July 22, 2026 — Global ransomware activity increased by 3% in Q2 2026 compared with the previous quarter, according to NCC Group’s latest Quarterly Cyber Threat Intelligence Report. The report’s analysis also shows that supply chain attacks continue to increase in scale and sophistication, reinforcing the need for stronger organizational resilience.
Supply chains remain vulnerable
In the last quarter, global threat groups have continued to target trusted software development ecosystems.
Rather than attacking organizations directly, threat actors are increasingly compromising trusted software and development tools that thousands of businesses rely on. This allows a single attack to cascade across multiple organizations, making supply chain attacks one of the most effective methods of large-scale compromise.
TeamPCP has emerged as one of the most prominent groups associated with this activity, with campaigns demonstrating how compromised software dependencies and development workflows can enable downstream compromise before attacks are detected.
Most targeted regions and sectors stay consistent
Industrials remained the most targeted sector, accounting for almost a third (30 %) of all ransomware attacks globally in Q2, followed by Consumer Discretionary and Information Technology (23%). These three sectors were also the most targeted in June, with Industrials ranking top with 183 (28%) attacks, followed by Consumer Discretionary with 166 (25%) and Information Technology at 63 (9%).
In Q2, North America was the most targeted region, accounting for almost half of all global attacks (44%). The region again was also the most targeted in June with 275 (41%) attacks, followed by 153 (23%) in Europe and 133 (20%) in Asia.
Same threat groups continue to dominate at the top
Qilin remained the most active threat group for the fifth consecutive quarter, responsible for 14% (301) of all attacks. The Gentlemen group followed, with 238 victims, and DragonForce ranked third with 145. In the last three months, KryBit emerged as a new entrant to the top 10 most active ransomware groups.
VPNs under spotlight
In Q2, corporate VPNs and internet-facing edge devices continued to be prioritised by attackers. This ranged from opportunistic hackers to ransomware-as-a-service operators and nation-state sponsored APT groups exploiting software vulnerabilities to gain unauthorised entry and deepen network compromise.
Vulnerabilities affecting specific VPNs or their manufacturers accounted for some of the most common threat intelligence alerts issued by NCC Group in the first half of 2026 with many of them rated either high or critical severity.
Matt Hull, VP and head of Cyber Intelligence and Response at NCC Group, said: “Supply chain attacks continue to be one of the most attractive routes for threat actors to cause significant operational, financial and reputational damage to organizations. We have seen these attacks continue to rise in scale and sophistication, and businesses should therefore ensure monitoring and resilience is continuous, rather than ad hoc.
“Although there has not been a material rise in ransomware volume in the last quarter, the trajectory of attacks continues upwards, and VPNs remain an increasingly attractive target,” he continued. “Alongside ongoing geopolitical tensions, rapidly evolving AI capabilities and increasingly sophisticated attack methods, organizations must remain resilient and proactive in their approach to cyber security, treating it as the board-level issue it is.”


