AhnLab’s August 2026 Ransomware Report Details Victim Trends and Major Attacks

· Original article ↗

Summary

AhnLab’s report tracks ransomware activity in August 2026, including affected industries and regions, a rise in top-10-group victim counts, Qilin’s attack on the ATF, and CL0P’s exploitation of PTC Windchill and FlexPLM vulnerabilities.

Key points

  • The report compiled ransomware sample, affected-system, and victim statistics for August; business victim data was based on information collected from ransomware groups’ leak sites through AhnLab’s threat-intelligence infrastructure.
  • Information and communication was the most affected industry with 63 reported cases, followed by manufacturing (46) and wholesale and distribution (26). The US led by region with 158 cases.
  • Among the top 10 groups, Qilin ranked first with 167 cases and The Gentlemen second with 112. Their combined top-10 total was 577, up from 406 the previous month.
  • Qilin claimed an attack on the US Bureau of Alcohol, Tobacco, Firearms and Explosives; the ATF confirmed its CALEA system had been compromised.
  • CL0P exploited vulnerabilities in PTC Windchill and FlexPLM, adding 42 companies and organizations in 33 countries to its victim list.
  • The report describes continued activity by established ransomware groups alongside the emergence of numerous new groups.

Article Details

Publisher
Asec Ahnlab
Report Period
2026-08
Scope
Ransomware samples, affected systems, targeted businesses, and major Korean and global ransomware issues. Targeted-business statistics are based on information collected from ransomware groups’ dedicated leak sites.
Sample Size
577 reported damage incidents attributed to the top 10 groups; no overall sample size disclosed.
Key Statistics
  • Information and communication had 63 reported incidents, Manufacturing 46, and Wholesale and distribution 26.
  • The US had 158 reported cases, followed by Cyprus with 15 and Italy with 14.
  • The top 10 groups accounted for 577 reported damage incidents, up from 406 the previous month.
  • Qilin ranked first with 167 reported cases of damage; Gentlemen ranked second with 112.
  • CL0P added 42 companies and organizations from 33 countries to its victim list after exploiting vulnerabilities in PTC Windchill and FlexPLM.
Recommendations
  • Continuously monitor emerging ransomware groups and large-scale campaigns exploiting vulnerabilities.

Threat Actors

AkiraRansomware group included among the top 10 by reported damage cases.BARRACUDAReported to have attacked four organizations based in South Korea and the US.Black XReported to have targeted IWIN.BlueWhaleListed as an emerging ransomware group.Booba TeamListed as an emerging ransomware group.Cl0pAlso named Clop in the report; reportedly exploited vulnerabilities in PTC Windchill and FlexPLM and added organizations to its victim list.ClopParenthetical name given for CL0P, which reportedly exploited vulnerabilities in PTC Windchill and FlexPLM.CmdorganizationRansomware group included among the top 10 by reported damage cases.CRPx0Listed among major ransomware groups active in August 2026.Dark ProjectListed as an emerging ransomware group.DarkProjectRansomware group included among the top 10 by reported damage cases.DireWolfRansomware group included among the top 10 by reported damage cases.DragonForceActive ransomware group reported to have targeted EduSpa.DYSPHOR1AListed as an emerging ransomware group.EclipseListed as an emerging ransomware group.emperadorActive ransomware group reported to have targeted Hanwha Renewables.EverestRansomware group included among the top 10 by reported damage cases.FalconListed as an emerging ransomware group.FEMBOYListed as an emerging ransomware group.fulcrumsecListed among major ransomware groups active in August 2026.GunraActive ransomware group reported to have targeted World Tube.HelixListed among major ransomware groups active in August 2026.iah647Listed as an emerging ransomware group.INC RansomRansomware group included among the top 10 by reported damage cases.KrybitRansomware group included among the top 10 by reported damage cases.MajinahanashiListed as an emerging ransomware group.MoondancerListed as an emerging ransomware group.OrovaRansomware group included among the top 10 by reported damage cases.PanzerReported to have targeted DL E&C.QilinRansomware group ranked first by reported damage cases; claimed an attack on the ATF.SafepayReported to have targeted Air Liquide Korea.SettraListed as an emerging ransomware group.SovcaliListed as an emerging ransomware group.StormListed as an emerging ransomware group.The GentlemenRansomware group ranked second by reported damage cases.The GentlemenListed among major ransomware groups active in August 2026.VYPRListed as an emerging ransomware group.xpl0itrsListed as an emerging ransomware group.ZaWooListed as an emerging ransomware group.

Vendors

Products

Countries

Canada(cy) (15 cases), Italy (IT) (14 cases), France (FR) (13 cases), the United Kingdom (GB) (11 cases), Canada (CA) (11 cases), Germany (DE) (10 cases), and India (IN) (10 cases).CyprusBy affected region, the US (us) (158 cases) accounted for the overwhelming majority, followed by Cyprus (cy) (15 cases), Italy (IT) (14 cases), France (FR) (13 cases), the United Kingdom (GB) (11 cases), Canada (CA) (11Franceaccounted for the overwhelming majority, followed by Cyprus (cy) (15 cases), Italy (IT) (14 cases), France (FR) (13 cases), the United Kingdom (GB) (11 cases), Canada (CA) (11 cases), Germany (DE) (10 cases), andGermany(IT) (14 cases), France (FR) (13 cases), the United Kingdom (GB) (11 cases), Canada (CA) (11 cases), Germany (DE) (10 cases), and India (IN) (10 cases).India(FR) (13 cases), the United Kingdom (GB) (11 cases), Canada (CA) (11 cases), Germany (DE) (10 cases), and India (IN) (10 cases).Italythe US (us) (158 cases) accounted for the overwhelming majority, followed by Cyprus (cy) (15 cases), Italy (IT) (14 cases), France (FR) (13 cases), the United Kingdom (GB) (11 cases), Canada (CA) (11 cases),South KoreaIn South Korea, Black X targeted IWIN, Emperador targeted Hanwha Renewables, SafePay targeted Air Liquide Korea, PANZER targeted DL E&C, Qilin targeted HIGEN MOTOR, DragonForce targeted EduSpa, Gunra targeted WorldUnited Kingdommajority, followed by Cyprus (cy) (15 cases), Italy (IT) (14 cases), France (FR) (13 cases), the United Kingdom (GB) (11 cases), Canada (CA) (11 cases), Germany (DE) (10 cases), and India (IN) (10 cases).United StatesBy affected region, the US (us) (158 cases) accounted for the overwhelming majority, followed by Cyprus (cy) (15 cases), Italy (IT) (14 cases), France (FR) (13 cases), the United Kingdom (GB) (11 cases), Canada (CA) (11

Industries

ConstructionDamage was also confirmed in Professional, scientific, and technical services (18 cases), Health and social welfare services (13 cases), and Construction (13 cases).financesector, information and communication (ICT) sector, public and law enforcement sectors, and finance; by region, widespread damage was confirmed, centered on the US.Health and social welfare servicesDamage was also confirmed in Professional, scientific, and technical services (18 cases), Health and social welfare services (13 cases), and Construction (13 cases).Information and communicationIn August 2026, the Information and communication sector (63 incidents) had the highest number of affected industries, followed by Manufacturing (46 incidents) and Wholesale and distribution (26 incidents).ManufacturingIn August 2026, the Information and communication sector (63 incidents) had the highest number of affected industries, followed by Manufacturing (46 incidents) and Wholesale and distribution (26 incidents).Professional, scientific, and technical servicesDamage was also confirmed in Professional, scientific, and technical services (18 cases), Health and social welfare services (13 cases), and Construction (13 cases).public and law enforcementpronounced in the Manufacturing sector, information and communication (ICT) sector, public and law enforcement sectors, and finance; by region, widespread damage was confirmed, centered on the US.Wholesale and distributionIn August 2026, the Information and communication sector (63 incidents) had the highest number of affected industries, followed by Manufacturing (46 incidents) and Wholesale and distribution (26 incidents).

Related Articles