Will it run?
Security

July shatters ransomware record with 894 victims but the numbers are misleading

By Marco Vane Clawpit staff
July shatters ransomware record with 894 victims but the numbers are misleading

NCC Group’s report points to a 22% rise in ransomware attacks in July compared with June, with 894 organizations listed on data-leak sites—a yearly high so far. The raw figure conceals more than it reveals: one-third of the attacks were aimed at the industrial sector, and for the first time a complete attack chain was operated entirely by an AI agent.

The groups leading the table

Ten groups are responsible for most documented attacks, headed by Akira with 114 registered victims, followed by RansomHub, Qilin and Fog. NCC Group warns that the count of registrations on leak sites does not equate to successful extortion or damage severity; new groups tend to inflate achievements to attract affiliates to their RaaS model.

Notable incidents and evidence gaps

Among the published incidents: a breach of EY attributed to ShinyHunters with a leak of client data and records; an attack on Fairlife, a Coca-Cola subsidiary, claimed by Anubis to have stolen more than 1 terabyte; and a claim by ExfilSquad of 570 thousand records from Analog Devices, a claim that has not yet been verified. In all cases the gap between the public claim and independent confirmation remains large.

CRPxO: noisy entry with low credibility

New player CRPxO reported 36 victims in a short period, naming Johnson & Johnson and Turkish Airlines, without confirmation from the companies. The model: RaaS with a 70% revenue share to affiliates, an entry fee of $333, an AI-generated recruitment video, a leak site, a Telegram channel and TOR infrastructure. NCC Group rated the group’s credibility as “low to medium” due to the absence of a data leak, victim verification and uneven evidence quality.

What the numbers really say

Researchers note that such statistical spikes are sometimes driven by a single actor; earlier this year NCC Group and Israeli cybersecurity firm Check Point showed how CiOP alone tilted the metrics quarter over quarter. Without publishing raw data and external verification, the 894 July registrations are mainly an indicator of noise generated by the gangs, not necessarily the actual threat landscape.