Vista elenco

The 80% Problem: Why AI resilience is more important than ever

14 Agosto 2026 ore 17:38

AI has been transformational for the workplace, saving time on repetitive tasks and freeing skilled staff to focus on higher-value work. It has become so embedded in organisations that ISACA’s research recently found that 82% of European companies expressly permit the use of AI at work.

However, there is a difference between using AI and governing AI use safely. Only 42% of organisations have a formal AI policy in place, and one in five (20%) don’t know who would be accountable if an AI system caused harm.

To further complicate things, it turns out that Microsoft Copilot now sits inside 80% of organisations using AI at work, well ahead of ChatGPT (56%), Gemini (37%), and Claude (21%). That means the majority of companies using AI are depending on just one vendor as an executive assistant, IT support, and sounding board.

In practice, this means that most of the business world is leaning on a single AI provider, with little planning for what happens if that provider is compromised or experiences an outage.

We use AI professionally and personally so much that, for many organisations, it is easy for compliance to become an afterthought. A tool people rely on daily doesn’t feel like a security risk – even when it is.

Leadership needs to challenge this by asking: what happens if this tool goes down, and what happens if it’s compromised? Some analysts expect over 200 high-signal disruption days across AI platforms this year and the negative impact that this will have on organisations’ productivity is considerable. Once staff begin to rely on AI-generated first drafts and summaries, reverting to manual work isn’t impossible, but it isn’t frictionless.

An over-reliance on AI – particularly on individual AI tools – can create a false sense of security, and the AI governance gap only gets worse when things go wrong. Three-fifths (59%) of companies do not know how quickly their organisation could halt an AI system in the event of a security incident, and only a fifth (21%) said they could do so within half an hour.

When a tool people rely on every day goes down, staff don’t stop working – they improvise. More than a quarter (26%) of organisations use no risk framework for AI at all, so when something does go wrong, there’s often no process to fall back on. That often means turning to whatever other AI tool is at hand, personal accounts, unapproved apps, and work-arounds that nobody has checked, at exactly the moment when careful handling of data matters most. This is why the fallback plan must exist before it’s needed, rather than being invented on the fly. The outage isn’t really the risk – how people cope during the aftermath is.

EU regulators have recognised and begun to address the AI governance gap, formally naming major cloud and AI providers, including Microsoft, as critical services to finance under the Digital Operational Resilience Act (DORA). Other sectors should expect similar action in line with NIS2 and the UK Cyber Security and Resilience Bill as the concentration risk argument spreads beyond finance.

What can businesses actually do about the AI governance gap? Firstly, they should review their AI use and record which important day-to-day work depends on a single AI tool. Where possible, they should try to diversify their provider use in order to mitigate the knock on effect of an outage.

This should be done as early as possible, as swapping AI providers isn’t like switching a light-touch SaaS tool. Foundation model capability sits with a small number of providers, so diversifying means retraining workflows and testing outputs.

Businesses should then look at their continuity plan and consider what the next steps are should their AI tools suffer an outage. Every organisation using AI should have a designated team that is responsible for managing an AI outage. But assigning ownership alone isn’t enough. Organisations also need a structured, maturity-based approach that embeds governance, accountability and resilience into day-to-day AI operations. Frameworks such as CMMI AIM provide a practical way to assess current capabilities, identify gaps and improve governance over time. That is not a decision that should be made mid-crisis, but before anything happens.

A backup option is also essential for operations that can’t afford to be put on hold until the AI is operational. Staff should be made aware of this contingency plan so that if their usual AI tool is unavailable, they don’t reach for something less secure out of habit.

This kind of business foresight is what will prevent your most useful tool becoming your biggest cybersecurity oversight.

None of this is to say that businesses should not use AI – rather that AI should be treated like any other critical part of the business, with a plan for when things don’t go smoothly. A designated owner and a tested fallback plan won’t stop the next outage, but it will decide whether it’s a minor disruption or a major one.

 

The post The 80% Problem: Why AI resilience is more important than ever appeared first on IT Security Guru.

Keeper Security Issues Cyber Guidance for Education IT Teams

14 Agosto 2026 ore 13:21

Keeper Security has urged schools, colleges and universities to strengthen their cyber defences ahead of the new academic year, warning that AI-powered phishing and a growing number of unmanaged machine identities are widening the education sector’s attack surface.

The identity security and privileged access management (PAM) provider said the annual rush to provision accounts, issue credentials and connect new devices creates a particularly attractive window for cybercriminals.

At the start of an academic year, IT teams can be responsible for onboarding thousands of students, faculty and staff while simultaneously enrolling devices and integrating third-party applications. Keeper warned that this combination can increase the likelihood of misconfigurations, stale credentials and excessive access going unnoticed.

Education institutions are already frequent targets for ransomware, credential theft and data breaches, in part because of the valuable information they hold, ranging from student and financial records to academic research.

Keeper said the threat is being compounded by relatively low levels of security awareness. Its research found that just 14% of schools mandate security awareness training, while almost one in five students and parents reported reusing passwords across personal and school accounts.

Artificial intelligence is adding another layer to the problem. AI-generated phishing messages can imitate communications from IT helpdesks, student funding departments and senior university figures with greater accuracy, potentially removing many of the spelling, grammar and formatting mistakes traditionally associated with phishing campaigns.

Deepfake technology also gives attackers the ability to impersonate trusted individuals through voice and video.

According to Keeper research, 52% of education leaders identify deepfake impersonation as a major concern, but only 26% are confident in their ability to recognise AI-enabled threats. The company also found that 41% of institutions reported being targeted by AI-generated phishing attempts or misinformation campaigns.

Beyond attacks targeting students and staff, Keeper highlighted what it describes as a less visible threat to education environments: non-human identities (NHIs).

These identities include service accounts used to synchronise student information and learning management systems, API keys connecting third-party EdTech applications, machine certificates authenticating connected equipment and cloud identities supporting automated workloads.

Increasingly, the category also includes AI agents and bots used for functions such as admissions, IT helpdesks and grading.

Keeper warned that credentials associated with these systems can be overlooked by conventional identity management practices. Service account passwords may remain unchanged for long periods, while API tokens belonging to applications that are no longer used can potentially remain active.

Cloud workloads can similarly accumulate permissions beyond those required for their function, while expired or incorrectly configured certificates can create additional security gaps.

Darren Guccione, CEO and co-founder of Keeper Security, said the education sector needed to broaden its approach to identity security.

“The conversation about education cybersecurity has historically focused on human accounts: students, teachers and administrators,” said Guccione. “But the real blind spot is the vast ecosystem of machine identities that power modern EdTech. Back-to-school is the right moment for education IT teams to take stock of every identity on their network, human and non-human alike.”

Keeper is recommending that education IT teams use the period before students return to review both human and machine access to their environments.

Among its recommendations is enforcing multi-factor authentication (MFA) across student, faculty and staff accounts, alongside deploying enterprise password management to reduce weak, reused and shared credentials.

Institutions should also audit privileged access and remove permissions associated with former employees, expired service accounts and applications that are no longer required, the company said.

For non-human identities, Keeper recommends creating an inventory covering service accounts, API keys, machine certificates, cloud identities and AI agents. Credential rotation policies should then be established, particularly for third-party EdTech integrations and AI systems introduced for the coming academic year.

The company also advised institutions to update phishing awareness programmes to account for increasingly convincing AI-generated communications.

Keeper said its zero-trust and zero-knowledge security platform can be used to discover, govern and rotate credentials belonging to both human and non-human identities. Its KeeperPAM platform additionally provides privileged access controls, session recording and audit capabilities.

As education environments become increasingly dependent on cloud services, connected equipment, third-party applications and AI, Keeper argues that knowing which identities have access (and whether they still require it) is becoming as important as protecting the students and staff behind traditional user accounts.

The post Keeper Security Issues Cyber Guidance for Education IT Teams appeared first on IT Security Guru.

Trump Signs Memorandum Allowing Private Firms to Launch Offensive Cyber Operations Against Foreign Threat Actors

14 Agosto 2026 ore 11:57

President Trump has signed a national security presidential memorandum allowing federal law enforcement agencies to partner with private technology companies to execute offensive cyber operations against foreign criminal groups and international adversaries. Under the directive, vetted private sector tech firms will be permitted to work under direct federal supervision to propose, coordinate, and execute targeted cyber actions.

The move marks a significant shift in US cyber policy, formalising a role for private industry in offensive operations that have traditionally been the preserve of government agencies.

“A coalition of the willing”

Commenting on the announcement, Kyle Hanslovan, CEO and co-founder of Huntress, said, “Considering the rapidly accelerated sophistication of organised cybercrime and nation-state actors, close public and private collaboration is no longer an option. When you add the reality of AI-powered autonomous threats, the only viable solution is a stronger coalition of the willing, which we are eager to support.

One key pillar to the success of this programme will be the appropriate use of hyperscalers for their breadth of intelligence data and die-hard security research labs like Huntress for their agility and operational depth to truly disrupt adversaries. Another key pillar will be the deconfliction process to ensure private industry doesn’t interfere with the value of long term persistent access operations which often lead to public arrests and geo-political negotiations.

All-in-all, I’m proud to see the US Government push the boundaries when it comes to denying, degrading, and disrupting these measurable threats to democracy. If done correctly, I believe it will ultimately slow the illegal transfer of wealth and knowledge from Western civilization.”

Concerns over collateral damage and delay

Not all reaction has been unreserved. Ben Bernstein, cybersecurity advisor at Huntress, added, “I’m all for expanding public-private cooperation because the government clearly can’t fight transnational cybercrime on its own, but I have concerns about how this actually plays out in the wild. When you look at the operational reality of green-lighting private offensive ops, you hit two massive roadblocks: collateral damage and bureaucratic lag.

Threat actors don’t launch attacks from labeled servers in Moscow; they route traffic through compromised, innocent infrastructure, like a vulnerable router at an Ohio dental office or a hospital network. That makes it practically impossible to “strike back” without taking out innocent bystanders. Plus, adversary infrastructure is incredibly ephemeral, often burning down in a matter of hours. By the time a vetted firm submits a target, sits through the DOJ and DHS deconfliction reviews, and finally gets a green light, they’ll be shooting at ghosts. Expecting government bureaucracy to move at the speed of modern ransomware operators is wildly optimistic.”

A signal to adversaries

Tim Mackey, head of software supply chain risk strategy at Black Duck, struck a more cautionary tone, concluding, “Ignoring the reality that it’s difficult to identify the source of cybercriminal activity, endorsing private companies to conduct offensive cyberactivity is far more likely to increase criminal, and potentially nation-state, activity than deter it. Without careful governance and control, individuals with access to sophisticated surveillance technologies could easily abuse that access and engage in surveillance efforts for personal gain. Unfortunately, one message this memo does send to adversaries is – the US government needs private companies and their capabilities to defend against cyberattacks.”

The memorandum is likely to prompt further debate within the security community over how offensive cyber operations conducted by private firms should be governed, vetted, and deconflicted from ongoing law enforcement and intelligence operations.

The post Trump Signs Memorandum Allowing Private Firms to Launch Offensive Cyber Operations Against Foreign Threat Actors appeared first on IT Security Guru.

Meet Huntress at International Cyber Expo 2026

14 Agosto 2026 ore 10:26

Huntress will be heading to International Cyber Expo 2026, where visitors can meet the team on Stand K94 and discover how the company is helping organisations tackle increasingly complex cyber threats with fewer resources.

One of the biggest challenges Huntress is seeing is the growing attack surface. Security teams are expected to protect endpoints, identities, cloud environments and other systems, often while dealing with limited time, resources and expertise.

At the same time, attackers are no longer operating in silos. Attacks increasingly move across different parts of an organisation’s environment, leaving security teams managing multiple tools and an overwhelming number of alerts.

At International Cyber Expo, Huntress will showcase its more unified, managed approach to security. The Huntress platform combines greater visibility across the attack surface with AI technologies and human security analysts to help partners and customers detect and respond to threats.

Tackling the rise of AI-powered attacks

AI-powered cybercrime will also be a major focus for Huntress at the show.

Generative AI is making it easier for attackers to create convincing phishing emails, develop malicious code and scale their operations. Tasks that previously required significant cybersecurity expertise can now be carried out with the help of readily available AI tools.

Huntress believes AI will also play an important role in helping defenders respond. Its approach uses AI to help analysts correlate security signals, summarise investigations and work faster, while retaining human judgement and context when making critical security decisions.

Visitors can also speak with Huntress about practical ways to strengthen their security posture. These include implementing multi-factor authentication, improving security awareness training and reducing vulnerabilities across the external network perimeter.

And when preventive controls fail, Huntress stresses the importance of having a mechanism to detect and respond to attacks quickly, including access to a 24/7 SOC that can support containment and remediation.

Listen to Huntress Senior Sales Engineer Alex Hitchen discuss the biggest cybersecurity challenges facing organisations today and what Huntress will be showcasing at International Cyber Expo 2026:

 

 

You can still register for FREE to attend International Cyber Expo HERE.

The post Meet Huntress at International Cyber Expo 2026 appeared first on IT Security Guru.

Scammers Exploit Shopify’s Own Notification System in New ‘Fake Refund’ Scam

13 Agosto 2026 ore 15:10

Security researchers have identified a phishing campaign that abuses Shopify’s own Shop app to deliver fake order and refund notifications directly to victims’ phones, marking a notable evolution of the classic “fake refund” scam.

According to research from cybersecurity firm Huntress, attackers are creating fraudulent Shopify seller accounts, or hijacking legitimate ones, to generate bogus orders against victims’ phone numbers or email addresses. Because Shopify’s Shop app treats these as genuine transactions, targets receive real push notifications and in-app receipts, rather than a suspicious email or text from an unfamiliar sender. Huntress said several of its own employees were targeted between May and August 2026, and that the technique has also been documented by researchers at Gen Digital and reported by users on Reddit.

In one example cited by Huntress, a fake receipt dated 7 August billed the recipient $339.96 for a “premium PC protection plan,” complete with a fabricated invoice number and transaction ID. The real sting sits in the shipping address field, which attackers repurpose to display a message urging the recipient to call a phone number if they did not place the order. Some variants dispense with the fake address altogether and instead push recipients toward the number via the order description, while others add a spoofed “out for delivery” shipment tracker to increase pressure on the target.

Victims who call the number are funnelled into a standard refund scam. Huntress said callers are typically talked into installing remote access tools such as ScreenConnect or AnyDesk, or into logging into their online banking. From there, scammers manipulate on-screen figures, sometimes editing displayed transaction details or coaching victims to misread a refund amount, to convince them they were mistakenly overpaid. Victims are then pressured to “return” the difference, usually by purchasing gift cards and handing over the redemption codes, which attackers cash out quickly.

Huntress frames the campaign as a variant of a technique it calls Living off Trusted Sites (LoTS), where attackers route victims through a legitimate, trusted platform before reaching a malicious outcome, rather than relying on a fake domain that is easier to flag. While earlier LoTS attacks used links to services such as Dropbox, Canva, or DocuSign to add credibility, this campaign instead abuses Shopify’s own notification pipeline to generate content that looks and functions exactly like a native alert. The firm noted a similar pattern in a previous campaign involving genuine PayPal invoices carrying fraudulent callback numbers.

Shopify has acknowledged the scam in its Help Center. The company and Huntress both advise users not to interact with unfamiliar phone numbers, email addresses, or links found within an order, and to contact Shop Support directly if they are concerned about the security of their account. Users who receive a suspicious order notification are advised to check their bank statements before assuming any charge went through, and can flag the order as “Not my order” within the Shop app. Huntress also recommends checking a store’s reviews and history before purchasing, noting that many of the fraudulent shopfronts used in this campaign were newly created.

The post Scammers Exploit Shopify’s Own Notification System in New ‘Fake Refund’ Scam appeared first on IT Security Guru.

Akira Ransomware Affiliate Rebooted Into Safe Mode to Dodge EDR and Broke Its Own Attack

13 Agosto 2026 ore 13:59

An affiliate of the Akira ransomware operation attempted a novel technique to blind endpoint defences during a recent intrusion, rebooting a compromised server into Windows Safe Mode to knock out both an EDR agent and Microsoft Defender in one move, only for the same stripped-down environment to cause the ransomware payload itself to crash before it could encrypt any files.

The incident, disclosed in a technical write-up published by managed detection and response provider Huntress, marks the first time researchers have observed Akira affiliates using a Safe Mode reboot to sidestep security tooling, a tactic more commonly associated with older ransomware families such as Snatch and AvosLocker.

Akira has been one of the most active ransomware operations tracked by Huntress over the past year, and its affiliates typically follow a consistent playbook: break in through an internet-exposed VPN appliance, most often from SonicWall, move laterally to the domain controller, enumerate Active Directory, exfiltrate data, and detonate the encryptor within a matter of hours. This latest attack followed that pattern almost exactly, according to Huntress, but introduced a twist at the final stage.

Credential Spray, No MFA, and a Familiar Path to the Domain Controller

According to Huntress, the intrusion began in early August with a burst of failed login attempts against a SonicWall SSL VPN, consistent with a credential-spraying attack. Roughly seven minutes later, one attempt succeeded: a valid VPN account with no multi-factor authentication in place. Nearly two hours passed before the attacker took hands-on action, logging into the domain controller over RDP and running PowerShell commands to dump full property details on every user and computer in the Active Directory environment, reconnaissance Huntress says is a hallmark of Akira intrusions.

The attacker then moved to an application server, installed WinRAR to archive mapped file shares, and used the S3 transfer tool s5cmd to upload the staged data to a cloud storage bucket under their control, standard double-extortion tradecraft designed to give the attacker leverage even if a victim can recover from backups. AnyDesk, a legitimate remote access tool, was installed as a persistent service and used both for hands-on-keyboard control and to deliver the ransomware payload itself.

The Safe Mode Gambit

Rather than spinning up a separate virtual machine to run the encryptor outside the reach of security software — a method Huntress has documented in earlier Akira cases- the affiliate instead used the built-in Windows configuration tool msconfig.exe to force the host to reboot into Safe Mode with Networking. Because Safe Mode loads only core Windows drivers and disables most third-party software by design, the reboot simultaneously took the Huntress agent offline and prevented Microsoft Defender’s real-time protection from starting, all while preserving the network connectivity the attacker needed to keep working.

The attacker had anticipated that Safe Mode would also block their own AnyDesk service, and pre-emptively added a registry entry to keep it running through the reboot, a detail Huntress says shows deliberate planning rather than an improvised move.

The Ransomware Undermined Itself

The plan worked well enough to blind defences, but it also appears to have doomed the attack. Minutes after the akira.exe payload launched, the host began throwing “out of virtual memory” errors, and the ransomware process tree failed before encryption could begin. Huntress attributes the crash to Safe Mode’s constrained memory environment, which was seemingly unable to support the ransomware’s resource demands.

A scheduled Defender scan eventually flagged the payload roughly an hour later, correctly identifying it as Akira, but could not quarantine it because real-time protection remained disabled in Safe Mode. The file was only removed after the attacker rebooted the host back into normal operation, restoring Defender’s protection in the process, meaning the attacker’s own anti-EDR trick was undone by their need to reverse it.

Despite the failed encryption, the attacker had already exfiltrated Active Directory data and file shares before the reboot, leaving the victim exposed to extortion even without any files being locked. Huntress cautioned that the outcome should not be read as a reliable defence: a host with more memory or a larger page file might allow the encryptor to succeed in Safe Mode, and researchers said it is plausible Akira’s developers will adjust the malware’s memory footprint or boot sequence to make the technique more reliable in future attacks.

Recommendations

Huntress urged organisations to enforce MFA on all VPN accounts, monitor for bursts of failed VPN logins followed by a successful one, and ensure EDR is deployed across every endpoint rather than a subset of the environment. It also recommended that defenders specifically alert on boot-configuration changes and Safe Mode reboots, including msconfig.exe and bcdedit activity, and Windows event log entries indicating a Safe Mode boot as well as any modification to the registry keys that control which services are permitted to run in Safe Mode.

The post Akira Ransomware Affiliate Rebooted Into Safe Mode to Dodge EDR and Broke Its Own Attack appeared first on IT Security Guru.

Forescout Launches Rapid Insight Assessment to Uncover Hidden Cyber Risks

13 Agosto 2026 ore 13:04

Forescout has launched a new Rapid Insight Assessment designed to help organisations uncover hidden assets, network blind spots, and security exposures as artificial intelligence accelerates vulnerability discovery.

The new assessment combines external analysis with passive network monitoring to give security teams a clearer picture of their attack surface. Forescout says the service can deliver actionable findings within days, helping organisations identify and prioritise risks before attackers exploit them.

The launch comes as security teams face the challenge of managing increasingly complex environments. Unmanaged devices, shadow assets, exposed services, and gaps in network visibility can all create opportunities for attackers.

At the same time, advances in AI are making it possible to discover and exploit vulnerabilities faster.

Finding security exposures before attackers do

The Rapid Insight Assessment uses open-source intelligence to examine an organisation’s external exposure. For internal assessments, Forescout can also deploy its portable Flyaway Kit to passively observe network activity without disrupting operations.

The Flyaway Kit provides visibility across IT, OT, IoT, cyber-physical systems, and unmanaged devices, including assets within remote and air-gapped environments.

The assessment can identify internet-facing remote access services, exposed administrative interfaces, previously unknown network devices, risky communications, and unmanaged OT and IoT assets.

It can also provide more detailed asset intelligence and identify devices associated with Known Exploited Vulnerabilities.

AI is shrinking the window for defenders

Craig Weimer, Vice President and General Manager of Americas at Forescout, said the increasing ability of AI systems to carry out cyber tasks is changing how quickly organisations need to identify security weaknesses.

“When an AI system can discover, connect, and exploit vulnerabilities on its own, the idea of an autonomous attacker is no longer just a future concern,” Weimer said.

He pointed to recent public disclosures from OpenAI, Anthropic, and Meta showing that frontier AI models can perform complex, multi-step cyber tasks against real environments with limited human involvement.

“The message for defenders is clear: the window between exposure and exploitation is getting smaller, and organisations need a complete understanding of their attack surface before adversaries find it first,” he added.

Tackling network blind spots

One of the challenges facing security teams is that they cannot protect assets they do not know exist. This becomes particularly difficult across large or distributed environments where new devices and services can appear without being captured by existing security processes.

Forescout says its Rapid Insight Assessment is intended to provide organisations with a faster way to uncover these gaps without lengthy assessment cycles.

“Organisations can’t afford assessment cycles that take months when hidden exposures, network blind spots, and unknown assets can quickly become opportunities for attackers,” Weimer said.

“The Rapid Insight Assessment gives organisations a fast, efficient way to see their most critical security risks and exposure gaps, delivering clear, actionable findings in days so they can address exposures before they become security incidents.”

As AI gives attackers greater speed and automation, gaining an accurate view of the attack surface could become increasingly important. For defenders, finding hidden exposures before an adversary does may prove critical to reducing the opportunity for an attack in the first place.

Learn more and request your free Forescout Rapid Insight Assessment.

The post Forescout Launches Rapid Insight Assessment to Uncover Hidden Cyber Risks appeared first on IT Security Guru.

UK Cyber Attacks Jump 26% Year-on-Year as Ransomware Activity Doubles Globally

13 Agosto 2026 ore 12:57

UK organisations were hit by an average of 1,597 cyber attacks per week each in July 2026, a 26% increase year-on-year, according to new data from Check Point Research, the threat intelligence arm of Check Point Software Technologies. The growth rate outpaced the 16% year-on-year rise recorded globally, even though UK attack volumes remained below the worldwide average of 2,336 weekly attacks per organisation.

The figures form part of Check Point Research’s Global Threat Intelligence report for July 2026, which found that cyber risk is accumulating across multiple fronts at once: rising attack volumes, a sharp acceleration in ransomware activity, and growing exposure from the use of generative AI tools in the enterprise.

In the UK, Education, Energy & Utilities, Software, Government, and Media & Entertainment were named as the five most targeted industries in July, reflecting attackers’ continued focus on sectors that hold sensitive personal data, run critical national infrastructure, or present broad, distributed attack surfaces.

Global attacks keep climbing

Worldwide, organisations faced an average of 2,336 weekly cyber attacks in July, up 3% month-on-month and 16% year-on-year. Education remained the most targeted sector globally, averaging 4,848 weekly attacks per organisation, up 14% year-on-year. Government followed with 3,044 attacks and Telecommunications with 2,927, while Energy and Utilities rose 20% to 2,759 attacks and Hospitality, Travel and Recreation entered the global top five with 2,614 attacks, up 28%, likely reflecting increased exposure during the summer travel period.

Regionally, Latin America recorded the highest attack volume, with 3,561 weekly attacks per organisation, up 19% year-on-year, followed by APAC at 3,316. Europe stood out for its rate of growth, with attacks up 18% year-on-year to 2,051 per organisation, ahead of North America’s 9% rise to 1,613.

Ransomware breaks from its earlier pattern

The sharpest shift in July came from ransomware. Reported victims reached 964 globally, up 87% year-on-year and 49% from June, marking a decisive break from the first half of 2026, when monthly ransomware activity averaged around 672 incidents. Business Services was the most affected sector, accounting for 32.5% of reported victims, followed by Industrial Manufacturing at 14.4% and Consumer Goods and Services at 13.4%.

North America remained the most affected region for ransomware, accounting for 45% of reported incidents, followed by Europe at 28% and APAC at 17%. At country level, the United States continued to dominate the victim count with 39.4% of reported attacks, followed by Germany, Canada, the United Kingdom and Italy.

The Gentlemen and Qilin were the most prevalent ransomware groups in July, each responsible for 14% of published attacks, while DeadLock climbed to third place with 10% and 97 reported victims, highlighting continued churn in the ransomware ecosystem.

GenAI exposure becomes a daily business risk

The report also highlighted the growing data exposure risk posed by generative AI tools. One in every 36 prompts sent from enterprise networks carried a high risk of sensitive data leakage, and 88% of organisations that regularly use GenAI tools were affected by high-risk prompt activity. Organisations used an average of eight GenAI tools in July, with individual users generating 95 prompts on average during the month.

Personal data was the most common sensitive category exposed, appearing in 70% of organisations, followed by financial data and network and IT infrastructure information, each present in 68% of organisations.

Email also remained a high-volume risk channel: one in every 128 emails, or 0.78%, was classified as phishing in July, with a further 20% falling into unwanted or risky categories such as graymail, spam and suspicious messages.

“Cyber risk is accumulating across multiple fronts”

“July’s data shows that cyber risk is accumulating across multiple fronts at once,” said Barnaby Nickels, regional sales manager for UKI & North EU at Check Point Software. “Attack volumes continue to rise, ransomware has accelerated sharply, and GenAI exposure is now part of daily business activity. Organisations need prevention-first, AI-driven security that protects networks, users, data and AI workflows before attacks can cause impact.”

For UK organisations, the message lands with particular urgency. With attack growth outpacing the global average and sectors ranging from education to critical infrastructure squarely in attackers’ sights, security teams are being urged to strengthen defences across network, cloud, endpoint, email and AI usage rather than relying on any single layer of protection.

The post UK Cyber Attacks Jump 26% Year-on-Year as Ransomware Activity Doubles Globally appeared first on IT Security Guru.

❌