Skip to content
You can now search across every topic, entity and event.What's new
Cybersecurity: Threats and Defences
5SEP

Ransomware claims rose 11 per cent in August

2 min read
12:09UTC

ThreatVectr counted 1,088 ransomware leak-site claims in August against 976 in July, with the number of groups posting a victim up from 68 to 83. Italy climbed faster than any other country.

TechnologyDeveloping
Key takeaway

August leak-site claims rose 11 per cent, with Italy contributing a fifth of the growth.

ThreatVectr, a commercial tracker that counts postings on criminal leak sites, recorded 1,088 ransomware claims in August against 976 in July, a rise of 112, while the number of groups posting at least one victim went from 68 to 83 12. A leak site is the criminal-run page where a crew names an organisation it says it has breached, usually to pressure it into paying.

Qilin claimed 165 August victims after 127 in July and took first place. The Gentlemen fell from 137 to 116 and second place, having passed Qilin in a shorter tracker window over the turn of the month . Qilin has topped a monthly ranking before, on a different tracker's June count , so the order changing hands twice inside a summer says less about capability than about who is posting.

The country breakdown carries the finding. The United States share barely shifted, 34.1 per cent in July and 33.5 in August, so American claims grew roughly in step with the total: 333 of 976, then 365 of 1,088. That works out at 32 of the 112 additional claims. Italy rose faster than anywhere else, from 27 claims and seventh place to 50 and third, a jump of 85 per cent inside one month 34. Those 23 extra claims account for roughly a fifth of the month's growth, and the published breakdown does not say where the remaining half sits.

These are claims posted by criminals, not confirmed breaches, and ThreatVectr says as much: crews exaggerate, duplicate and occasionally invent. ThreatVectr also revised both months upward after first publishing them, as leak-site counts move when late postings are scraped, so treat the totals as an estimate rather than a closed number. BlackFog, a data-security vendor that counts publicly disclosed attacks instead of leak-site posts, recorded 111 disclosed attacks across 27 countries in July and named The Gentlemen the month's most active crew on 11 attacks 5. Two methods, two leaders, and what actually changed in August is who posts most.

Deep Analysis

In plain English

Ransomware gangs often publish a list of victims who have not paid, to pressure them, on what is called a leak site. ThreatVectr counts those posts each month to track ransomware activity. August saw more posts and more active gangs than July. Qilin became the most active gang. Italy saw a big jump in claimed victims, rising from seventh to third place among countries.

Deep Analysis
Root Causes

Ransomware-as-a-service lowers the barrier for a leak site to launch, since operators lease encryptors and infrastructure rather than build them, so a rise in posting groups can reflect affiliate churn between brands more than a genuine increase in criminal capacity.

Qilin's move to first place with 165 claims, displacing The Gentlemen's 116, points to an active affiliate market where crews compete on payout share and tooling rather than on loyalty to one brand.

First Reported In

Update #13 · Four privileged platforms under live attack

ThreatVectr Intelligence· 5 Sept 2026
Read original
Different Perspectives
ENISA
ENISA
ENISA published an SME cyber-resilience maturity model on 6 August and updated the Cyber Resilience Act reporting-platform FAQ on 31 August. The agency supplies common implementation tools for smaller operators, but it cannot fine organisations that do not use them.
UAE Cyber Security Council
UAE Cyber Security Council
On 10 August, the UAE Cyber Security Council said national teams contained attacks on aviation, energy and education before objectives were reached. Its second monthly statement, after a 3 July financial-sector disclosure, makes public reporting of stopped attacks part of its operating posture.
South African authorities
South African authorities
INTERPOL said on 25 August that South African authorities made 39 arrests, seized US$2.67 million and blocked 257 accounts during Operation Jackal IV. Their share of the 23-country operation shows the material enforcement burden in a cross-border fraud case.
Europol
Europol
On 2 September, Europol announced the sinkholing of Sality after a 31 August operation involving US, Bulgarian, Hungarian and Romanian authorities. Its more than 11 million linked IP addresses measure infrastructure contact, not confirmed victims, and show why technical partners joined the action.
CISA
CISA
From 3 August to 2 September, CISA recorded three-day deadlines for 24 of 37 KEV additions, compared with 34 of 39 from 10 June to 29 July. The falling share changes the urgency signal that US federal agencies and private-sector tooling draw from the catalogue.
Beacon
Beacon
On 3 September, Beacon said its final report found that an intruder likely exported its customer database during roughly one hour and 27 minutes on 27 July. Charities using the CRM now have a named exposure route, a compromised AWS access key in public build artefacts.