IT Brief Asia - Technology news for CIOs & IT decision-makers
Asia
NCC Group logs record July ransomware cases as AI rises

NCC Group logs record July ransomware cases as AI rises

Thu, 27th Aug 2026 (Today)
Joseph Gabriel Lagonsin
JOSEPH GABRIEL LAGONSIN News Editor

NCC Group reported 894 ransomware cases in July, the highest monthly total it has recorded so far this year.

The July figure was up 22% from June but 19% below the monthly record of 1,099 attacks logged in February 2025. The company published the data in its latest threat intelligence report, which also pointed to growing use of artificial intelligence in ransomware activity.

Industrials remained the most targeted sector in July, accounting for 28% of attacks. That kept critical national infrastructure and industrial organisations at the centre of the threat landscape, as ransomware groups continued to focus on operationally sensitive targets.

North America and Europe again saw the most attacks, with 41% recorded in North America and 29% in Europe. Together, the two regions accounted for 70% of all ransomware activity tracked during the month.

The data also showed a shift in threat group activity. The Gentlemen was the most active named group in July, linked to 15% of all attacks recorded by NCC Group.

A newer group, CRPxO, claimed responsibility for 36 victims in the same month. NCC Group warned that the evidence behind those claims was inconsistent and noted that new ransomware groups sometimes overstate their activity to appear more significant.

AI factor

The report said the rise in ransomware activity was driven in part by developments in AI. It identified JADEPUFFER as the first known fully autonomous, end-to-end AI-driven agent to demonstrate that it could infiltrate systems and carry out attacks without human instruction.

According to NCC Group, this marked a change in how attacks may be conducted, with autonomous tools able to move through multiple stages of intrusion and extortion without direct operator input. Current examples appear to have been aimed more at demonstrating the technology's capabilities than at generating immediate financial returns.

For defenders, the concern is that once such methods are proven, they can be refined and repeated more widely. That could allow cyber criminals to launch attacks at greater volume while reducing the manual work needed to compromise systems, move through networks and deploy ransomware.

The findings come amid increased scrutiny of cyber risks facing UK critical infrastructure and industrial operators. Those organisations often run a mix of legacy systems and newer connected technology, which can make it harder to maintain visibility, control access and patch vulnerabilities quickly.

For security teams, the combination of sustained ransomware pressure and more sophisticated automation presents a dual challenge. Established criminal groups remain active, while newer entrants can use noise, exaggerated claims and rapid tooling changes to increase uncertainty and stretch incident response resources.

Matt Hull, Vice President of Cyber Intelligence and Response at NCC Group, said the changes underway did not alter the importance of basic cyber defences.

"AI is changing the speed and scale of cyber attacks. It's allowing attackers to automate more of what they do, operate at greater scale and create increasingly convincing phishing, social engineering and other malicious content. That can make threats harder for both organisations and individuals to identify.

"For organisations, the response doesn't need to be complicated. Getting the fundamentals right remains incredibly important: strong identity and access controls, good vulnerability management, visibility across your environment and the ability to detect and respond quickly when something goes wrong.

"There's also a human element. As AI-generated content becomes more convincing, employees need to understand what threats look like, know when something doesn't feel right and have a simple way to report it.

"AI is equally valuable for defenders, helping security teams process information faster and identify potentially malicious activity. The challenge is making sure we use that technology effectively while maintaining the human judgement needed to understand what represents a genuine threat," Hull said.

The July figures underline that ransomware remains a high-volume threat for industrial organisations and Western economies, even as attackers' methods begin to shift. With 894 cases in a single month and industrial targets accounting for more than a quarter of attacks, pressure on operators to tighten access controls, improve patching and strengthen detection remains acute.