Telling your board in June that ransomware attacks were decreasing would make the figures for July more difficult to present at your next meeting.
The slowdown in the second quarter was only a temporary halt, not a genuine decline. Attacks nearly got back to the level they reached during the year. The sectors of finance and technology recorded the largest month-by-month increases, and those leak sites which had been inactive earlier became active once more. The underground economy’s capacity remained unchanged; it was merely waiting for the next wave.
Yet the number of the attacks is not the most significant aspect of this month, even though the majority of the reports concentrate on it; what truly makes July 2026 stand out are the structural changes which will still be important after the figures have been reset.
AI is no longer merely a subject of debate; it is now taking an active role. It has been discovered that there is ransomware capable of carrying out its own attack chain and malware that selects its targets according to the expected payout. In another instance, an autonomous agent managed to breach the world’s largest public model repository. Within a single month the agents served as both attacker and target and also acted as the targeting engine. Whatever your organisation’s attitude towards AI risk was in June, it is now time to look at it again.
Secondly, attacks are no longer beginning at the perimeter. This month, the link shared by the various victims — a dairy subsidiary, an accounting firm, a taxi operator, a billing vendor, and a national telecommunications regulator — was the fact that they were part of someone else’s supply chain, not that they had a common weakness. The involvement of poisoned npm and PyPI packages, a backdoored obfuscation library, hundreds of fake software repositories, and a third-party platform which exposed the employee data of a Big Four firm all contributed to the situation. Today, the way to manage your attack surface is less about simply applying patches and more about having a full knowledge of your inventory.
Thirdly, the focus of enforcement has changed. On 13 July the sanctions were directed at a VPN provider and a cryptor seller, not at a ransomware group, an affiliate, or a marketplace administrator. This comes after the seizure of the infrastructure in May and the fact that the user database is still having an effect on Russian-language forums. Although one gang is usually replaced by another, disrupting the services that all the gangs depend on could have a more lasting impact. Although it is still early and unproven, this is now the evident strategy.
This report then goes on to give a detailed account of the month, including the figures and the differences between them, the key activities relating to extortion and leak sites, trends in the forums and on data markets, operations concerning critical infrastructure and those linked to state actors, new tools, enforcement actions, and the most widely exploited vulnerabilities. Remember that claims made by leak sites are merely statements by the attackers until a victim verifies them, and any items that have not yet been verified are noted.
1. A short overview of the month
The quiet phase ended in July. Following the slow pace of May and June, the number of extortion cases had once again nearly reached record levels, and The Gentlemen and Qilin competed for the position at the top. Nevertheless, the most significant changes this month were three less obvious ones:
A new stage has been reached. This month two separate campaigns made use of AI agents to carry out the whole of the attack chains, not just to assist with them. This represents a fundamental change, not merely an increase in activity.
The supply chain is now the primary means of access since half of the serious intrusions this month took place via a vendor, an npm package, a PyPI dependency, or a third-party platform rather than by means of the victim’s own perimeter.
The enforcement efforts were directed at the infrastructure rather than at the individuals. On 13 July the sanctions were imposed on a VPN provider and a seller of cryptors. Although the decryption keys were not seized, the underlying services were.
2. By the numbers
The figures will vary according to the method employed. You can view them as three different approaches, not as three methods leading to the same total.
| Source | July count | Change vs. June |
|---|---|---|
| Comparitech | 799 attacks, up from 668 in June — second-highest month of the year behind March’s 805 | +19% |
| ZeroFox | At least 776 ransomware and digital extortion incidents | +22% |
| BlackFog | 111 publicly disclosed attacks across 27 countries, US at 53% | +6.7% YoY |
According to Comparitech, the finance sector increased by 71%, technology rose by 62%, healthcare went up 46% and education also rose by 44%; meanwhile utilities, legal and government sectors all saw a decline. The number of attacks aimed at the US went up by 31% month on month.
Here is the leaderboard: together the Gentlemen and Qilin carried out about 33% of all the attacks — 135 and 125 respectively. The top five entries on ZeroFox’s list were CRPx0, SafePay and INC Ransomware, these five as a group being responsible for at least 344 incidents.
There is a noticeable geographical trend in that the proportion of targets in North America decreased by 12% from the previous year, whereas organisations in Europe compensated for this decline. This indicates that attackers are moving into other areas at a faster rate than they are increasing their presence in the United States.
3. There has been significant activity involving extortion and leak sites
On 16 July, Coca-Cola halted production at its Fairlife dairy after suffering a ransomware attack. Anubis then listed the company, stating that it had encrypted Nutanix infrastructure and had taken about 1TB of corporate data, and threatening to release it unless negotiations took place. Coca-Cola did not confirm the data theft or the attacker’s statement regarding the systems affected, and the claims could not be verified at the time of reporting. The kind of manufacturing shutdown that occurs at a subsidiary of a consumer brand is precisely the kind of pressure scenario these teams are aiming to optimise for.
On 1 July the SafePay company carried out an attack on the Indra Group, a multinational firm involved in defence, air traffic management and digital transformation, as data is said to have been stolen and made available on the internet.
According to a report by Stadler Rail from 22 July, the Swiss train manufacturer has refused to make payment. Different sources give different figures: one states that Anubis asked for $123 million, whereas Comparitech says that Everest demanded 10 million Swiss francs (approximately $12.3 million) and adds that this is Stadler’s second confirmed instance of a ransomware attack. In either case, it is the second such incident and they are still not paying.
From 13 to 15 July, Japan’s biggest taxi operator turned off its internal systems following an attack. The group claimed that 2.9TB of data had been exfiltrated. This had been identified by analysts as AiLock’s first known target in Japan since the group appeared in 2025 — and on the same day it announced a second Japanese victim, a CRM provider, indicating a deliberate move to enter that market.
Clop, once again (24 July). The group has launched another large-scale operation aimed at stealing data from PTC Windchill and FlexPLM systems. Their method is the same as before: they identify a widely used enterprise product, carry out large-scale attacks on it, omit encryption, and instead concentrate on extorting the victims using the data they have stolen. More disclosures of victims are to be expected in the coming two quarters.
On 12 July, DragonForce was given a list concerning a Saudi company that is involved in the chemical and logistics businesses serving the petrochemical sector, with a claimed amount of 115.54 GB stolen and a deadline for the publication of two days. DragonForce operates a cartel-style affiliate model by distributing white-label ransomware builders.
Other examples include Mount Royal University (World Leaks), William Buck in New South Wales (SafePay), Medical Computer Business Services — a medical billing company whose data breach impacted about 1.3 million patients in a number of healthcare organisations (PEAR). Hahn Airport in Germany was compromised by SafePay; Eurohold Bulgaria by KRYBIT.
Unverified. A ransomware group stated that it had breached Deutsche Bank; the bank replied that it was looking into the matter and had not confirmed that a breach had occurred. It should be treated as unproven.
4. Forum and data market activity
The Philippine telecom regulator’s data was listed on BreachForums on 13 July. A user going by the name “DNH” advertised approximately 126GB — amounting to over 200,000 documents containing employee personal data — from the country’s national telecom regulator, stating that the leak was a form of protest against the government’s reaction to a mass shooting in June. Analysts described this as a typical example of hacktivism, since releasing government data could lead to further attacks by other people. Nowadays, the distinction between hacktivism and criminal activity has become blurred.
The month was busy for ShinyHunters. Medtronic informed its customers who had been affected by a breach linked to ShinyHunters on 2 July, and later in the month employee data from EY came to light following a compromise of a third-party platform that was attributable to the same group. The Salesforce-related extortion operation which is responsible for their 2026 output does not appear to be ending.
According to the Bank of Baroda (27 July), there has been a breach resulting from a compromised employee email account. The individual who referred to themselves as TripleX stated that almost 1TB of customer and internal banking data had been obtained; it was reported that the core banking systems were not affected.
On 29 July, a group which calls itself ExfilSquad obtained more than 740,000 records — namely the contact information of government staff, teachers, police officers and members of the public — and asked for payment in order to avoid further leaks.
The number of affected users was 23 million according to Paidwork, while KDDI stated that its breach impacted up to 12 million individuals. SplitVPN had more than 58 million connection logs leaked, even though it had advertised a strict no logging policy. This demonstrates that “no logs” is merely a claim and not a guarantee.
Diplomatic targeting: South Korea’s Ministry of Foreign Affairs has reported a long-term breach as a result of which about 10,000 current and former diplomats and government staff have been affected. The decision was to replace all of the diplomats’ email addresses, a measure which is unusual and indicates the extent of the expected follow-up phishing attacks.
5. Critical infrastructure and activities linked to the state
On 29 July, a coordinated attack focused on the operational technology of more than 30 community water systems, causing a temporary disruption of the automated controls at a number of locations. The drinking water remained safe and the response teams managed to contain the incidents. It is suspected that CyberAv3ngers, a group linked to Iran and associated with the IRGC, carried out the attack. As before, small utilities that have no dedicated security staff and which have PLCs exposed to the internet are still the same easy targets in CyberAv3ngers’ previous campaigns.
On 1 July DHS stated that hackers had gained access to the Homeland Security Information Network, the system used for sharing sensitive information with government agencies and security partners.
The activity in question is linked to Russia. Malware known as Starland was delivered through Trojanized installers for Webex and Zoom, and state-supported groups took advantage of a zero-click vulnerability in Zimbra Collaboration (CVE-2025-66376) in order to steal email and authentication data. Furthermore, in another report, the attack on Jaguar Land Rover, which is estimated to have resulted in losses of $2.5 billion, was attributed to Russian actors.
The malware known as LongLeash, which is associated with China, was employed in order to extend a network of Operational Relay Boxes, thereby compromising internet-connected devices to establish a covert infrastructure for future operations.
6. The move to AI in the area of tooling
I would have written this section in a completely different way six months ago.
JadePuffer was found to be an AI-powered autonomous ransomware program — researchers noted that a large language model carried out the entire attack chain by itself. Dolphin-X employed AI to rank and prioritise high-value victims, which allowed the operators to focus on those targets most likely to pay. Moreover, Hugging Face — the biggest public repository of AI models — was compromised by an autonomous agent that exploited weaknesses in the repository, thereby raising serious questions about the integrity of models that are hosted.
Put together, the agents now function as the attacker, as the target selector, and even as the target.
This month’s other new tools include Spirals, which is able to encrypt a network within 24 hours; the Avalon framework, which provides modular capabilities for post-exploitation and for the delivery of payloads; msaRAT, which was deployed by Chaos in order to achieve persistence before encryption; and MsaRAT, which routes C2 traffic via Chrome and Edge in order to match normal browser behaviour.
Developments on the delivery side involved ChocoPoc inserting malicious code into Python dependencies. The Jscrambler npm package had a backdoor installed which allowed for the theft of information. The AsyncAPI npm packages contained code designed to steal credentials. Almost 300 GitHub repositories pretended to be genuine software. Malware was quietly installed using Notepad++ plugins, and some malicious websites created their payloads directly in browser memory in order to avoid being detected.
Social engineering was carried out by making fake IT support calls through Microsoft Teams, which led to the deployment of EtherRAT. The DNS of hotel Wi-Fi was hijacked in order to gather Microsoft 365 credentials. A fake Claude AI application, which was promoted via ads on Bing, delivered SectopRAT. A group that has recently been identified, named Helix, combined phone-based vishing with an attack on SharePoint.
7. Law enforcement and sanctions
On 13 July the United States and the United Kingdom jointly issued the designations. The Office of Foreign Assets Control (OFAC) designated First VPN Service (1VPNS), its administrator Dmytro Rashevskyi, and Yegeniy Vladimirovich Silayev, who deals in cryptors used to conceal ransomware from security tools. The action was carried out in coordination with the UK’s Foreign, Commonwealth & Development Office and came after the takedown in May 2026 of the 1VPNS infrastructure, a move that was supported by the FBI. The FBI also issued a complementary advisory on 1VPNS’s tradecraft.
The information available in May enables an explanation of the present exposure risk: Europol obtained the service’s user database and spotted VPN connections, thus exposing thousands of users who were involved in cybercrime. These users had been informed. Ever since, the underground reaction has been straightforward — migration, mutual blaming, and an increase in operational security on the Russian-language forums.
This month as well, the EU and the UK jointly imposed sanctions on Russian cyber actors and the organisations that support them; the United States sanctioned the VPN and malware service providers who support ransomware gangs; and the Finnish authorities published an international wanted notice concerning the suspect from the Vastaamo psychotherapy clinic.
The suspect involved in the Odido telecom attack was arrested by the Dutch police.
8. Exploitation drivers
The majority of the activity this month was due to three vulnerabilities.
The Adobe ColdFusion CVE-2026-48279 issue, which is of maximum severity, was confirmed to have been exploited on 6 July and was included in CISA’s KEV catalog on 8 July, with a federal patching deadline set for that same week. This came after urgent patches were issued on 2 July to address seven maximum-severity vulnerabilities in ColdFusion and Campaign Classic.
The Langflow CVE-2026-0770 was the subject of an urgent federal patching order by CISA on 22 July after it was observed that attackers were compromising AI workflow servers. Furthermore, on 8 July CVE-2025-3248, another Langflow authentication bypass, was included in the KEV. AI orchestration tools are now a target that is actively being exploited, and not merely a potential risk.
Microsoft SharePoint CVE-2025-53770 is still currently being exploited, and CISA is once again reminding people of the need to apply patches.
Also worth fixing if you haven’t already: the Progress ShareFile CVE-2025-5777 (a zero-day vulnerability that comes after the StorageZone shutdown), 7-Zip CVE-2025-55188, the WordPress Core “WP2Shell” CVE-2025-6463/6464 with publicly available exploit code, Zimbra CVE-2025-53901, and the zero-day vulnerabilities affecting SonicWall SMA1000 and Check Point SmartConsole.
Credential attacks are still a major problem. Researchers observed more than 81 million login attempts directed at Microsoft 365 accounts as part of a password-spraying campaign, and Microsoft also issued a warning regarding an increase in ACR Stealer activity. Chick-fil-A said that a breach had affected over 13,000 customers because of credential stuffing, since the stolen credentials had been posted on Telegram channels.