The Asia-Pacific region accounted for 143 of the 1,034 publicly named victims in August, or about 13 per cent of the global total. The Americas recorded the highest number at 603, followed by Europe with 270.

New Delhi: Ransomware activity climbed to its highest monthly level of 2026 in August, with 1,034 organisations worldwide publicly identified as victims, according to a report by Cyble Research and Intelligence Labs (CRIL).
The report said 88 ransomware groups were responsible for the publicly reported victims in August, translating to an average of about 33 organisations being named each day.
August marked a sharp reversal after ransomware activity declined for three consecutive months between March and June. The number of publicly named victims increased by 60 per cent in July before rising another 25 per cent in August, the report said.
India was the most targeted country in the Asia-Pacific region during the month, with 24 claimed victims. Globally, India ranked seventh, ahead of all other countries in the region.
“India was the most targeted country in Asia-Pacific with 24 claimed victims, ranking seventh worldwide and ahead of every other country in the region,” it said.
Manufacturing emerged as the most affected sector worldwide, recording 151 publicly named victims. Professional services followed with 147, while IT and IT-enabled services (ITES) reported 126 victims and healthcare 98.
According to CRIL, these sectors are particularly exposed because ransomware-related disruptions can cause significant operational losses, while the sensitive information they hold can increase pressure on organisations to pay attackers.
“These sectors face heightened risks because of the impact of operational downtime and the sensitive client data they handle, with India’s large IT services and manufacturing base exposed to both factors.”
The report further noted that India has a substantial presence in both manufacturing and IT services, leaving organisations exposed to operational disruption as well as data-extortion risks.
“These industries are particularly vulnerable as operational disruptions can be costly, while access to sensitive client data can increase pressure on victims to pay ransoms. “India's IT services and manufacturing base sits in both categories,” it said.”
The Asia-Pacific region accounted for 143 of the 1,034 publicly named victims in August, or about 13 per cent of the global total. The Americas recorded the highest number at 603, followed by Europe with 270.
“India, Thailand, Taiwan and Japan (11) accounted for 68 victims, nearly half the region. Australia and New Zealand, tracked separately, recorded 22,” it said.
The United States remained the country with the highest number of reported victims, with 484 organisations accounting for 48 per cent of the global total. Italy was second with 50 victims.
The ransomware landscape also varied across regions. Qilin, described in the report as the world's most active ransomware group, did not record the highest number of victims in Asia-Pacific.
“Asia-Pacific was the only region where Qilin, the world's most active gang, did not lead. The Gentlemen claimed 20 victims in the region against Qilin's 16,” the report said.
Regional ransomware groups Krybit and Orova recorded 13 and 12 victims respectively in Asia-Pacific. Combined, their claimed victims exceeded Qilin's regional total, despite neither group being among the five most active ransomware groups globally, according to the report.
Published: 28 Sept 2026, 02:02 pm IST
ABOUT THE AUTHOR
Related Topics
Get Latest Mathrubhumi Updates in English
Disclaimer: Kindly avoid objectionable, derogatory, unlawful and lewd comments, while responding to reports. Such comments are punishable under cyber laws. Please keep away from personal attacks. The opinions expressed here are the personal opinions of readers and not that of Mathrubhumi.

