July 2026 was an exceptionally active month for cyber threats, with new reporting showing both a sharp increase in ransomware activity and widespread attacks against U.S. critical infrastructure.
According to research from NCC Group reported by ZDNET, ransomware activity reached a year-to-date high in July, with 894 victim organizations listed during the month, a 22% increase from June. While ransomware leak-site figures should be treated carefully because not every claim represents a verified compromise, the increase demonstrates the continued scale and persistence of ransomware activity.
At the same time, the Cybersecurity and Infrastructure Security Agency (CISA) reported more than 100 internet-exposed systems in the U.S. water and wastewater sector were being targeted during July. Attackers primarily targeted programmable logic controllers (PLCs) connected directly to cellular modems, creating the potential for operational disruption across critical infrastructure.
Together, these developments reinforce an important reality for organizations: cyber incidents can escalate quickly, and the middle of an attack is not the time to determine how your organization will respond.
Ransomware Activity Reaches a 2026 High
NCC Group recorded 894 ransomware cases in July, the highest volume of 2026 so far. Industrial organizations accounted for 28% of observed activity, while North America remained the most heavily targeted region, representing 41% of recorded attacks.
The Gentlemen emerged as the most active ransomware group during the month, responsible for approximately 15% of observed attacks, followed closely by Qilin.
The numbers themselves are only part of the story. Ransomware remains a highly active criminal ecosystem where established groups, new ransomware-as-a-service operations, and emerging technologies can quickly change the threat environment.
For organizations, this means ransomware preparedness cannot be based on the assumption that an incident is unlikely to occur.
Critical Infrastructure Faces Growing Cyber Pressure
The activity affecting U.S. water utilities demonstrates how quickly cyber threats can move beyond data and IT systems into operational environments.
CISA reported malicious activity targeting more than 100 internet-exposed water and wastewater systems during July. Earlier reporting indicated attacks across multiple states, including incidents that locked operators out of systems and contributed to operational disruptions.
CISA has urged critical infrastructure organizations to reduce unnecessary internet exposure, secure remote access, change default credentials, patch supported systems, implement controls such as multi-factor authentication, and continuously monitor for suspicious activity.
These defensive measures are critical. But organizations also need to prepare for what happens when prevention is not enough.
Why a Ransomware Response Retainer Matters
A proactive ransomware response retainer helps establish those relationships before an incident occurs.
Instead of searching for specialized resources during an active ransomware event, organizations can have experienced support ready to activate when it’s needed.
Depending on the incident, that support may include:
  • Threat actor intelligence and assessment
  • Ransomware negotiation support
  • Compliance review
  • Compliant ransomware payment capabilities
  • Support throughout the incident response and recovery process
Preparation cannot eliminate a ransomware risk, but it can significantly improve an organization’s ability to respond when every minute matters.
Prepare Before the Incident
July’s activity is another reminder that ransomware and disruptive cyberattacks are not isolated problems affecting only a handful of organizations of industries.
From hundreds of ransomware victim claims worldwide to attacks against U.S. water infrastructure, organizations continue to operate in an environment where cyber incidents can develop quickly and carry significant operational, financial, and reputational consequences.
The organizations best positioned to navigate these incidents are those that have established their response plans, partners, and escalation procedures before they are under attack.
Do not wait for an active ransomware incident to determine who you will call.
DigitalMint Cyber’s Proactive Retainer gives organizations access to experienced cyber incident response resources before an attack occurs, helping establish a clear path forward if ransomware strikes.
Reach out to our team to learn more about our proactive retainer and get started.