Ransomware volumes in July 2026 reached their highest point of the year so far. Cyber security firm NCC Group, which tracks publicly claimed ransomware incidents month by month, recorded almost 900 attacks over the course of July — more than any other month in 2026, and enough to put the year back on the trajectory that the industry had cautiously hoped was flattening out. The figure still sits below the all-time monthly record of 1,099 attacks set in February 2025, but the direction of travel matters more than the gap. Twenty-nine per cent of those July victims were organisations in Europe.
The number that should hold a British business owner’s attention, though, is not 900. It is one. In the same month, NCC recorded the emergence of a threat actor it calls Jadepuffer, which it describes as an agentic actor capable of executing a successful, end-to-end ransomware intrusion entirely autonomously — reconnaissance through to encryption, without a human operator steering it. To date it appears to have been used as a proof of concept rather than for financial gain. That distinction is real, and it is also temporary. Today, 27 August 2026, the practical question for a UK small or medium-sized business is no longer whether attackers have access to automation that compresses an intrusion from weeks into hours. It is whether the controls in your own environment were designed for an attacker moving at human speed, and what happens to them when that assumption stops holding.
What NCC Group actually reported
NCC Group’s monthly threat intelligence reporting counts ransomware attacks that have been publicly claimed — typically posted to a leak site by the group responsible, or otherwise disclosed. July 2026’s tally of almost 900 makes it the busiest month of the year to date. That is a meaningful high-water mark for 2026, and it arrives after a period in which several months had suggested the ecosystem might be consolidating rather than expanding. It has not consolidated. It has redistributed.
The regional split is the first thing worth reading properly. Forty-one per cent of July’s victims were in North America and 29% were in Europe. For a UK business, the European figure is the one that lands closest to home: close to three in ten publicly claimed ransomware victims last month were operating under broadly similar regulatory obligations, insurance markets and supply-chain structures to your own. This is not a distant American phenomenon reported at one remove. The gap between the North American and European shares has narrowed considerably from where it sat a few years ago, and the practical reading is that European organisations — including mid-market and smaller UK firms that would not describe themselves as obvious targets — are now a routine part of the target set rather than an occasional one.
The second finding concerns who is doing the attacking. The single largest contributor to July’s volume was a group calling itself The Gentlemen, which accounted for 15% of all attacks recorded in the month. The Gentlemen is a splinter from Qilin, one of the more established ransomware-as-a-service operations, and it reportedly formed after a dispute over a ransom payment. Since then it has scaled faster than any other group NCC tracks, claiming more than 300 victims in a year. That growth curve is the story in miniature: a group that did not meaningfully exist eighteen months ago is now responsible for roughly one in seven publicly claimed ransomware incidents worldwide. The barrier to standing up a competent, high-volume ransomware operation is not a technical one. It is organisational, and the ecosystem has become very good at solving organisational problems quickly.
The third finding is a caution against reading claim counts too literally. A newer group, CRPxO, claimed 36 attacks in July, but NCC assessed the group as only “partially verified” — meaning some of those victim claims could not be substantiated. NCC’s reading is that a proportion may have been exaggerated to make the group appear more threatening than its actual capability warrants. This is a familiar pattern. Leak-site posts are marketing as much as they are disclosure, and a new entrant with an inflated victim list is trying to recruit affiliates, not just extort victims. For defenders, the lesson is that headline group rankings should be treated as a directional signal about where the ecosystem’s energy is going, not as an audited ledger.
And then there is Jadepuffer. NCC describes it as an agentic threat actor: not a tool that assists a human operator, but a system capable of executing a successful ransomware intrusion end to end, autonomously, without human oversight at each step. NCC’s assessment is that it has so far been used as a proof of concept rather than for financial gain — a demonstration, in other words, that the thing works. Matt Hull, NCC Group’s vice president of cyber intelligence and response, framed the broader trend plainly: AI is “changing the speed and scale of cyber attacks”, letting attackers automate more of their operations and generate far more convincing phishing and social engineering content than they could before.
Most SME security postures rely, whether or not anyone has said so out loud, on the attacker being slow. Someone reviews alerts in the morning. Patches get applied at the next maintenance window. The backup is checked when there is time. Those cadences work because a human-operated intrusion typically takes days or weeks between initial access and encryption, which leaves a window in which a slow defender can still win. An agentic actor collapses that window. Reconnaissance, credential harvesting, lateral movement and deployment can run continuously, without fatigue, at machine pace, across every exposed asset simultaneously. Jadepuffer is currently a proof of concept. The controls that would have stopped it — enforced multi-factor authentication, least-privilege access, prompt patching of internet-facing systems, and immutable offline backups — take months to put in place properly. Those months need to start before the proof of concept becomes a product.
How July 2026 got here: a timeline
Ransomware volume does not spike randomly. July’s figure is the output of a set of structural shifts that have been accumulating for roughly eighteen months — the fragmentation of established ransomware brands into faster-moving splinters, the arrival of generative AI in the attacker’s toolkit, and a UK policy environment that has been in flux. The chronology below sets out the reference points that matter for reading the July number in context.
Reading the 900: region, group and the limits of the data
A single monthly total is a blunt instrument. What makes July’s figure useful is that it can be cut two ways from the same reporting: by where the victims were, and by who claimed them. The chart below does both against the same base of roughly 900 attacks. The first three bars split the month by victim region. The remaining four split the same month by the group doing the claiming. They are two views of one dataset, not a single ranking, and they are read separately.
The two residual bars — “rest of world” at 30% and “all other tracked groups” at 81% — are arithmetic rather than reported figures, derived from the published shares. They are included because they carry the more important message in each view. In the regional cut, the residual tells you that ransomware is not concentrated in two continents; roughly three in ten victims sat outside both North America and Europe. In the group cut, the residual tells you that even the fastest-growing operation in the ecosystem accounts for only about one in seven incidents. There is no single group to defend against. Removing The Gentlemen from the picture entirely would still leave more than 750 attacks in July.
That is the strategic point that gets lost when reporting focuses on named groups. Law-enforcement takedowns and brand disruptions are worth doing, and they have had real effect, but the ecosystem’s response has consistently been redistribution rather than reduction. Qilin fractured and produced The Gentlemen, which now claims a larger share of monthly volume than most of the brands that preceded it. The defensive implication is that your control set should be indifferent to attribution. Enforced multi-factor authentication does not care which group is trying the credential. An immutable backup does not care whose encryptor ran. Attribution matters for insurers, regulators and law enforcement; it should not shape an SME’s roadmap.
Twenty-nine per cent: the number that makes this a UK story
Of every hundred publicly claimed ransomware victims in July 2026, twenty-nine were European. That is the figure a UK business should be planning against, because it is the one that reflects a target population operating under conditions much like your own: UK GDPR and the ICO’s 72-hour breach notification expectations, a hardening cyber insurance market that increasingly asks for evidence of controls rather than assertions, and supply chains dense with small suppliers who hold client data and system access disproportionate to their headcount.
There is a second reason the UK reading is sharper than the raw European share suggests, and NCC flags it directly in the report: the country’s recent change of prime minister creates a period of policy transition, and policy transitions extend opportunities for threat actors. That is not a comment about any government’s security competence. It is a structural observation about what happens when personnel and processes change. New ministers bring new special advisers and new private offices. Departments reorganise. Suppliers get new points of contact. Approval chains are rewritten, and for a period nobody in the organisation has a reliable instinct for what a normal instruction from a new name looks like.
For attackers, that period is reconnaissance gold. Social engineering works by exploiting the gap between what an organisation formally requires and what its people actually recognise as routine. When the roster changes, that gap widens for everyone in the chain — not just central government, but every supplier, contractor and professional-services firm that touches it. A UK accountancy practice, IT reseller or facilities contractor sitting three tiers down a public-sector supply chain will see the same effect: emails from unfamiliar names, referencing genuine reorganisations, arriving at plausible moments. Combine that with Hull’s point about AI producing more convincing phishing content and the traditional detection heuristics — odd phrasing, poor grammar, wrong register — stop earning their keep.
Where UK SMEs are actually exposed
Volume figures describe the weather. The table below describes the building. These are the control gaps we see most often when assessing UK small and medium-sized businesses, rated by how frequently they turn out to be the weak point that matters in a ransomware scenario. The ratings are Cloudswitched’s assessment based on assessment and remediation work with UK SMEs, not NCC Group data — but each maps directly to one of the fundamentals Hull identified as still mattering most.
The pattern in that list is worth naming. Almost none of these are exotic. There is no zero-day on it, no nation-state capability, nothing that requires a large budget to address. They are the fundamentals, and they are exactly the fundamentals Hull pointed to: strong identity and access controls, good vulnerability management, visibility across the IT environment, and the ability to detect and respond quickly when something goes wrong — alongside staff training that has actually been updated for the era of AI-generated social engineering.
The reason they persist is not ignorance. It is that each one is individually easy to defer. Enforcing MFA on the last eleven accounts means dealing with the four people who will complain. Testing the restore means booking a day nobody has. Decommissioning the dormant service account means finding out what it does first, and the person who set it up left in 2023. Every one of these is a small piece of organisational friction, and ransomware readiness is mostly the discipline of clearing small friction before it compounds. An agentic attacker does not need a sophisticated exploit if a valid credential without MFA is available.
What ransomware readiness costs a UK business
The most common objection to any of this is budget, so it is worth being concrete about the order of magnitude. The bands below are indicative annual figures for UK SMEs, covering managed security fundamentals rather than a full enterprise programme — identity hardening and MFA enforcement, patch and vulnerability management for endpoints and internet-facing systems, immutable backup with tested restores, centralised logging with monitoring, and Cyber Essentials certification. They are planning ranges, not quotations; the actual figure depends on estate complexity, compliance obligations and how much remediation is needed before a steady state is reached.
| Business size | Typical estate | Indicative annual spend | Realistic first-year focus |
|---|---|---|---|
| Micro (1–9 staff) | Microsoft 365, a handful of laptops, one cloud line-of-business app | £1,200 – £3,500 | MFA enforced on every account, managed endpoint protection, backup with a verified restore, Cyber Essentials self-assessment |
| Small (10–49 staff) | Mixed cloud and on-premises, a file server, VPN or remote access, one or two SaaS platforms | £4,000 – £12,000 | The above plus patch management for internet-facing systems, privileged access review, centralised logging, quarterly restore tests |
| Medium (50–149 staff) | Multiple sites or hybrid working, line-of-business servers, supplier integrations, some regulated data | £14,000 – £40,000 | The above plus monitored detection and response, immutable and offsite backup tiers, supplier access review, rehearsed incident response |
| Upper mid-market (150–250 staff) | Complex estate, compliance obligations, meaningful downstream supply chain | £45,000 – £110,000 | The above plus continuous vulnerability management, segmentation, Cyber Essentials Plus, tabletop exercises with named decision-makers |
Set those figures against the alternative. A ransomware incident at a small UK business rarely costs only the ransom, and in many cases the ransom is never paid. The cost is the downtime — days or weeks of no order processing, no invoicing, no client access — plus incident response fees, legal advice, ICO engagement if personal data was involved, notification, credit monitoring, insurance excess, premium increases at renewal, and the contract losses that follow when a client asks how it happened and does not like the answer. For most SMEs, a fortnight of operational paralysis costs multiples of a year’s security budget before a single specialist invoice arrives.
Reactive versus proactive: the same budget, spent at different times
The difference between businesses that survive a ransomware incident well and those that do not is rarely the size of the security budget. It is when the money was spent. The comparison below sets out the two postures as we encounter them.
Reactive posture
What a great many UK SMEs run today
- MFA is switched on in the tenant but exceptions were granted for convenience and never revisited
- Backups run nightly; nobody has attempted a full restore since the system was installed
- Firewall and VPN firmware is updated when something breaks or a vendor advisory makes the news
- Leavers are removed from payroll promptly and from the directory eventually
- Logs sit on individual devices and are overwritten within days, so an incident cannot be reconstructed
- Security awareness training is an annual video, unchanged since before AI-generated phishing was convincing
- The incident response plan is a document; nobody has read it aloud in a room with the people named in it
- Cyber insurance is held, and its control warranties have never been checked against reality
Proactive posture
Where Cloudswitched takes you
- MFA enforced by conditional access on every account with no standing exceptions, reviewed monthly
- Immutable backups with scheduled restore tests and a documented, timed recovery objective
- Internet-facing systems on a managed patch cycle with an emergency route for critical advisories
- Joiner, mover and leaver process tied to the directory, with dormant and service accounts reviewed quarterly
- Centralised log retention across identity, endpoint and network, so an intrusion leaves a readable trail
- Training refreshed against current lures, including AI-generated business email compromise and voice pretexting
- Incident response rehearsed with named decision-makers, out-of-band contacts and pre-agreed authority to act
- Cyber Essentials certification maintained, with evidence that satisfies insurers and procurement questionnaires
Neither column is a maturity fantasy. The right-hand column is achievable inside a year for most UK SMEs at the budgets in the table above. What separates the two is not spend but sequence: the proactive posture pays for controls before an incident, when the work can be scheduled, scoped and negotiated. The reactive posture pays for the same controls afterwards, at emergency rates, while the business is not trading, and with an insurer and possibly a regulator watching. The controls end up in place either way.
That score is our own editorial assessment rather than a figure from NCC’s report, and it is deliberately assembled from the four fundamentals Hull named — identity and access control, vulnerability management, environment visibility, and detection and response — plus the fifth he added, staff training refreshed for AI-generated social engineering. A typical UK SME scores reasonably on the first (MFA is usually deployed, if imperfectly enforced) and poorly on the third and fourth, because visibility and response capability are the two that cost real money and produce nothing visible until the day they are needed. Thirty-four out of a hundred is not a crisis. It is a normal starting position, and it is fixable in a planned sequence.
Test a restore. Not a file-level restore — a full recovery of one business-critical system to a point in time, performed by the person who would actually have to do it under pressure, timed from start to finish. It is the one exercise that validates several controls at once: that the backups are complete, that they are not reachable from a compromised domain account, that the restore media and credentials exist somewhere the ransomware cannot reach, and that the recovery time objective written in your continuity plan bears some relationship to reality. Businesses are routinely surprised by the result, and it is far better to be surprised on a Tuesday afternoon than at 3am with an encrypted estate and a countdown on a leak site.
At a glance: the July 2026 ransomware picture
| Item | Detail |
|---|---|
| Attacks recorded, July 2026 | Almost 900 publicly claimed ransomware attacks — the highest monthly total of 2026 so far |
| Standing monthly record | 1,099 attacks, set in February 2025; July 2026 approached but did not exceed it |
| Source of the data | NCC Group monthly threat intelligence reporting |
| Victims in North America | 41% of July’s total |
| Victims in Europe | 29% of July’s total — the figure most relevant to UK businesses |
| Largest single group | The Gentlemen, at 15% of all July attacks |
| The Gentlemen’s origin | A splinter from the Qilin operation, reportedly formed after a dispute over a ransom payment |
| The Gentlemen’s growth | More than 300 victims claimed in a year; scaled faster than any other group NCC tracks |
| CRPxO | 36 attacks claimed in July; assessed by NCC as only “partially verified”, with some claims possibly exaggerated |
| Jadepuffer | Agentic threat actor able to execute an end-to-end ransomware intrusion autonomously; apparently a proof of concept rather than financially motivated |
| NCC on AI | Matt Hull: AI is “changing the speed and scale of cyber attacks”, enabling automation and more convincing phishing and social engineering |
| NCC on defence | The fundamentals still matter most: identity and access controls, vulnerability management, environment visibility, fast detection and response, plus training for AI-generated social engineering |
| UK policy factor | The recent change of prime minister creates a transition period; personnel and process change generates new reconnaissance and social engineering targets |
| UK SME baseline control set | Cyber Essentials, covering firewalls, secure configuration, user access control, malware protection and patch management |
| Indicative annual security spend | From roughly £1,200 for a micro business to £110,000 at the top of the SME range |
Related coverage
This report sits alongside several threads we have followed over recent weeks. The autonomous-intrusion angle connects directly to our coverage of the Sleepwalker Windows backdoor, where persistence rather than encryption was the objective, and to the Microsoft Entra ID maximum-severity flaw, which showed how quickly an identity-layer weakness becomes an estate-wide one — precisely the failure mode an agentic attacker is built to exploit. On the infrastructure side, the PSTN switch-off deadline is forcing migrations that put alarms, payment terminals and emergency lines onto IP networks, expanding the attack surface many SMEs are now defending, while the Gamma Communications takeover reshapes the UK supplier landscape those migrations depend on. And for a view of how enforcement is changing the compliance calculus more broadly, our report on the HMRC crypto tax crackdown covers the same underlying shift: data-driven authorities, shorter grace periods, and less tolerance for organisations that cannot evidence what they did and when.
Get the fundamentals certified, not just intended
Cyber Essentials covers the five control areas that stop the overwhelming majority of ransomware intrusions before they start — and certification forces you to evidence them rather than assume them. Cloudswitched takes UK businesses through assessment, remediation and certification, then keeps the controls in place year-round.
Talk to us about Cyber Essentials CertificationFrequently asked questions
The window is the point
Almost 900 attacks in July, 29% of them in Europe, a year-old splinter group taking 15% of the total, and a first documented case of an autonomous agent running an intrusion from end to end. Read together, those figures describe an ecosystem that is getting faster, more distributed and less dependent on skilled human operators. None of them describe a new class of vulnerability. The way in is still an unpatched edge device, an unenforced authentication policy or a person persuaded to do something reasonable-sounding.
That is genuinely good news, because it means the defensive work is known, bounded and affordable. It is also the reason delay is expensive. The controls that stop an agentic intrusion are the same ones that stop a human one — they simply have to be in place beforehand, because there will be less time to improvise. Jadepuffer is a proof of concept today. The interval between proof of concept and commodity tooling in this ecosystem has historically been measured in months, and enforcing MFA properly, getting internet-facing systems onto a managed patch cycle and proving a restore works takes about the same amount of time. Starting now means those two clocks run in parallel rather than one behind the other.
Make July 2026 the month you stopped deferring the fundamentals
Cloudswitched works with UK businesses on exactly the controls NCC Group identifies as still mattering most — enforced identity and access management, managed vulnerability and patch cycles, visibility across the estate, and tested immutable backups — with Cyber Essentials certification as the evidenced baseline that satisfies clients, insurers and procurement.
Talk to us about Cyber Essentials Certification


