← BACK TO FEED
ransomwarecybersecurityQilinNHSdata breach

Ransomware Surges While Everyone's Busy Watching the AI Show

Ransomware attacks surged nearly 20% in July 2024, reaching 799 incidents — the second-highest monthly total of the year — with finance, tech, pharmaceutical, and education sectors seeing the sharpest increases. The US was the most targeted country, accounting for 322 of the attacks, while two gangs — The Gentlemen and Qilin — together claimed responsibility for roughly a third of all incidents. Notably, attacks on utilities, legal firms, and government agencies actually declined during the same period.

July was a rough month if you happened to work in IT security somewhere other than a water utility. Ransomware attacks climbed nearly 20 percent last month, with Comparitech logging 799 confirmed or claimed incidents, up from 668 in June. Fifty-one of those were verified by victims themselves. That puts July just behind March as the busiest ransomware month of 2025, with March edging it out at 805 attacks.

The sector breakdown tells an interesting story. All the noise around cyberattacks targeting US water infrastructure has dominated security coverage lately, but that threat is a separate beast entirely. Ransomware hits on utility companies actually dropped 44 percent in July. Legal firms and government agencies also saw declining attention from criminal groups, down 31 and 11 percent respectively. Make of that what you will.

The sectors getting hammered instead? Finance, tech, pharma and medical billing, and education. Attack rates in those areas jumped 71, 62, 46, and 44 percent respectively over the previous month. This tracks closely with data from pentesting outfit DeepStrike, which found that manufacturing, education, healthcare, and finance firms are the most likely to actually pay when hit. Even the most reluctant sector on that list, finance, still coughs up a ransom more than half the time. Attackers are not stupid. They go where the money is.

The US remained the most popular target by a wide margin, absorbing 322 of the 799 recorded attacks. Germany came second with 40. That gap is not a typo.

On the attribution side, two names stand out. Qilin, the gang responsible for the 2024 attack on NHS pathology provider Synnovis that caused genuine disruption to UK hospital services, claimed 125 victims in July. But they were pipped by The Gentlemen, a newer outfit that has rapidly become one of the more prolific ransomware operations around and earlier this year claimed the attack on UK software consultancy Adaptavist Group. The Gentlemen led the month with 135 claimed victims. Together, these two groups were behind roughly a third of all attacks logged in July.

How they're getting in varies. Trend Micro has linked The Gentlemen's approach to stolen credentials, which is unglamorous but effective. Qilin, by contrast, told The Register they exploited zero-day vulnerabilities to breach Synnovis last year. Different methods, same outcome. Comparitech didn't break down ingress vectors for July's data, so the specifics remain unclear for now.

The broader takeaway is fairly bleak. Ransomware is not slowing down, the perpetrators are getting more organised, and the targets are increasingly the kinds of institutions that genuinely cannot afford extended downtime. Schools, hospitals, banks. The AI conversation is important, but this threat is immediate, ongoing, and apparently quite profitable.

READ NEXT
American Bank Trusts Ransomware Gang's Pinky Promise to Delete Stolen DataGrafana Labs Got Its GitHub Raided. It's Not Paying Up.3.8 Million Patient Records Exposed in Ohio Healthcare Software Breach