Ransomware groups had their busiest month of the year in August, according to The Ransomware Brief from Cyble Research and Intelligence Labs (CRIL). The August 2026 edition records 1,034 publicly claimed victims, the highest monthly total of 2026, across 88 active gangs. Taken together, the findings suggest the threat is growing and becoming harder to detect.
The numbers
Qilin was the month’s most prolific operator, claiming 147 victims. The United States remained the primary target, absorbing 488 attacks, roughly 47% of all claims worldwide. This repeated pattern shows how consistently attackers go where the money is.
Stealing instead of locking
The report’s most striking finding is a change in method. Cl0p-linked affiliates are exploiting a critical flaw, tracked as CVE-2026-12569, in PTC Windchill and FlexPLM, software widely used by manufacturing and engineering firms to manage product designs.
Attackers chain two bugs to gain remote control of a system without logging in. Then they skip the usual ransomware playbook. There is no encryption and no ransom note. Instead, they plant hidden web shells and quietly copy sensitive material such as blueprints, CAD files and supply-chain data, which they later use for extortion.
Because nothing is locked or destroyed, standard endpoint detection tools that watch for ransomware behaviour can miss the intrusion. More than 40 organizations have already been named as victims. For companies whose value lies in their designs, silent theft can be as damaging as an outage.
Old flaws, still open
Several attacks rely on long-known weaknesses. Akira affiliates continued to use CVE-2024-40766, a SonicWall VPN flaw patched in August 2024 and listed by CISA as actively exploited since September 2024. Gunra affiliates, meanwhile, gained entry through two Fortinet vulnerabilities (CVE-2024-55591 and CVE-2025-24472), named in a joint advisory dated 10 August 2026.
The lesson is simple: unpatched, internet-facing devices remain a favourite way in.
Asia-Pacific: A different picture
The Asia-Pacific region accounted for 143 claimed victims, or 13% of the global total. India led the region with 24 claims, followed by Thailand (17), Taiwan (16), Japan (11), and the Philippines and China (10 each).
This is also the one region where Qilin did not lead. The Gentlemen group claimed 20 victims, against Qilin’s 16. Two smaller specialists, Krybit (13) and Orova (12), together claimed more victims in the region than Qilin, yet neither appears in the global top five. The report argues that such regional operators are often under-weighted in global threat models and in vendor coverage built around headline names. For security leaders in Asia, The Gentlemen should be the primary planning case.
Why it matters
Three takeaways stand out for business and security leaders:
- Patch quickly. Attackers are still exploiting flaws that are two years old.
- Look beyond encryption. Data theft without ransomware can slip past tools built to catch it.
- Plan locally. Global rankings can hide the groups most likely to target your region.
A caveat is worth noting: the figures count publicly claimed victims, so they reflect what criminal groups choose to announce, not every attack that occurs. Even so, the report offers a clear view of how the threat is evolving, and it suggests that the most dangerous intrusions may be those that make no noise.
