IT Brief New Zealand - Technology news for CIOs & IT decision-makers
New Zealand
Cyberattacks & ransomware surge in July, Check Point

Cyberattacks & ransomware surge in July, Check Point

Fri, 14th Aug 2026 (Today)
Joseph Gabriel Lagonsin
JOSEPH GABRIEL LAGONSIN News Editor

Check Point reported a rise in global cyberattacks in July, while ransomware activity also climbed sharply.

Organisations faced an average of 2,336 weekly cyberattacks in July, up 3% from June and 16% from a year earlier. The figures suggest the increase seen earlier in the summer continued rather than reversed, with average weekly attacks per organisation up 13.7% since May.

Education remained the most targeted sector, with an average of 4,848 weekly attacks per organisation. Government followed at 3,044, then telecommunications at 2,927.

Energy and utilities moved into fourth place with 2,759 weekly attacks, up 20% year on year. Hospitality, travel and recreation entered the top five with 2,614 attacks, up 28%, as the sector faced heavier digital exposure during the summer.

Regional picture

Latin America recorded the highest volume of attacks, with an average of 3,561 weekly incidents per organisation, up 19% from a year earlier. APAC followed with 3,316, while Africa ranked third despite a 5% annual decline.

Europe recorded one of the sharpest growth rates, with attacks rising 18% year on year. North America posted a 9% increase.

The regional figures show a mixed picture: the highest volumes and fastest growth were not always in the same markets. Latin America led in total attack activity, while Europe showed a notable acceleration.

AI exposure

Check Point also identified growing risk linked to workplace use of generative artificial intelligence tools. Organisations used an average of eight GenAI tools in July, while the average user generated 95 prompts during the month.

According to the company's analysis, one in every 36 prompts from enterprise networks carried a high risk of sensitive data leakage. It found that 22% of prompts contained potentially sensitive information, and 88% of organisations with regular GenAI use were affected by high-risk prompt activity.

The issue extended across several categories of information. Personal data was the most common sensitive category, appearing in 70% of organisations. Financial data and network and IT infrastructure each appeared in 68%, legal and regulatory content in 63%, and employee and HR data in 62%.

By region, exposure was highest in Latin America and North America. By sector, business services and healthcare and medical recorded the highest risk levels, followed by information technology and government.

The findings suggest the risk is moving beyond isolated experiments with AI tools into routine office activity. That makes the problem less about a single application and more about how staff handle internal records, customer information and operational data across multiple services.

Email threat

Email remained a major source of cyber risk in July. One in every 128 emails, or 0.78%, was classified as phishing, while another 20% fell into unwanted or risky categories such as spam, graymail and suspicious messages.

Africa recorded the highest phishing rate, with one in every 106 emails classified as phishing. North America followed at one in every 117 emails.

Those numbers show that older attack channels remain central even as attention shifts to AI and other newer areas of concern. Phishing and related email threats still provide a common route into organisations for credential theft, malware delivery and business email compromise.

Ransomware jump

The sharpest monthly shift came in ransomware. Reported ransomware victims reached 964 in July, up 49% from June and 87% from a year earlier.

That marked a break from the pattern in the first half of the year, when monthly ransomware activity averaged about 672 incidents. The increase was spread across several regions and industries, though business services remained the most affected sector and accounted for almost one-third of reported victims.

North America remained the most affected region, accounting for 45% of reported ransomware incidents. Europe followed with 28%, while APAC accounted for 17%.

At country level, the United States accounted for 39.4% of reported attacks. Germany, Canada, the United Kingdom and Italy followed.

The ransomware figures were drawn from leak sites run by double-extortion groups that publish victim information. Such sources do not capture every incident and can reflect the tactics of the groups involved, but they remain one of the clearest public indicators of shifts in criminal activity.

Groups in focus

The Gentlemen and Qilin were the most prevalent ransomware groups in July, each responsible for 14% of published attacks. DeadLock ranked in the top three with 10% and 97 reported victims.

Check Point described The Gentlemen as a fast-growing ransomware-as-a-service operation launched in mid-2025. The group combines ransomware operations with initial access brokering, helping it expand quickly.

Qilin was identified as a longer-established ransomware-as-a-service group, with victim disclosures dating back to 2022. Renewed recruitment activity and an established affiliate structure appear to have helped it increase victim listings.

DeadLock, first observed in July 2025, has drawn attention for using blockchain-based methods to rotate command-and-control proxy addresses alongside legitimate remote management tools. The approach reflects the continuing adaptation of ransomware operators as defenders improve detection on more conventional infrastructure.

Overall, July showed pressure building on several fronts at once: rising attack volumes, persistent email risk, broader AI data exposure and a marked increase in ransomware victims. Education topped the sector list with 4,848 weekly attacks per organisation, while ransomware victims reached 964 for the month.