Skip to content

Image: assets.infosecurity-magazine.com · rights & removal

Executive Summary

Ransomware activity reached a record quarterly peak in the third quarter of 2026, characterized by significant volume increases across all critical sectors. While the finance and technology industries saw the sharpest growth, the surge extended to government, healthcare, and utilities. This spike is potentially linked to advancements in AI, exemplified by the JadePuffer campaign, which may allow attackers to scale and accelerate their operations.
A shift toward "triple extortion" is evident, where threat actors target not only the primary organization but also its clients and employees to increase pressure. Recent cases involving MIP Holdings, Stadler Rail, and the State of Berlin illustrate that paying ransoms does not guarantee data deletion and that refusal often leads to massive data leaks. The United States remains the primary target geographically, though emerging markets like Argentina and India are experiencing rapid growth in incident rates. There remains a notable gap between the number of attacks claimed by ransomware groups and those officially confirmed by the victims.

Facts Only

* 2,627 claimed ransomware attacks occurred between July and September 2026.
* This figure represents a 27% increase over Q2 2026 and a 61% increase over Q3 2025.
* 247 of the 2,627 claimed attacks were confirmed by the involved entities.
* Finance and technology sectors saw increases of 72% and 70% respectively from Q2 2026.
* Education, healthcare, government, and utilities saw increases of 50%, 39%, 36%, and 32% respectively.
* The JadePuffer campaign was identified in July 2026 as an AI-driven ransomware attack.
* The average ransomware demand in Q3 2026 was $602,400.
* Everest demanded $12.3m from Stadler Rail in July 2026; 201 GB of data was leaked.
* Rhysida demanded $2.3m from the State of Berlin; 5.7 TB of data was leaked.
* Qilin (357 attacks) and The Gentlemen (342 attacks) were the most prolific groups.
* Clop attacks increased from one in Q2 to 48 in Q3.
* The US had the highest volume of attacks (1,066), followed by Germany (121).
* Argentina and India saw increases of 150% and 116% respectively compared to Q2.

Full Take

The strongest version of this narrative is that we have entered a new era of automated cyberwarfare where AI eliminates the traditional bottlenecks of human-led campaigns, leading to an exponential rise in successful breaches and more aggressive extortion models.
The narrative relies heavily on a specific data gap: the discrepancy between "claimed" attacks (2,627) and "confirmed" attacks (247). By centering the urgency on the claimed figures while acknowledging the low confirmation rate, the narrative maintains a high-alarm state without requiring a proportional amount of verifiable evidence. This creates a tension where the threat is presented as systemic and overwhelming, yet the evidence is primarily based on the self-reporting of the attackers themselves.
Patterns detected: ARC-0024 Ambiguity
This situation echoes the historical pattern of "threat inflation" often seen during technological transitions. The unstated assumption is that AI is the primary driver of this surge, though other factors—such as geopolitical instability or systemic infrastructure decay—remain unexamined. This shifts the focus toward a technological "boogeyman," potentially steering organizations toward AI-based security solutions rather than fundamental hygiene.
The implication is a steady erosion of digital agency. As "triple extortion" becomes standard, the cost of a breach is shifted from the negligent corporation to the innocent client or citizen, effectively socializing the risk of corporate insecurity.
How does the reliability of "claimed" attacks compare to "confirmed" attacks when assessing actual risk? If attackers are incentivized to inflate their success rates to attract recruits or intimidate victims, how does that change the interpretation of these percentages?
A coordinated influence campaign would use record-breaking statistics and the fear of "AI-driven" attacks to create a sense of inevitability, pushing targets toward a specific vendor's "AI-defense" suite. The content here matches the statistical profile of such a campaign but lacks a direct commercial call-to-action, remaining within the realm of intelligence reporting.

From the original · InfoSecurity Magazine

Ransomware attacks reached their highest ever quarterly volume in the third quarter of 2026, according to an analysis by Comparitech. The firm identified a total of 2627 claimed attacks during the three-month period from July to September 2026.
Read the full story at infosecurity-magazine.com
Q3 2026 Sets New Record for Ransomware Attacks | Huntaegis