NCC Group published its Monthly Threat Pulse for August 2026 on 23 September, and the headline number is stark: 1,073 organisations worldwide fell victim to ransomware attacks that month, a 12% jump on July’s already-elevated total of 973 and the highest monthly figure recorded so far this year. It’s the second consecutive month of record-breaking activity, and NCC Group’s own analysts point to AI-accelerated attack tooling and ongoing geopolitical instability as the two forces pushing the numbers up rather than down.
Industrial organisations bore the brunt, accounting for 31% of reported attacks, with Europe representing over a quarter of all known incidents globally. Two groups — Qilin and The Gentlemen — were behind close to a quarter of all attributed attacks between them. Both names have already shown up repeatedly against UK targets this year, from professional services firms to manufacturers, which is exactly why this isn’t a report to skim past as background noise.
Why “we’re too small to be a target” keeps being wrong
The pattern behind these record months hasn’t changed even as the totals climb: ransomware crews are not hand-picking large, famous targets. They’re running automated scanning against exposed VPNs, unpatched edge devices, and remote access tools at scale, and then working through whichever organisations respond to the scan — regardless of size. A small manufacturer or professional services firm with an unpatched firewall is just as visible to that scan as a large enterprise, and considerably less likely to have someone watching for the intrusion overnight. The record monthly totals are, in large part, built from exactly these smaller, opportunistic hits rather than headline-grabbing enterprise breaches.
It’s also worth noting why industrial and manufacturing firms keep topping these monthly breakdowns. Many run older operational technology alongside modern office IT, patched on a slower cycle because production can’t simply be switched off for an update window. That mismatch between fast-moving attacker tooling and slow-moving patch cycles is exactly the gap ransomware crews are built to exploit, and it isn’t unique to large industrial groups — plenty of smaller UK manufacturers and engineering firms run the same mix of legacy and modern systems with far fewer people watching them.
What actually reduces your odds this month
Three things move the needle more than anything else right now, in order of impact. First, check that VPNs, firewalls, and any remote access software are fully patched — edge devices remain the most common way ransomware crews get an initial foothold, and vendors have pushed out fixes for several actively exploited flaws in the past few weeks alone. Second, make sure backups are genuinely offline or immutable, not just sitting on a second drive on the same network, since ransomware crews specifically hunt for and encrypt connected backups first. Third, if you don’t currently have anyone actively monitoring for signs of compromise — unusual login times, new admin accounts, unexpected outbound traffic — that gap is worth closing before your business becomes one of next month’s record-breaking statistics rather than after. This is precisely the ongoing monitoring gap that KeepSafe was built to close for smaller UK businesses that can’t justify a full in-house security team but still need someone watching.
The takeaway
Two consecutive record months isn’t a blip — it’s a trend, and it’s being driven by opportunistic attacks on exactly the kind of exposed, under-monitored systems that smaller UK businesses are more likely to be running. If you haven’t checked your VPN and firewall patch status in the last month, or tested that your backups would actually survive an attack, this week is a reasonable time to do both.