Organisations worldwide experienced an average of 2,336 cyber attacks per week in July 2026, a 16 per cent increase year on year, according to new Global Threat Intelligence insights from Check Point Research, the threat intelligence arm of Check Point Software Technologies.
The clearest shift came from ransomware, with reported attacks reaching 964 in July, up 49 per cent from June and 87 per cent compared with July 2025 — a decisive break from the more stable pattern seen in the first half of 2026, when monthly ransomware activity averaged around 672 incidents.
APAC among the most attacked regions
Latin America remained the most attacked region globally, with 3,561 weekly attacks per organisation, up 19 per cent year on year. APAC followed closely at 3,316 attacks per organisation, ahead of Africa at 3,237. Europe stood out for growth, rising 18 per cent year on year to 2,051 weekly attacks, while North America increased 9 per cent to 1,613.
On ransomware specifically, North America accounted for 45 per cent of reported incidents and Europe 28 per cent, while APAC accounted for 17 per cent of the global total. The Gentlemen and Qilin were the most prevalent ransomware groups in July, each responsible for 14 per cent of published attacks, with DeadLock ranking third at 10 per cent.
“July’s data shows that cyber risk is accumulating across multiple fronts at once,” said Omer Dembinsky, Data Research Manager at Check Point Research. “Attack volumes continue to rise, ransomware has accelerated sharply, and GenAI exposure is now part of daily business activity. Organisations need prevention-first, AI-driven security that protects networks, users, data and AI workflows before attacks can cause impact.”
GenAI exposure becomes an everyday business risk
- One in every 36 enterprise prompts carried a high risk of sensitive data leakage
- 88% of regular GenAI-using organisations were affected by high-risk prompt activity
- Organisations used an average of eight GenAI tools, with users generating 95 prompts on average
- Personal data was the most common sensitive category exposed, appearing in 70% of organisations, followed by financial data and network and IT infrastructure data at 68% each
Education remains the most targeted sector
Education remained the most targeted industry globally, averaging 4,848 weekly attacks per organisation, up 14 per cent year on year. Government followed with 3,044 attacks and Telecommunications with 2,927, while Energy and Utilities rose 20 per cent to 2,759 and Hospitality, Travel and Recreation entered the top five with 2,614 attacks, up 28 per cent.
Email also remained a high-volume risk channel: one in every 128 emails, or 0.78 per cent, was classified as phishing, with a further 20 per cent falling into unwanted or risky categories such as graymail and spam.
“Attack volumes continue to rise, ransomware has accelerated sharply, and GenAI exposure is now part of daily business activity,” said Omer Dembinsky, Data Research Manager, Check Point Research.



Share your thoughts