SecurityBrief Australia - Technology news for CISOs & cybersecurity decision-makers
Australia
Ransomware attacks hit yearly high in August, says NCC Group

Ransomware attacks hit yearly high in August, says NCC Group

Wed, 7th Oct 2026 (Today)
Joseph Gabriel Lagonsin
JOSEPH GABRIEL LAGONSIN News Editor

Ransomware attacks reached 1,073 in August, the highest monthly total of the year and 12% above the 960 recorded in July, according to NCC Group.

The cyber security company's monthly threat intelligence findings also showed a change in the leading threat group. Qilin was responsible for 15% of all attacks, overtaking The Gentlemen.

North America remained the most targeted region, accounting for 44% of attacks in August. Europe followed with 26%, continuing a pattern in which Western markets bore most of the reported incidents.

Industrials remained the main target by sector, accounting for 31% of attacks in August, up from 28% in July. The increase underscores sustained pressure on businesses involved in infrastructure, manufacturing and related operations.

The data points to continued disruption across large organisations. Incidents cited in the report included a customer data leak at Manchester Airports Group that affected car park, lounge, fast track bookings and in-airport WiFi systems, and an intrusion at US medical technology company Boston Scientific that disrupted manufacturing, shipping and customer order processing.

Aurora case

NCC Group also described a case handled by its Digital Forensics and Incident Response team involving the Aurora ransomware group and a transportation organisation.

In the account, Aurora exploited a virtual private network and left a short ransom note on an encrypted hypervisor. The note said confidential files had been encrypted and instructed the victim to make contact through the Tor browser using a provided .onion link and access key.

The case suggests data extortion has become a priority for the group alongside encryption and, in some cases, destruction. Aurora first emerged this year and has since targeted organisations in manufacturing, legal and research and development, the report said.

The findings come as cyber security groups track how artificial intelligence is affecting both cyber attacks and defensive measures. NCC Group pointed to the recent Hugging Face incident as an example of concerns about the behaviour of advanced AI models, saying similar issues were prompting wider debate about policy and regulation.

Matt Hull, vice president of cyber intelligence and response at NCC Group, said the latest figures suggested a sustained rise in ransomware activity rather than a one-off spike.

"August was the second consecutive month of highest ransomware levels for the year, indicating a steady rise in global activity. A combination of factors is driving this increase, including rapid advancements in AI and ongoing geopolitical volatility, which are fuelling state-sponsored threats.

"As the threat landscape evolves, organisations must ensure their resilience and response capabilities keep pace.

"AI is becoming a powerful tool for defenders and attackers. As these technologies continue to advance, the most effective approach to protecting against cyber threats will be combining AI's speed and scale with human expertise and experience. Keeping people at the centre of cyber defence, while using technology responsibly, will be key to identifying and responding to cyber risk."