
July 2026 was the worst month for ransomware activity so far this year: 811 tracked victims across 66 active groups, edging past March's 808 after a noticeably quieter second quarter. TheGentlemen and Qilin tied for the highest volume at 119 victims each.
The number is worth pausing on, but the composition of the month tells a more useful story than the total. Three incidents in particular describe how the threat has changed.
The Quarter Two Lull Was Not a Retreat
The drop in activity through the spring was read in some quarters as evidence that pressure on ransomware operations — law enforcement disruption, infrastructure takedowns, payment interdiction — was working.
July argues otherwise. Sixty-six distinct groups posting victims in a single month indicates fragmentation rather than suppression. Disruption operations break up large, recognisable brands; they do not remove the operators, the affiliates, or the tooling. What follows is a larger number of smaller groups, which is a harder problem for defenders in several concrete ways.
Attribution becomes unreliable, and with it the threat intelligence that incident response depends on. Negotiation behaviour becomes unpredictable, because norms that established groups maintained to protect their reputation — honouring decryption, not re-extorting, avoiding certain sectors — do not hold across dozens of new entrants. And sanctions screening before any payment becomes considerably harder when the group is three weeks old and has no established profile.
From Encryption to Destruction
On July 14, an attacker deleted Romania's entire land registry database, including the backups, after an extortion attempt failed. The National Agency for Cadastre and Land Registration confirmed that a ransomware attack had encrypted and deleted part of its virtualisation infrastructure. Property transactions across the country stopped. Notaries could not authenticate sales, register transactions, or record mortgages.
This is the case study that belongs in front of every board this quarter, because the attacker's first target was the backups and the outcome was not recoverable through payment.
Encryption-based ransomware, whatever its cost, preserves the possibility of restoration. Destruction removes it. An organisation whose recovery plan assumes that data exists somewhere — in a backup, on the attacker's infrastructure, behind a decryption key — has no plan for the scenario Romania experienced. Immutable, segmented, and independently verified backups are the difference, and verification is the step most often skipped.
Third-Party Portals and Operational Disruption
The month's largest data exposure came through a customer-facing portal. Aflac Life Insurance Japan disclosed that attackers compromised its customer portal and other systems, exposing personal information of approximately 4.38 million policyholders — names, addresses, phone numbers — with premium payment account details compromised for roughly 230,000 of them.
Elsewhere the disruption was operational rather than informational, including production impacts at food and beverage manufacturers and facility-level disruption at healthcare providers. The pattern across the month is consistent: attackers are targeting the systems whose unavailability stops the business, not simply the databases whose contents can be sold.
Five Questions for the Next Tabletop Exercise
- Can we operate if the data is gone rather than encrypted? Run the Romania scenario explicitly, including deleted backups, and measure how long essential functions survive.
- Have we verified backup immutability and tested a full restore recently? An untested backup is a hypothesis.
- Who screens a ransom payment for sanctions exposure, and how fast can they do it? With 66 active groups and rapid rebranding, this determination now takes longer than the negotiation window allows unless it is pre-planned.
- What third-party and customer-facing portals sit outside our core security perimeter? The Aflac Japan exposure came through the portal, not the core systems.
- What are our regulatory notification clocks, in every jurisdiction we operate in, and who starts them? These run concurrently with technical response and are routinely missed in the first forty-eight hours.
The Bigger Picture
The operating assumptions many organisations formed during 2024 and 2025 — that a manageable number of identifiable groups behave in broadly predictable ways, that paying restores data, that backups constitute recovery — were reasonable at the time and are no longer safe.
A fragmented ecosystem of 66 active groups, some willing to destroy rather than encrypt, targeting operational availability and third-party portals as readily as data stores, is a different problem. It is worth reviewing whether the incident response plan on file was written for the threat that existed when it was drafted.


