Forget AI — Here’s the Real Cyber Crisis Escalating Right Now
How do you compete for attention with viral headlines proclaiming that an AI Doomsday may be coming soon?
Answer: You don’t, unless you are the President of the United States or the CEO of a trillion dollar company with your own views on this debate about slowing AI development.
But moving on to another — vastly under-reported but still significant — cybersecurity topic, ransomware attacks, along with related stories, are quietly surging as we head into the fall of 2026.
I know, I know, this ransomware topic is a decade-old narrative that is not sexy right now.
Nevertheless, the overall ransomware story is not heading in the right direction. Consider these trends:
Record Numbers: Global ransomware attacks continue to spike. For example, “Global ransomware attacks hit record 997 in August 2026 as utility, healthcare and business attacks surge.” Here’s an excerpt from that story:
“New data from Comparitech disclosed a record 997 ransomware attacks worldwide in August 2026, averaging 32 attacks per day and representing a 23% increase from 809 attacks in July. The total surpassed the previous monthly record of 988 attacks recorded in February 2025. Businesses accounted for 861 attacks, up 24% from July, while ransomware incidents targeting healthcare providers rose 30% to 69. Utility companies recorded the sharpest sector increase, with attacks doubling from five in July to 10 in August.”
Year-Over-Year Growth: Comprehensive datasets (such as Black Kite tracking) point to a nearly 25 percent increase in publicly disclosed ransomware victims compared to previous periods, with victim volumes running significantly higher as the year progresses.
Target Concentration: Attacks are hitting critical sectors hard, with manufacturing, healthcare, technology, legal services and utilities experiencing steep monthly and year-over-year spikes. Note: Attacks against water systems have also been highlighted by the FBI, even though they are not ransomware attacks.
Allow me to show what I mean with relevant examples:
Straight Arrow News (SAN) — Ransomware gang leaks more than half a million files after Florida DMV hack: “Scans of passports, driver’s licenses and Social Security cards are among the more than half-million documents leaked Monday following a hack of the Florida Department of Highway Safety and Motor Vehicles.
“The hacker group known as ‘ShinyHunters’ released a downloadable archive of the data on the dark web. The release apparently came after the hackers demanded payment from the state.
“‘State of Florida failed to reach an agreement with us despite our incredible patience, all the chances and offers we made,’ the hackers wrote. ‘They don’t care.’”
Blackfog — 105 attacks chronicled in August. I appreciate the efforts that Blackfog takes each month in reporting these metrics. Here is a sampling of those highlighted attacks, but please go to the links for many more details:
CISA — Critical VMware RCE flaw now exploited by ransomware gangs: “The U.S. Cybersecurity and Infrastructure Security Agency (CISA) warned security teams that ransomware gangs have now joined ongoing attacks exploiting a critical VMware vCenter vulnerability patched in July.
“Broadcom addressed the security flaw (tracked as CVE-2026-59310) on July 29, describing it as a critical directory traversal vulnerability in the vCenter Syslog server that unauthenticated attackers can exploit to execute arbitrary code.
“The company also warned customers in a supplemental FAQ at the time to treat fixing CVE-2026-59310 as an emergency and install patches as soon as possible.
“Two weeks later, digital forensics and incident response (DFIR) company QUIRSO reported finding over 361 IP addresses across 47 countries compromised after a suspected advanced persistent threat (APT) actor began exploiting the vulnerability to deploy a reverse SSH tool for persistence and remote access.
“Days later, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-59310 to its Known Exploited Vulnerabilities (KEV) Catalog and ordered government agencies to secure their vCenter systems within three days.”
CrowdStrike — State of Ransomware Survey: “CrowdStrike surveyed 1,100 global security leaders, and the results reveal a significant gap between perceived and actual ransomware preparedness. While half of organizations feel ‘very prepared’ to face ransomware, 78% experienced ransomware attacks last year — and fewer than 25% achieved recovery within a day. More concerning, 83% of organizations that paid ransoms were attacked again, and 93% lost data regardless of payment.”
Bitsight — Top ransomware victims per country: In the past 12 months, United States led all countries with 4294 attacks, or 36.1% of the total.
WHAT HAPPENS WHEN RANSOMWARE STRIKES?
When ransomware hits, the preparedness talk track that is common at cyber conferences is not really working as advertised. Most firms are still unable to recover quickly from ransomware, according to Infosecurity Magazine:
“Only four out of more than 800 clients (0.5%) assessed by Fenix24 came close to their own 24 to 48-hour ransomware recovery targets, and then only for partial business operations. None reached full operational capacity until several weeks after the incident.
“The finding comes from the incident response firm’s first State of Recoverability report, drawn from more than 500 ransomware recoveries and published on September 15.
“Recovery plans failed the same way each time, it said, looking sound on paper and coming apart once an attacker was inside. …
“Fenix24 found 99.2% of clients arrived with no documented identity recovery plan, and none of the plans that did exist survived contact with the threat actor. …
“The directory itself was the problem in nearly all of them. Fenix24 said Active Directory was usually the first major system to fall, and that 94% of clients had tied their backup systems to the very directory the attacker seized.”
InfoSecurity also chronicled a CISO’s lessons in ransomware response and recovery after a real-world LockBit attack. Zach Lewis, CISO at the University of Health Science and Pharmacy in St. Louis, described what happened to them in detail. Here is an excerpt:
“I was in my office at the end of the day, and I saw the README file. I just remember getting a sinking feeling in my stomach, knowing that it should not be there. I opened it up and saw the ransom note: ‘We’ve got in your system, we’ve owned it, if you don’t pay us, we’re going to come back and get you again.’
“You know it’s a make or break moment for your career. It’s one of the worst feelings in cybersecurity when your environment’s just completely down, it’s been taken out by bad guys and you can’t really do anything about it. It sucks.”
TIPS TO STOP RANSOMWARE
WCAX wrote this: Cybersecurity expert says ‘zero-trust’ approach can help prevent scams, ransomware attacks.
I’ve also covered ransomware on this blog for years. Here are a few of those articles:
CISA: Stop Ransomware government portal
No More Ransome website
FBI: How we can help (portal on ransomware).
FINAL THOUGHT
One bit of good news to share: According to Cyber News, “Conti ransomware operator sentenced to 4 years in jail for playing part in a $150M extortion campaign. The Conti ransomware extortion group may be gone, but justice has finally caught up with one of its members.”
