New figures published this week by threat-tracking firm Comparitech show ransomware attacks jumped 19% in July 2026 compared to June, with 799 claimed attacks logged globally — the second-highest monthly total of the year, behind only March. Two gangs, The Gentlemen and Qilin, were responsible for nearly a third of all attacks between them, locked in what researchers are calling a battle for dominance as each tries to out-claim the other on victim leak sites. The UK, meanwhile, has accounted for roughly 17% of all ransomware incidents recorded across Europe so far in 2026 — a disproportionately large share for the size of the economy.

What makes this uptick notable isn’t just the number. It’s the timing. Business and media attention this summer has been almost entirely fixed on AI — new model releases, price changes, agentic tools, governance debates. Ransomware operators haven’t paused to watch. If anything, a distracted market is exactly the condition they operate best in: fewer headlines, less pressure on vendors to patch fast, and IT teams stretched thin evaluating AI tools instead of reviewing basic security hygiene.

Why “boring” defences matter more when attention is elsewhere

Ransomware gangs overwhelmingly still get in through the same handful of doors: unpatched internet-facing software, weak or reused passwords, phishing emails, and remote access tools without proper multi-factor authentication. None of that has changed with the rise of AI-driven attacks — it’s simply competing for less attention than it used to. For a small or mid-sized UK business, that’s a useful moment to ask a plain question: when did we last actually check our backups restore properly, rather than just assuming the job ran?

The two leading groups this cycle, The Gentlemen and Qilin, both favour double extortion — stealing data before encrypting it, so paying for a decryption key doesn’t stop the threat of a public leak. That means prevention and early detection matter more than ever; once data is out the door, there’s no clean recovery, only damage control.

What to check this week

Start with the basics that consistently fail in breach post-mortems: is multi-factor authentication enforced on every remote access point, not just email? Are backups tested with an actual restore, not just a completed-job notification? Is there a named person responsible for applying security patches within days, not months, of release? If any of those questions get a shrug rather than a confident answer, that’s the gap worth closing before it becomes a headline. CoolCoding can run a practical review of exactly this kind of infrastructure hygiene without a lengthy audit process.

It’s also worth having a plan for the moment you’d rather not think about — the “we think we might have been breached” moment. Knowing who to call, what to isolate, and what your legal and regulatory obligations are shouldn’t be worked out for the first time under pressure. KeepSafe monitors continuously for exposed credentials and early signs of compromise, so a quiet breach doesn’t get louder before you notice it.

Why size doesn’t buy you protection

There’s a persistent myth that ransomware gangs only chase large enterprises with deep pockets. The victim data doesn’t support that — both leading groups this cycle have hit manufacturers, retailers, and service firms of every size, because double-extortion economics work the same whether the ransom demand is six figures or six thousand pounds. A smaller business often has less redundancy to absorb a week of downtime, and less legal and PR capacity to manage a data leak once it happens. That makes the basic hygiene checks above more urgent for an SME, not less, even though the headlines tend to focus on household-name victims.

The takeaway

Ransomware didn’t slow down this summer just because AI took the headlines — it sped up. The businesses that stay off the leak sites aren’t the ones with the most exciting new tools; they’re the ones that keep patching, backing up, and enforcing MFA even when nobody’s watching. Worth five minutes today to check yours are actually happening.