Independent Reporting · Not Legal or Security Advice · Verify With the Breached Company · Editorial Policy

Ransomware Attacks FAQ for September 2026: Source-Checked Answers to Common Questions

In September 2026, ransomware is still a leading cyber threat. The FBI logged thousands of complaints in 2025, and federal agencies issued new alerts on the Gunra and Medusa groups in August 2026. This FAQ covers the latest figures, the groups named in recent warnings, the first steps an organization should take and where victims can report an attack.

Ransomware is malicious software that locks or steals an organization's data. The attackers then demand payment to unlock the data or to keep it from being published. The answers below draw on FBI and CISA material, and they explain what those sources can and cannot tell you.

Table of Contents

How many ransomware attacks were reported in 2025?

The FBI's 2025 Internet Crime Report says its Internet Crime Complaint Center (IC3) received 3,611 ransomware complaints in 2025. Reported losses from those complaints topped $32 million. That ransomware total is part of a much larger picture. Across all types of cybercrime, IC3 counted $20.9 billion in US losses in 2025, up 26% from 2024.

It was also the first year IC3 received more than 1 million complaints. Critical infrastructure took a steady share of the attacks. FBI figures reported by Yahoo News show ransomware complaints from US infrastructure organizations rose about 9% in 2025. More than 2,100 related incidents were reported to federal authorities that year.

Why the $32 million figure understates the real cost

The IC3 loss figure leaves out downtime, recovery work and other operating losses, as GovTech's coverage of the FBI report notes. Ransomware's true cost is therefore far higher than $32 million. For a hospital or a city government, the ransom is often a small part of the damage. A week of offline systems, rebuilt servers and staff overtime can easily cost more.

Keep that in mind when you use the IC3 total to budget for defenses or judge your insurance coverage. The complaint count has limits too. It only includes victims who reported to IC3. It does not show every attack that happened.

Which ransomware groups are the most active?

FBI IC3 data compiled by VikingCloud shows the top five variants by complaint count in 2024. They were Akira, LockBit, RansomHub, Fog and Play. Industry trackers named Qilin the most active group in 2025.

The two rankings measure different things. The FBI list counts US complaints, while industry trackers usually count victims listed on leak sites. Groups also rename themselves, split up and disappear, so a ranking is a snapshot rather than a fixed threat list.

What did the August 2026 Gunra and Medusa advisories say?

On Aug. 10, 2026, CISA, the FBI, the NSA, DC3, the Secret Service and South Korea's national police agency issued a joint warning about Gunra. CISA advisory AA26-222A says Gunra affiliates target healthcare, financial services, government facilities and nonprofits around the world. Gunra first appeared in April 2025. It is built from leaked source code of Conti, an older ransomware group. It uses double extortion, meaning the attackers encrypt the victim's data and also threaten to leak it.

By early 2026, Gunra was recruiting affiliates on dark-web forums as ransomware-as-a-service. In that model, the developers rent the malware to other criminals, who carry out the attacks. On Aug. 18, 2026, the FBI and its partners published a new #StopRansomware advisory on Medusa. It updates the joint Medusa advisory first issued in March 2025. If your team acted on the 2025 version, check the new one for changes.

What should organizations patch first?

The Gunra advisory names two ways attackers get in: CVE-2024-55591 and CVE-2025-24472. Both are flaws in internet-facing devices. Start by patching those flaws on edge devices, the equipment that sits between your network and the internet.

  • List every internet-facing device and check whether either CVE applies to it.
  • Apply patches, or take exposed management interfaces offline until you can.
  • Compare your detection rules with the guidance in the Gunra and Medusa advisories.
  • Keep offline backups so you can restore data without paying a ransom.

Frequently Asked Questions

Where can I find every current federal ransomware alert?

CISA's StopRansomware alerts page lists every joint CISA and FBI alert, with detection and mitigation guidance for each one.

Who should a victim report a ransomware attack to?

Victims can report incidents to the FBI's IC3 or to CISA.

Is Gunra related to Conti?

Yes. According to the joint advisory, Gunra was built from leaked Conti source code.


You Might Also Like

Owed money from a settlement? Check what is open at OpenClassActions.com. Caring for someone with dementia? Find practical guides at HelpDementia.com. Working out a skin routine? Evidence-based answers at AcneAdvocate.com. Forgot the name of a movie? Identify it at FindThisMovie.com.

We use cookies to run this site, measure how it’s used, and show ads. Choose “Essentials only” to limit cookies to what the site needs to work. Privacy Policy. Cookie Policy.