Up, Down, and Sideways: What Three Ransomware Trend Claims in One Week Actually Measure- 304
August 9, 2026
Three pieces of ransomware reporting circulated within days of each other this month, and a reader skimming headlines alone could be forgiven for concluding the security press had lost the ability to agree on the most basic fact about the threat: is ransomware getting worse, or is it finally being brought under control? One report says attacks jumped nearly 20 percent in a single month. Another cites a 389 percent surge in confirmed victims. A third says attacks are falling as businesses get better at defending themselves. Read as three data points about the same phenomenon, they look irreconcilable. Read more carefully, they turn out to be measuring three different things, over three different timeframes, using three different levels of evidentiary rigor — and only one of the three actually shows its work.
The most substantive of the three comes from Comparitech, whose monthly count, reported by The Register, tracked 799 ransomware incidents in July, up from 668 in June — a real, specific, sourced number, tied to a defined methodology of counting claimed or confirmed attacks within a single calendar month. Comparitech's own data immediately complicates any simple "ransomware is surging" headline, though: July was still the second-busiest month of the year, narrowly behind March's 805 incidents, meaning the jump reads less like a new record than like ordinary month-to-month noise within a range that has stayed elevated all year. More tellingly, the aggregate figure conceals a significant reallocation beneath it rather than a uniform increase — attacks on utility companies fell 44 percent, legal firms fell 31 percent, and government agencies fell 11 percent, even as finance, technology, pharmaceutical and medical-billing, and education organizations all saw sharp increases, from 44 to 71 percent depending on sector. A single topline number — up 20 percent — is true and also conceals that ransomware operators visibly redirected their effort toward more profitable, more exposed sectors rather than simply attacking more of everything. Comparitech also names names: Qilin and a fast-rising operation called The Gentlemen together claimed nearly a third of July's attacks, giving the topline trend an actual attributable source rather than leaving it as an abstract statistical drift.
The second claim, carried by a report surveying multiple vendor sources, cites Fortinet's figure of a 389 percent year-over-year surge in confirmed ransomware victims, from roughly 1,600 in 2024 to 7,831 in 2025. On its face this looks like it flatly contradicts nothing in Comparitech's July data — the two numbers aren't actually incompatible, because they aren't measuring the same window at all. Comparitech's 799 is a single month in 2026; Fortinet's 7,831 is a full calendar year, one year earlier. Presented side by side in the same week of coverage, though, an unwary reader has no way to know that, and the natural instinct is to read "up 20 percent" and "up 389 percent" as competing estimates of the same underlying trend rather than as two entirely different measurements that happen to share a topic. The more important detail in this second report is who is doing the talking: every expert quoted — from Fortinet, Sophos, SentinelOne, Tenable, Nile, Delinea, Risk Ledger, and DriveSavers — sells a product or service whose value proposition depends on ransomware being a large and growing threat. That does not make their observations wrong; Fortinet's victim count is a real, if differently-scoped, data point, and the underlying claim that AI tools have lowered the cost of running a ransomware operation is plausible and consistent with what Comparitech's sector data shows. But a set of quotes drawn entirely from vendors with a direct commercial stake in threat severity is not neutral evidence about the state of the threat, and the piece surveying them makes no attempt to seek out a countervailing, disinterested source before printing "ransomware is more sophisticated than ever" as its framing.
The third claim is the one that should draw the most scrutiny, precisely because it received the least. A report asserting that ransomware attacks are falling thanks to improved patch management, wider multi-factor authentication adoption, and more mature endpoint detection and response tooling cites no organization, no dataset, no year-over-year comparison, and no specific figure of any kind — not the number of attacks it claims are declining, not the period over which they declined, not a single named analyst or firm behind the observation. Every mechanism it describes — better MFA, better patching, better backups, better detection — is a real and independently well-documented industry trend, and each one plausibly would reduce successful ransomware compromises if adopted widely enough. But plausible mechanisms are not the same thing as an established trend, and nothing in the piece connects the stated mechanisms to an actual measured decline in attack volume anywhere. It reads, structurally, like industry best-practice advice content dressed in the language of an observed statistical trend — which matters a great deal when it runs, unlabeled, in the same week as two reports built on named datasets, because a reader has no obvious way to distinguish "ransomware is falling, and here is the data" from "ransomware would probably fall if organizations did the following things, phrased as though it were already happening."
None of this means Comparitech's or Fortinet's numbers are beyond question — leak-site and claimed-victim counts are themselves an imperfect proxy for the true scale of ransomware, since they only capture attacks a gang chooses to publicize or a victim chooses to confirm, missing silent payouts, quietly resolved incidents, and attacks blocked before encryption ever occurred. But there is a meaningful difference between a metric that is imperfect and disclosed, and a claim that supplies no metric at all. The actual finding this week isn't that the security industry can't agree on whether ransomware is up or down. It's that "ransomware trend" coverage routinely blends genuinely different measurements — a monthly incident count, an annual victim tally, and an undocumented assertion — into a single undifferentiated conversation, and that the version of the story requiring the least evidence is often the one that travels the easiest, because a tidy narrative about improving defenses needs no citation to feel true, while a specific, sourced number inevitably invites the harder questions about what, exactly, it does and doesn't count.
