SECURITY Signal 20
Ransomware victim claims reached 894 in July 2026, a year-to-date high
July 2026 saw ransomware victim claims rise to 894 listings, a year-to-date high, amid the first fully agentic AI ransomware attack and claims by the new group CRPxO.
Engineers must assess whether spikes reflect real threat or inflated claims, as new groups may exaggerate victim counts to build reputation. The low-cost RaaS model of CRPxO shows how easily affiliates can join, increasing the potential attack surface. Reliance on unverified claims can lead to misallocated defenses if not validated.
Written by elseif from the cluster below · every claim links back to a sourceThe three things worth knowing
Ransomware victim listings reached 894 in July 2026, a year-to-date high and a 22% increase from June.
July 2026 also saw the first recorded incident of a fully agentic AI ransomware attack chain.
CRPxO claimed 36 victims shortly after its emergence but NCC Group rated its credibility low to moderate due to unverified claims and a low-cost RaaS model.
THE READ
What the cluster adds up to.
In July 2026, ransomware activity reached a year-to-date high of 894 victim organization listings, marking a 22% increase from June. Almost a third of the attacks targeted the industrial sector, with consumer services, technology, critical services, finance and healthcare also heavily affected. Geographic distribution showed 41% of incidents in the US, 29% in Europe, 14% in Asia and 9% in South America.
The month also recorded the first incident of a fully agentic AI ransomware attack chain, as noted in the NCC Group threat advisory. This development represents a shift toward automation in attack planning and execution. Engineers need to consider how AI-driven chains may bypass traditional detection that relies on human-operated patterns.
A newly observed ransomware group, CRPxO, claimed responsibility for 36 victims shortly after its appearance in July. NCC Group assessed the group's credibility as low to moderate, citing inconsistent evidence and lack of victim confirmation. The group operates a RaaS model offering affiliates a 70% share of payments with a low $333 entry cost, which lowers the barrier for participation.
Because claimed victim counts can be inflated to boost reputation, relying solely on numbers may mislead risk assessments. Engineers should verify claims through independent sources before allocating defensive resources. The low-cost RaaS structure means that even modestly skilled actors can launch attacks, increasing the volume of low-sophistication threats.
Earlier in the year, a single threat actor, CiOP, had been shown to drive quarterly ransomware rate fluctuations, indicating that a few groups can dominate trends. The July spike therefore reflects both genuine activity and potential exaggeration by emerging groups. Defenses must balance detection of novel AI-enhanced tactics with scrutiny of claim validity to avoid over- or under-investment.
Written by elseif from the cluster below · checked for specifics the sources never containedTHE CLUSTER
↗