Ransomware activity surged in August, with 1,034 organisations publicly named as victims worldwide, according to a new “Ransomware Brief” from Cyble Research and Intelligence Labs (CRIL).
The report says victims were attributed to 88 ransomware gangs, averaging about 33 claimed victims a day. CRIL said activity increased 25% from July and was nearly double June levels, reversing an earlier decline.
In Asia-Pacific, CRIL recorded 143 victims, representing 13% of the global total. India was the most targeted country in the region with 24 claimed victims, ranking seventh globally. Thailand and Taiwan followed with 17 and 16 victims respectively, while Japan recorded 11. The report also said Australia and New Zealand, tracked separately, recorded 22.
CRIL pointed to sector targeting that it said reflected attacker pressure points. Manufacturing, professional services, IT and ITES, and healthcare were the most targeted industries in August, with the report arguing these sectors face acute operational disruption risks and handle sensitive client data.
Globally, CRIL said the United States accounted for 484 victims, or 48% of the worldwide total, with Italy listed second at 50.
The report also highlighted regional differences in the groups driving attacks. CRIL said Asia-Pacific was the only region where Qilin—described as the world’s most active ransomware group in August—did not lead activity. Instead, CRIL reported The Gentlemen claimed 20 victims in Asia-Pacific compared with Qilin’s 16, while Krybit (13) and orova (12) also recorded notable activity in the region.
CRIL said 96 gangs posted claims in August and that the top five groups accounted for 38% of activity. It attributed the monthly surge to affiliate recruitment and exploitation of internet-facing infrastructure, rather than new encryption capability. The report also said some campaigns relied on data theft without encryption, citing Cl0p’s PTC Windchill campaign, and claimed attackers are using AI to speed up intrusions.
“The quieter first half of the year was never a sign that ransomware was fading. Gangs were regrouping, and August shows what they regrouped into,” said Daksh Nakra, Senior Manager of Research and Intelligence at Cyble. “For Indian organisations, the lesson is to stop planning against the names in the headlines. The groups most active in this region often have little global profile, and the defences that hold against them are the fundamentals: knowing what is exposed to the internet, who can reach it, and whether you can recover without paying.”
The brief recommended “discipline in existing controls,” including risk-prioritised patching of internet-facing systems, phishing-resistant multi-factor authentication extended to third parties, network segmentation, tested offline backups, and monitoring for exposure in leak and access markets.
You can read the full report here.

