SECURITY Signal 387
Ransomware attacks spike as world distracted by AI
Ransomware incidents rose about 20% in July to 799 recorded attacks, with a notable shift toward finance, technology, pharmaceutical and education sectors while attacks on utilities, legal and government targets declined.
For engineers, the spike underscores that foundational controls, multi-factor authentication, patching, and backups, remain critical even as AI-driven threats dominate headlines. The sectoral shift means organizations in finance, tech, pharma and education should prioritize monitoring and hardening those environments. Despite the novelty of AI-focused attacks, the observed tactics still rely on familiar vectors such as stolen credentials or zero-day exploits.
Written by elseif from the cluster below · every claim links back to a sourceThe three things worth knowing
July ransomware attacks increased nearly 20% year-over-year to 799 incidents, up from 668 in June.
Finance, technology, pharmaceutical and education sectors saw the largest rises, with finance up 71% and tech up 62%.
The gangs Qilin and The Gentlemen together claimed about one-third of the July attacks.
THE READ
What the cluster adds up to.
The recorded ransomware volume rose to 799 incidents in July, a jump of roughly 20% from the 668 incidents logged in June. This increase pushed July to the second-busiest month of the year, trailing only March’s 805 attacks. The shift in victim profile was pronounced: attacks on utilities, legal firms and government agencies fell, while finance, technology, pharmaceutical and education targets rose sharply. Finance alone saw a 71% increase, technology 62%, pharmaceutical 46% and education 44%.
Engineers should weigh the ongoing cost of basic controls, enforcing a second authentication factor, keeping software patched, and maintaining regular backups, against the observed rise. These measures address the most common ingress routes cited for the leading gangs, such as stolen credentials or abuse of zero-day vulnerabilities. However, if attackers successfully exploit a previously unknown flaw or obtain valid credentials, those controls may not prevent initial compromise, highlighting where the defenses stop working. The article notes that Comparitech provided no specific ingress data, leaving the exact failure points uncertain.
The prominence of Qilin and The Gentlemen, which together claimed about one-third of July’s victims, shows that a small set of groups can drive a large share of activity. Their methodologies, credential theft for The Gentlemen and zero-day use for Qilin as reported, reinforce that attackers rely on established techniques rather than novel AI-only methods. Consequently, diverting resources exclusively to AI-focused threats may leave gaps in defending against these proven vectors. Maintaining a balanced security posture that covers both legacy and emerging risks remains the prudent approach.
Written by elseif from the cluster below · checked for specifics the sources never containedTHE CLUSTER