Skip to content
The ColumnInvestigation· No. 2791

23 ransomware attacks a day, China now in the crosshairs in 2026

The report published on July 2, 2026 by the cybersecurity firm Comparitech paints an unambiguous picture: during the first six months of

Premium reading
MadMax
Key takeaways
  1. The report published on July 2, 2026 by the cybersecurity firm Comparitech paints an unambiguous picture: during the first six months of
  2. Introduction: a world record confirming a worrying trend
  3. A report that quantifies the real scale of the threat
Transparency

Facts, quotes, and cited links remain in the body. Interpretations are framed as analysis or opinion according to the format.

Introduction: a world record confirming a worrying trend

A report that quantifies the real scale of the threat

The report published on July 2, 2026 by the cybersecurity firm Comparitech paints an unambiguous picture: during the first six months of 2026, researchers recorded 4,217 ransomware attacks worldwide, an average of 23 attacks a day. That figure marks an 11% increase over the second half of 2025, which had already totaled 3,809 attacks, according to data from the Comparitech report.

Of those 4,217 attacks, only 484 were formally confirmed by the targeted organizations themselves. The remaining 3,733 attacks were claimed solely by ransomware groups on their data-leak sites, with no public confirmation from victims, which shows just how far the real scale of the phenomenon outstrips what companies are willing to acknowledge publicly.

Over five million records compromised in six months

The human impact behind these abstract numbers is considerable: in total, 5,019,204 records were compromised in confirmed attacks alone during this period, according to Comparitech. The median ransom demand stands at $150,000, while the average climbs to $1.36 million, a gap that reveals a handful of extremely lucrative attacks pulling the average upward.

I'll say it plainly: these figures do not describe a marginal phenomenon confined to large multinationals. They describe a global criminal industry, organized, profitable, and one that keeps growing year after year despite Western enforcement efforts.

What strikes me most in this report is not the raw figure of 23 attacks a day, it's the speed at which this criminal industry has professionalized. We are no longer talking about lone hackers; we are talking about a full ecosystem with specialized groups, strategically chosen targets, and profitability that rivals some legal industries.

Qilin and The Gentlemen, the two groups dominating the rankings

A criminal hierarchy in constant flux

The group Qilin remains the most prolific of this first half of 2026 with 641 claimed victims in total, closely followed by The Gentlemen with 464 victims, then Akira with 317 victims, according to data compiled by Comparitech. It is also Qilin, with 54 confirmed attacks, and The Gentlemen, with 51 confirmed attacks, that post the strongest records for incidents officially acknowledged by their victims.

A notable fact reported by the specialized outlet The IT Nerd: in June 2026, The Gentlemen managed to knock Qilin off the top monthly spot for the first time in many months, a shift that shows even the most established groups remain vulnerable to internal competition within this criminal ecosystem.

A fragmented industry that resists police crackdowns

This competition between groups is not a sign the phenomenon is weakening, quite the opposite. According to several cybersecurity industry analyses, the growing fragmentation of the ransomware landscape, with dozens of groups active simultaneously rather than a handful of dominant players, makes the job of Western law enforcement considerably harder: dismantling one group often just shifts its affiliates to another player in the market.

This is exactly the pattern that has repeated with the dissolution of several major groups in recent years: their operators and affiliates recycle themselves almost immediately into new structures, making it illusory to believe that a one-off victory against a specific group can durably contain the overall threat.

I stay clear-eyed about this: celebrating the takedown of a ransomware group without going after the financial structures that let these criminals launder their gains means winning a battle while losing the war. As long as crime pays this easily, we will keep watching these rankings reshuffle indefinitely.

The United States remains target number one, but the gap is narrowing

A geographic shift that reveals criminal priorities

The United States remains, unsurprisingly, the most targeted country in the world with 1,832 attacks recorded in the first half of 2026, according to Comparitech. Next come Canada with 200 attacks, Germany with 164 attacks, the United Kingdom with 157 attacks, Italy with 131 attacks, France with 117 attacks, and Spain with 100 attacks.

It is worth noting, however, that attacks in the United States actually fell by 8% compared to the second half of 2025, which suggests either a genuine strengthening of American defenses or, more likely according to several industry analysts, a strategic redistribution of criminal groups' targets toward other regions of the world seen as less protected.

The West remains the preferred target, but not the only one

This ranking confirms an underlying geopolitical reality: the wealthiest, most digitized Western economies remain the preferred targets of ransomware groups, precisely because their ability to pay and their reliance on critical IT systems make them especially lucrative victims. France, with its 117 recorded attacks, illustrates well the persistent vulnerability of European digital infrastructure to a threat that knows no borders.

This Western concentration of attacks reinforces, in my view, the urgency of more robust transatlantic coordination on cyberdefense, rather than a fragmented, country-by-country approach that leaves criminals free to exploit the weakest links in the chain.

That the West remains target number one should surprise no one: we are the wealthiest, most connected economies, and therefore the most profitable to hold for ransom. But this vulnerability must not turn into fatalism. We have the technological resources to reverse this trend, provided we actually coordinate our efforts.

China, this report's most striking revelation

A 540% surge that cannot be ignored

The most striking element of this Comparitech report concerns China, which recorded one of the sharpest increases in attacks anywhere in the world: a 540% surge, rising from just 5 attacks in the second half of 2025 to 30 attacks in the first half of 2026. A figure that remains modest in absolute terms compared to the 1,832 attacks suffered by the United States, but whose growth trajectory deserves particular attention.

This sudden explosion in the number of attacks targeting China raises a legitimate question: is the Chinese regime, long seen as relatively spared by Western ransomware groups, partly due to its own digital censorship and closed infrastructure, gradually becoming a target like any other for a criminal underworld that draws no ideological distinctions when it comes to extorting a solvent victim?

What this surge reveals about Chinese vulnerabilities

According to a separate report from the firm CYFIRMA published in April 2026, the cyberthreat landscape targeting China remains dominated by groups like LockBit, World Leaks, and The Gentlemen, which primarily target the telecommunications, energy, information technology, and manufacturing sectors. These sectors, deemed strategically important by Beijing, turn out to be paradoxically just as vulnerable to ransomware as their Western counterparts, despite the tight state control exercised over the Chinese internet.

This finding seriously complicates the image of a cyber-invulnerable China that the regime likes to project internationally. If even China's critical infrastructure struggles to contain this wave of ransomware, it confirms that information security remains a universal challenge, independent of the degree of authoritarian control exercised over a society.

I say this with a certain clear-eyed satisfaction: watching China, which claims to fully master its cyberspace through censorship and mass surveillance, suffer a 540% surge in ransomware attacks, exposes an uncomfortable truth for Beijing. Authoritarian control of information is absolutely not the same thing as robust information security.

The hardest-hit sectors: business, government, and healthcare

Businesses remain the preferred target by volume

Of the 484 confirmed attacks in the first half of 2026, 319 directly targeted businesses, while 83 targeted government entities, 49 healthcare sector companies, and 33 educational institutions, according to detailed figures from Comparitech. This breakdown confirms that the private sector remains, by far, the most profitable and most frequently targeted victim for criminal groups, who know that businesses generally have more available cash to pay a ransom quickly.

Attacks against governments and businesses overall rose by 12%, while the healthcare sector saw a more moderate 4% increase. Conversely, attacks against the education sector fell by 13%, a trend Comparitech attributes potentially to strengthened cybersecurity in schools after several years of massive, widely publicized attacks.

Healthcare, a sector where the stakes go beyond finances

Even though the healthcare sector does not show the sharpest statistical increase, every attack in this field carries a direct human risk that far exceeds financial concerns: compromised medical records, paralyzed hospital systems, delayed procedures. A separate report cited by industry analysts even mentions a record ransom demand of $100 million against a Japanese hospital in the first quarter of 2026, though that payment was ultimately never made.

This reality is a reminder that behind every statistic in this report potentially lies a patient whose care was delayed, a company whose employees fear for their jobs, or a public administration unable to deliver essential services to citizens for several days, or even weeks.

One can debate ransomware statistics endlessly as if it were a purely technical problem. But when a $100 million ransom demand targets a hospital, we are no longer talking about abstract cybersecurity: we are talking about human lives potentially put at risk by pure criminal greed.

An increasingly professionalized criminal industry

The ransomware-as-a-service model keeps thriving

What makes this threat particularly hard to fight is its economic structure: the ransomware-as-a-service model, in which malware developers lease their tools to affiliates in exchange for a cut of the proceeds, allows criminals with little technical skill to launch sophisticated attacks. This model largely explains why the number of active groups keeps rising year after year, despite Western judicial enforcement efforts.

Several cybersecurity industry reports, including those from firms like GuidePoint Security, confirm that the number of distinct ransomware groups continues its rapid growth, with a 46% rise in the number of active groups between 2024 and 2025 according to their own data, a growth rate that reflects the troubling vitality of this global criminal ecosystem.

Ransom payments down, but demands up

Paradoxically, several analyses point to a roughly 8% decline in the total amount of ransom payments actually made in 2025, likely a consequence of large Western companies increasingly refusing to give in to extortion, often on the advice of their cyber insurers and law enforcement authorities. But at the same time, the median amount of individual payments has risen sharply, meaning criminals are now targeting fewer but more solvent victims, with higher individual financial demands.

This strategic shift by criminals, who now favor target quality over victim quantity, illustrates the constant adaptation of this industry in the face of Western defensive measures, a cat-and-mouse game showing no sign of slowing as the second half of 2026 approaches.

That Western companies increasingly refuse to pay is good news in principle. But as long as the median ransom keeps climbing, it simply means criminals are adapting faster than we are strengthening our defenses. This is a race the West cannot afford to lose.

What this means for Western cybersecurity in the long run

A threat that goes far beyond ordinary crime

Beyond the purely criminal dimension, several cybersecurity experts point out that some ransomware groups maintain direct or indirect ties with state actors hostile to the West, notably Russia, which has long tolerated, or even tacitly encouraged, the activity of certain criminal groups operating from its territory as long as they did not target Russian interests. This strategic tolerance considerably complicates Western diplomatic efforts to secure effective international judicial cooperation against these groups.

This geopolitical dimension turns the fight against ransomware into an issue that goes beyond simple corporate cybersecurity: it becomes an indirect battleground between the West and powers that have no real interest in seeing this threat disappear, so long as it quietly weakens Western economies without requiring direct military action.

The urgency of a coordinated response among Western allies

Given this reality, the urgency of tighter coordination among Western cybersecurity agencies, from the American FBI to its European, British, and Canadian counterparts, has never been greater. Rapid intelligence-sharing on new ransomware strains, criminal groups' command infrastructure, and their cryptocurrency money-laundering techniques is the only realistic path toward durably reversing this alarming growth curve.

Without this strengthened coordination, each Western country will keep fighting in isolation against a decidedly global, interconnected threat, a fight that recent cybersecurity history shows is lost in advance against criminal groups able to reorganize faster than our administrations can adapt their regulations.

I deeply believe this: Western cybersecurity can never win this fight in scattered order. As long as every country treats this threat as a purely national problem, we will keep chasing criminals who, for their part, operate with no regard whatsoever for borders.

A particularly heavy spring for criminal groups

Monthly data compiled by Comparitech show a jagged but broadly upward trajectory since January 2026: 711 attacks in January, a peak of 780 attacks in March, then a dip to 628 attacks in April, before regaining stronger momentum in May with a 48% increase compared to May 2025, according to figures relayed by Check Point. This month-to-month volatility illustrates how hard it is to precisely predict the pace of attacks from one month to the next, but the underlying trend remains firmly upward across the entire half-year.

May 2026 also saw a particularly sharp rise in Asia, with a 119% increase in attacks in that region, compared to 40% in Europe, the Middle East, and Africa, and 39% in the Americas, according to Check Point data. This Asian acceleration could partly explain, or at least fit within the same regional dynamic as, the dramatic increase observed in China over the whole half-year.

The business services sector especially targeted

Another worrying signal flagged by Check Point concerns the business services sector, which alone accounted for 35% of all ransomware victims in May 2026, with a year-over-year increase of 359%, rising from 54 to 248 incidents in the span of a single month compared to the previous year. This concentration on a sector as cross-cutting as business services particularly worries analysts, because a successful attack in this field can have cascading repercussions across all of the affected company's clients.

This cascade effect, where a single attack on a service provider can paralyze dozens of client companies simultaneously, represents one of the most dangerous developments in this criminal industry: ransomware groups have realized that attacking a central link in a digital supply chain multiplies their leverage far beyond a single isolated attack.

This cascade logic should alarm us far more than the raw figures on individual attacks. A single compromised digital service provider can paralyze dozens of Western businesses at once. We need to stop thinking about cybersecurity company by company and start thinking about it as a critical supply-chain issue.

Conclusion: a race the West cannot afford to lose

A tally that confirms the lasting scale of the threat

This Comparitech report confirms, with figures to back it up, that the ransomware threat is not a passing phenomenon but a solidly entrenched global criminal industry, constantly growing, and increasingly sophisticated in its targeting methods. With 23 attacks a day on average in the first half of 2026, and a dramatic 540% increase in attacks targeting China, this report maps out a global picture of cybercrime that should spare no economy, including those that believed themselves relatively protected by their authoritarian model of digital control.

For the West, this finding should serve as a wake-up call rather than just one more statistic to add to a long list of annual cybersecurity reports. The United States remains target number one, France and its European neighbors are not spared, and nothing in the current data suggests this trend will naturally slow in the months ahead.

What to watch in the second half of 2026

It will be worth closely following, in the upcoming quarterly reports from Comparitech and other specialized firms, whether the Chinese surge proves to be a lasting trend or remains a one-off spike, as well as how the balance of power evolves between criminal groups like Qilin and The Gentlemen, whose rivalry could paradoxically intensify the overall volume of attacks even further in the months ahead, each seeking to outdo the other for dominance of this lucrative criminal market.

I close this investigation with a firm conviction: as long as the West keeps treating the fight against ransomware as a compartmentalized technical problem rather than a coordinated national security issue among allies, this curve will keep climbing. The figure of 23 attacks a day is not inevitable; it is the direct result of a response that remains far too fragmented against a perfectly organized threat.

By Maxime Marquette, columnist

Columnist's transparency note

On my sources and my method

This investigation relies primarily on the semiannual report published by Comparitech on July 2, 2026, supplemented by an analysis from the firm CYFIRMA on the Chinese cyberthreat landscape, as well as journalistic coverage of this data by The IT Nerd. All figures cited come directly from these sources, and I have made no personal extrapolation beyond what these reports explicitly document.

I should note that the true scale of the ransomware phenomenon likely exceeds the figures cited here, since many attacks are never made public by the organizations affected, out of concern for their reputation or for legal reasons.

On my editorial positioning

My geopolitical analysis regarding the tolerated ties between certain criminal groups and states like Russia reflects a consensus documented by numerous Western cybersecurity experts, without constituting a formal legal accusation against a specific state for each individual attack recorded in this report.

Sources

Primary sources

Comparitech, Ransomware Roundup H1 2026 stats on attacks, ransoms, and active gangs — July 2, 2026

Comparitech, All Ransomware Studies Guides

Secondary sources

The IT Nerd, Ransomware Roundup H1 2026 stats on attacks, ransoms, and active gangs — July 2, 2026

CYFIRMA, China Cybersecurity Threat Intelligence Report — April 2026

GuidePoint Security, GRIT 2026 Ransomware and Cyber Threat Report — January 2026

Chain Store Age, retailers see sharp uptick in ransomware attacks

Get the tech columns

AI, platforms, digital power: the next analyses straight to your inbox.

Cite this article

Maxime Marquette (2026). 23 ransomware attacks a day, China now in the crosshairs in 2026. MadMax. https://mad-max.co/en/article/23-attaques-de-rancongiciels-par-jour-la-chine-dans-la-ligne-de-mire-en-2026

How does this piece make you feel?
MM
Maxime Marquette
Independent columnist

Maxime Marquette writes most of the analyses and columns published on MadMax — geopolitics, technology, and current events, no filler.

The Newsletter

Enjoyed this piece? Get the next one.

One chronicle a week, straight to your inbox. No noise.

Comments

0 / 2000

Be the first to weigh in.

This article was generated with AI assistance, under human supervision.

Investigation2992 words15 min read