Ransomware activity kept climbing through August 2026, and the numbers point to a shift in who gets hit hardest. NCC Group’s latest cyber threat intelligence report counted 1,073 ransomware attacks worldwide last month, up 12% from 960 in July. Industrial organizations took the brunt of it: 329 attacks, or roughly one in three incidents NCC Group tracked. Layer in a set of Microsoft threat intelligence reports published in late September, and a clearer picture emerges of how ransomware affiliates are standardizing their tradecraft across brands while pushing deeper into cloud identity systems.

None of this reads like a single breach story. It is a trend line, and trend lines matter more than isolated incidents because they tell security teams where to spend their next budget cycle. This piece breaks down the August data, the specific tactics researchers documented, what it means for industrial and cloud-reliant companies, and where the numbers are likely headed next.

NCC Group’s August Numbers: 1,073 Attacks, a 12% Jump

NCC Group tracks publicly disclosed ransomware activity through its monthly Cyber Threat Intelligence reports, drawing from leak-site postings, victim notifications, and incident response engagements. The August 2026 edition recorded 1,073 attacks globally, up from 960 in July, a 12% month-over-month increase. That is not a one-off spike. NCC Group has flagged ransomware activity as range-bound but elevated for most of 2026, and August marks one of the higher monthly totals the firm has logged this year.

It is worth being precise about what this figure represents. NCC Group’s count reflects publicly tracked incidents, meaning leak-site claims and confirmed disclosures the firm can verify, not every ransomware event that occurred. Plenty of attacks go unreported or get resolved quietly without a leak-site posting. So 1,073 is a floor, not a ceiling, on actual ransomware volume for the month.

Still, the month-over-month comparison is useful because it uses the same methodology both times. A 12% jump measured consistently tells you more than a single absolute number ever could.

Industrial Organizations Bear the Brunt: 329 Attacks, Nearly a Third of All Incidents

The sector breakdown is where August’s report gets interesting. Industrial organizations accounted for 329 of the 1,073 tracked attacks, about 31% of the total. That means roughly one out of every three ransomware incidents NCC Group recorded last month hit a manufacturer, utility, logistics operator, or other industrial target.

Industrial targeting has been a recurring theme in ransomware reporting for several years, but a 31% share in a single month is a concentrated number. It suggests affiliates are not spreading attacks evenly across sectors; they are deliberately favoring targets where downtime is expensive and where operational technology networks often run older, harder-to-patch systems alongside modern IT infrastructure.

MetricJuly 2026August 2026Change
Total tracked ransomware attacks9601,073+12%
Attacks against industrial organizationsNot separately reported329–
Industrial share of total attacksNot separately reported~31%–
Non-industrial attacks (all other sectors combined)Not separately reported~744–

NCC Group’s report did not break out a July industrial figure for direct comparison, so the month-over-month industrial trend itself is not yet established. What is established is that in August, industrial organizations were the single largest sector grouping in the data, ahead of any other named vertical.

Why Manufacturing and Industrial Targets Are So Attractive to Ransomware Gangs

The economics explain the targeting pattern. A hospital or a school district can sometimes operate in a degraded state for days. A factory running just-in-time production lines cannot. Every hour of downtime on a manufacturing floor translates directly into missed shipments, contractual penalties, and in some cases line-wide safety shutdowns. That urgency is exactly what ransomware affiliates are betting on when they set a ransom deadline.

Industrial environments also tend to run a mix of modern IT and decades-old operational technology (OT) that was never designed with network segmentation in mind. Patching an OT controller is not like patching a laptop; it can require scheduled downtime, vendor sign-off, and sometimes physical plant shutdowns. Attackers who get a foothold on the IT side often find an easier path to the OT network than security teams would like to admit.

This isn’t a new observation, but the August numbers put a sharper point on it. Readers interested in how a single industrial-adjacent ransomware case played out, including a lawsuit filed within days of the breach, can see the pattern up close in our earlier coverage of the Gold Star Mortgage BrainCipher incident.

Storm-2570: One Affiliate, Four Ransomware Brands

Separately from the NCC Group monthly numbers, Microsoft’s security research team published a report on September 24, 2026, tracking a ransomware affiliate it calls Storm-2570. According to Microsoft’s writeup, Storm-2570 has deployed ransomware under at least four different brand names: Qilin, DragonForce, Anubis, and BERT.

That detail matters for how defenders think about ransomware gangs. The brand on the ransom note is often a franchise label, not a fixed group of people. Ransomware-as-a-service operators lease their encryption tooling and leak-site infrastructure to affiliates, and a single affiliate can rotate between brands depending on which service offers the best split, the most reliable infrastructure, or simply isn’t under law enforcement pressure that week. Microsoft’s researchers said Storm-2570 used consistent post-compromise methods regardless of which ransomware brand it deployed, which is how they were able to link the activity across four seemingly unrelated groups.

The Common Playbook Behind the Brand Names

Microsoft’s report described a repeatable sequence across Storm-2570’s deployments: remote-access tooling for persistence, credential theft to move beyond the initial foothold, lateral movement across the network, tampering with security tools to blind defenders, and cloud-based data exfiltration before the ransomware payload ever detonates. That order is deliberate. Exfiltrating data first means the affiliate still has leverage, the threat of a public leak, even if a victim restores from backup and refuses to pay for a decryption key.

This double-extortion model is not new, but the consistency Microsoft documented across four ransomware brands suggests affiliates have settled on a playbook that works well enough that they see no reason to vary it by franchise.

The INC Ransomware Intrusion: 175 Endpoints and a 17-Day Gap

The same research window documented a separate INC ransomware intrusion that affected at least 175 endpoints. Two details stand out. First, the intrusion relied on a technique known as BYOVD, or bring-your-own-vulnerable-driver, to disable security tooling on infected machines. Second, researchers identified a 17-day gap in the intrusion timeline between initial access and ransomware deployment, which they said could indicate that a separate access broker sold entry to a distinct ransomware operator rather than one group handling the entire attack chain.

That gap is a meaningful operational detail. It points to the continued role of initial access brokers, criminals who specialize in breaching a network and then selling that access on underground forums rather than deploying ransomware themselves. A 17-day window between breach and encryption gives defenders a real, if narrow, opportunity to catch an intrusion before it turns into a full-blown ransomware event, provided they are watching for the right signals during that gap.

AnyDesk and Scheduled Tasks: Living Off Legitimate Tools

The INC intrusion also used AnyDesk, a legitimate remote-desktop application, alongside Windows scheduled tasks to support lateral movement across the network. Both are standard IT administration tools, which is precisely why attackers favor them. Security products are far more likely to flag an unfamiliar executable than a remote-access tool that IT help desks use every day. This living-off-the-land approach, pairing legitimate software with a BYOVD technique to kill endpoint protection, has become close to a baseline expectation in modern ransomware intrusions rather than an advanced outlier tactic.

BYOVD Explained: How Attackers Disable Security Tools With Legitimate Drivers

BYOVD attacks exploit a structural weakness in how operating systems trust signed kernel drivers. Windows requires kernel-level drivers to be digitally signed, which is meant to stop malicious code from running with the highest level of system privilege. Attackers get around this not by forging a signature, but by bringing along an older, legitimately signed driver that has a known vulnerability, installing it on the target machine, and then exploiting that vulnerability to execute code in kernel mode. Because the driver itself is signed by a trusted vendor, it often passes right through allow-list checks that would block an unsigned or unknown binary.

Once an attacker has kernel-level access, disabling antivirus or EDR agents is straightforward; kernel code can terminate, blind, or tamper with security processes that normally run with elevated protection. MITRE’s ATT&CK framework catalogs this family of techniques under Impair Defenses (T1562), and BYOVD specifically has shown up in intrusions tied to multiple ransomware families over the past two years, not just INC.

The defensive challenge is that blocking every vulnerable signed driver requires maintaining an extensive, constantly updated blocklist, something most organizations do not do well without dedicated tooling such as Microsoft’s vulnerable driver blocklist feature in Windows.

Storm-3168 and JADEPUFFER: Ransomware Tactics Move Into Azure Cloud Identities

A second Microsoft report, published September 25, 2026, documented a cluster it tracks as Storm-3168, associated with activity Microsoft calls JADEPUFFER. According to Microsoft’s analysis, this cluster used compromised service principals, the credentials applications use to authenticate to Azure, to conduct destructive operations directly inside cloud environments rather than targeting on-premises servers first.

That shift matters because it skips a step attackers traditionally needed: breaching an endpoint, moving laterally, and eventually reaching a server worth encrypting. A compromised service principal with excessive permissions can let an attacker reach deep into a tenant’s cloud resources without ever touching a traditional endpoint. For companies that have spent the last several years hardening endpoint detection while treating cloud identity governance as a lower priority, Storm-3168’s approach is a direct test of that imbalance.

The Cloud Identity Blind Spot

Service principals are often over-provisioned because it is easier to grant broad permissions once than to scope access narrowly for every integration an organization builds. That convenience is exactly what Storm-3168 is reported to have exploited. Security teams that audit human user permissions rigorously but rarely review what a service principal or managed identity can actually touch are left with a governance gap that traditional endpoint-focused ransomware defenses were never built to close.

Historical Context: How 2026’s Ransomware Volume Compares

August’s 1,073 attacks did not happen in a vacuum. Ransomware activity has been on a multi-year upward trend despite periodic law enforcement wins against individual groups. Our earlier coverage found that ransomware groups overall grew 49% during 2025, with 8,159 total victims recorded across the year, according to the analysis in Ransomware Groups Up 49%: 8,159 Victims Hit in 2025. At the same time, the share of victims actually paying a ransom has been falling. A separate analysis on this site found ransomware payment rates sinking to a 23% low even as attack volume climbed, detailed in Ransomware Payments Sink to 23% Low as Attacks Climb.

Put together, the picture is a volume-over-conversion strategy: affiliates are launching more attacks even as fewer victims pay, which likely explains why the operational tradecraft documented in Storm-2570 and the INC intrusion leans so heavily on double extortion. If fewer victims will pay just for a decryption key, the threat of a public data leak becomes the more reliable lever.

Regional data tells a similar story. Japan recorded a record 123 ransomware cases in the first half of 2026 alone, as covered in our report on Japan’s record ransomware case count, underscoring that the August spike NCC Group recorded is part of a broader, sustained global pattern rather than an isolated monthly blip.

Comparing the Tactics: Storm-2570, the INC Intrusion, and Storm-3168

Each of the three threat clusters documented in late September approaches the same goal, getting paid or extracting leverage, through a different technical path. Laid side by side, the differences show how fragmented and specialized the ransomware ecosystem has become even as its overall output grows.

Threat clusterRansomware brands/associationPrimary techniqueNotable detail
Storm-2570Qilin, DragonForce, Anubis, BERTRemote access tooling, credential theft, cloud exfiltration before encryptionSame tradecraft reused across four separate ransomware brands
INC ransomware intrusionINCBYOVD to disable security tools, AnyDesk and scheduled tasks for lateral movement175 endpoints affected; 17-day gap suggests separate access broker
Storm-3168 / JADEPUFFERNot tied to a single named ransomware brandCompromised Azure service principals for destructive cloud operationsSkips endpoint compromise, attacks cloud identity directly

The common thread across all three is a preference for tools and credentials the target organization already trusts, whether that is a signed driver, a help-desk remote-access app, or a cloud service principal. None of the three relies primarily on a novel piece of custom malware. That is arguably the most important finding for defenders: the tools are not exotic, which means detection has to focus on behavior and permission scope rather than signature matching alone.

Market Impact: Insurance, Downtime Costs, and Vendor Response

A 31% industrial share of ransomware attacks has direct implications for cyber insurance underwriting. Insurers price industrial and manufacturing policies partly on business interruption risk, and a sustained pattern of industrial targeting tends to push premiums higher or narrow the coverage terms insurers are willing to offer for OT-adjacent claims. Companies that have not segmented IT and OT networks are likely to see underwriters ask harder questions at renewal time.

For cloud providers, Storm-3168’s targeting of Azure service principals adds pressure on Microsoft and its enterprise customers alike to tighten default permission scopes for app registrations and managed identities. Expect identity governance vendors and cloud security posture management tools to lean harder into service-principal auditing as a selling point over the next few quarters, since this is now a documented attack path rather than a theoretical one.

Security vendors that sell endpoint detection and response products also have a messaging problem to solve. If BYOVD techniques can blind an EDR agent at the kernel level, customers are going to ask what additional layer catches that failure mode. Expect more vendors to highlight kernel-level driver blocklisting and tamper-protection features in product marketing through the rest of 2026.

What Security Teams Should Watch For

Several concrete defensive steps fall directly out of the tactics documented this month. Industrial organizations should prioritize network segmentation between IT and OT environments, since that boundary is where Storm-2570-style lateral movement either stalls or succeeds. Security teams should also audit remote-access tool usage; if AnyDesk, TeamViewer, or similar software is not part of an approved IT workflow, its presence on a machine deserves immediate investigation, not a routine ticket.

On the cloud side, reviewing service principal and managed identity permissions against the principle of least privilege is no longer optional hygiene; it is now a documented attack surface. Teams should also enable and keep current Microsoft’s vulnerable driver blocklist, since BYOVD depends entirely on an outdated or unpatched signed driver being present on the system.

Finally, the 17-day gap in the INC intrusion is a reminder that detecting an initial-access broker’s footprint, unusual authentication patterns, unfamiliar remote tools, new scheduled tasks, before ransomware deploys is the highest-leverage window defenders get. The FBI’s Internet Crime Complaint Center, reachable at ic3.gov, remains the primary channel for reporting ransomware incidents in the United States, and early reporting can help responders and researchers track these campaigns before they widen.

  • Industrial and manufacturing targeting will stay elevated through the rest of 2026, since affiliates have little incentive to abandon a sector that keeps producing fast payouts under deadline pressure.
  • More ransomware-as-a-service affiliates will be documented operating across multiple brands, following the pattern Microsoft identified with Storm-2570, as franchise operators compete for the same pool of skilled affiliates.
  • Cloud identity attacks resembling Storm-3168’s service-principal abuse will become a standard line item in ransomware threat reports by early 2027, not a novelty.
  • Ransom payment rates will likely keep drifting down from the 23% low already recorded this year, pushing more affiliates toward pure data-leak extortion that does not depend on a working decryptor at all.
  • Expect at least one more major BYOVD-driven intrusion disclosure before the end of 2026, given how effective the technique has proven at neutralizing endpoint defenses cheaply.

How This Wave Differs From Earlier 2026 Ransomware Coverage

It is worth distinguishing this trend story from the single-victim ransomware incidents that have dominated headlines this year. Cases like the law enforcement action against KillSec, detailed in our report on the KillSec takedown, show what happens after a specific group gets disrupted. The NCC Group and Microsoft data released this month describes the opposite side of the cycle: even as individual groups get arrested, sued, or shut down, the overall ecosystem of affiliates, tooling, and targeting strategy keeps adapting and, by the August numbers, keeps growing.

That is consistent with how researchers have described ransomware’s evolution for the past two years: takedowns remove specific brands or operators, but the underlying affiliate labor pool, malware-as-a-service infrastructure, and extortion playbook persist and simply regroup under new names. Our earlier look at how ransomware groups are adapting their exfiltration methods covers that resilience pattern in more depth.

The Bigger Picture for Enterprise Security Budgets

Security budgets for 2027 planning cycles are being set right now at most large enterprises, and August’s data gives CISOs concrete ammunition for two specific asks: OT network segmentation funding and cloud identity governance tooling. Both have historically lost budget battles to more visible priorities like endpoint detection and email security, partly because the attack paths through OT networks and service principals were less documented than phishing or malware delivery.

That documentation gap is closing fast. With NCC Group quantifying industrial exposure at nearly a third of all ransomware activity and Microsoft publishing a named cloud-identity attack cluster, security leaders now have vendor-backed, dated evidence to cite in budget conversations rather than general warnings about theoretical risk. The takeaway for 2026 and into 2027: the two areas ransomware operators are actively exploiting right now, industrial OT boundaries and cloud identity permissions, are also the two areas most enterprise security programs have historically under-invested in.

Frequently Asked Questions

How many ransomware attacks happened in August 2026?

NCC Group’s cyber threat intelligence report recorded 1,073 ransomware attacks worldwide in August 2026, up 12% from 960 in July 2026.

Which sector was targeted most by ransomware in August 2026?

Industrial organizations were the most targeted sector, accounting for 329 of the 1,073 tracked attacks, roughly 31% of the total, according to NCC Group’s data.

What is Storm-2570?

Storm-2570 is the name Microsoft’s security research team uses for a ransomware affiliate it documented deploying ransomware under at least four different brand names: Qilin, DragonForce, Anubis, and BERT, using consistent post-compromise tactics across all four.

What does BYOVD mean in a ransomware attack?

BYOVD stands for bring-your-own-vulnerable-driver. Attackers install an older, legitimately signed kernel driver that has a known vulnerability, then exploit it to run code with kernel-level privileges, which lets them disable antivirus and endpoint detection tools that would otherwise block the ransomware payload.

What is Storm-3168 and JADEPUFFER?

Storm-3168 is a threat cluster Microsoft documented using compromised Azure service principals, the credentials applications use to authenticate to cloud resources, to conduct destructive operations directly inside cloud environments. Microsoft associates this activity with what it calls JADEPUFFER.

Is ransomware getting worse in 2026?

By attack volume, yes. NCC Group’s monthly tracking shows attacks climbing from 960 in July to 1,073 in August 2026, continuing a broader multi-year upward trend in total ransomware incidents, even as the share of victims who actually pay a ransom has fallen.

Why are ransomware groups using double extortion instead of just encryption?

Because fewer victims are paying for decryption keys alone, affiliates exfiltrate data before deploying ransomware so they retain leverage, the threat of a public data leak, even if a victim restores from backup and refuses to pay.

Where can organizations report a ransomware attack in the US?

The FBI’s Internet Crime Complaint Center, at ic3.gov, is the primary US reporting channel for ransomware and other cybercrime incidents.