private networks. Its attacks have also deleted shadow copies and, in one case, backup and archived data across primary and disaster-recovery environments. A backup connected to the same vulnerable environment may therefore fail when it is needed most.

What the Medusa update adds

CISA, the FBI, and HHS updated their Medusa advisory on August 18 after FBI investigations identified activity through April. Medusa had affected more than 500 victims across medical, education, legal, insurance, technology, and manufacturing organizations, according to the updated federal advisory. Medusa now operates through affiliates and combines encryption with data-theft extortion.

Authorities also found that its operators exploit newly announced vulnerabilities rapidly, reducing the safe delay between disclosure and patching. The recommended defenses address both entry and spread: patch promptly, segment networks, and restrict access to remote services from untrusted sources. Organizations should prioritize exposed firewalls, VPNs, and remote-management pathways rather than relying only on endpoint defenses.

What August events do—and do not—show

ATF disclosed an August cybersecurity incident involving a standalone system, disconnected that system, and began forensic work with the Justice Department. Officials classified it as a "major incident" but said enterprise systems, eForms, missions, and other ATF systems were unaffected, according to the agency's August 26 statement. ATF did not identify the event as ransomware in the supplied disclosure, so it should not be counted as a ransomware attack without further evidence.

The incident instead illustrates why confirmed scope and official attribution matter when early reports emerge. August also brought criminal accountability. On August 5, the Justice Department announced a 16-year sentence for a Belarusian creator of Ransom Cartel, an operation that attacked at least 18 companies worldwide from 2021 through 2023 and demanded payment for decryption or nonpublication of stolen data.

What defenders should watch next

The immediate priorities follow the observed attack paths and recovery failures: Backup testing should measure whether an organization can restore essential systems after primary data, shadow copies, archives, and disaster-recovery resources are targeted together. Record the last successful restore test and confirm that at least one recovery copy remains isolated from production systems.

  • Inventory every internet-facing firewall, VPN, and remote service.
  • Apply available security updates promptly, especially after new vulnerabilities are announced.
  • Restrict remote access from untrusted sources and segment critical systems.
  • Keep isolated, immutable backups that attackers cannot alter or delete.
  • Test restoration from both primary and disaster-recovery environments.

You Might Also Like

Owed money from a settlement? Check what is open at OpenClassActions.com. Caring for someone with dementia? Find practical guides at HelpDementia.com. Working out a skin routine? Evidence-based answers at AcneAdvocate.com. Forgot the name of a movie? Identify it at FindThisMovie.com.

We use cookies to run this site, measure how it’s used, and show ads. Choose “Essentials only” to limit cookies to what the site needs to work. Privacy Policy. Cookie Policy.