Key takeaways
- New NCC Group research says that July 2026 saw a spike in ransomware activity, with a year-to-date record of 894 victim listings recorded…
- This was also when the first incident of a fully agentic AI ransomware attack chain was also recorded.
- NCC Group data reveals that 10 cybercriminal groups were attributed to most of these ransomware attacks against businesses, ranked as…
What happened
New NCC Group research says that July 2026 saw a spike in ransomware activity, with a year-to-date record of 894 victim listings recorded in the month alone. But what's actually behind it? According to NCC Group's July threat advisory report, published on Wednesday, global ransomware attacks increased by 22% in July 2026, compared to June 2026.
CRPxO operates a RaaS model and offers criminal affiliates a 70% share of ransomware payments, with a low $333 cost of entry, according to an AI-generated recruitment video. There's evidence of a leak site -- used to publicly pressure victims to pay up under the threat of having their information leaked online -- a Telegram channel, and Tor-hosted infrastructure.
However, 36 successful attacks, with alleged high-value victims including Johnson & Johnson and Turkish Airlines (there has been no confirmation of this), seem like a lot for a new entry. " "Looking ahead, the group's low barrier to entry and relatively generous affiliate revenue share may allow it to attract more affiliates and increase the number of claimed attacks in the near term," NCC Group said in the report.
" CRPxO's case is important because it reflects what we've previously found in ransomware rates and spikes: the numbers can't always accurately reflect what is really going on. Data from earlier this year, released by NCC Group and Check Point, revealed that, quarter after quarter, a single threat actor, CiOP, was impacting ransomware rates.
A successful attack can lead to data theft and exposure, destruction, reputational harm, and a serious blow to bank balances -- and while they remain profitable, we should expect new ransomware groups to appear and for this illicit industry to continue. We also have to keep a close eye on how AI-powered ransomware attacks continue to evolve.
Why it matters
This was also when the first incident of a fully agentic AI ransomware attack chain was also recorded. Almost a third of attacks were launched against the industrial sector. Other popular targets were consumer services and technology, critical services, finance, and healthcare. In total, 41% of recorded incidents occurred in the US; 29% in Europe, 14% in Asia, and 9% in South America.
NCC Group data reveals that 10 cybercriminal groups were attributed to most of these ransomware attacks against businesses, ranked as follows: Numbers are one thing, but high rates don't automatically mean severe attacks or even successful extortion. However, there were some notable incidents in July.
The reputation of a cybercriminal group, especially one that has just emerged, is based not just on the ransomware it uses or the service it offers -- known as Ransomware-as-a-Service (RaaS) -- but also on how many victims it has claimed and which organizations they are.
So, it's possible that new groups will try to stroke their own egos and carve out a solid reputation without the evidence to back it up. In particular, we are talking about CRPxO, a new criminal entity that claimed to have hacked 36 organizations shortly after its emergence in July.
What to watch
July 2026 saw a surge in ransomware activity, accounting for 894 organization victims, a 22% increase month-on-month. However, as shown in the case of CRPxO, leak sites and boasting are as much about street credibility as anything else, and so we should consider this spike with reservations. Still, that's not to say ransomware isn't a serious and devastating problem for everyone, from individuals to enterprises.
Revealed in early July, JadePuffer is believed to be the first documented case of a ransomware attack powered by AI from start to finish. With other ransomware operators experimenting with LLMs, by this time next year, cybersecurity firms could be splitting their ransomware rate figures between human and AI-controlled attacks.



![[Update] Ringg AI Nets Additional $10 Mn, Closes Series](https://inc42.com/cdn-cgi/image/quality=90/https://asset.inc42.com/2026/01/Untitled-design-1-1.png)
