August Cyber Threats Rise as Ransomware Nearly Doubles and GenAI Data Exposure Becomes a New Enterprise Risk
Check Point Research reveals a 22% year-on-year increase in global cyber attacks and a rise in phishing activity. Attacks on African organisations exceed global averages
Check Point Research, the threat intelligence arm of Check Point® Software Technologies Ltd., today released its Global Threat Intelligence insights for August 2026, revealing that organisations worldwide experienced an average of 2,422 cyber attacks per week, representing a 4% increase month on month and a 22% increase year on year.
Weekly attacks on organisations in African countries exceeded the global average in August. Of the four countries included in the August 2026 report, Angola had 5,416 attacks per organisation per week (up 47% YoY), followed by Nigeria with 4,906 attacks (up 45% YoY), and Kenya with 3,658 attacks per organisation per week (up 6% YoY). South Africa was slightly lower than the global average at 2,086 attacks per organisation per week (down 3% YoY).
The findings point to a broad escalation in cyber risk, with attack volumes continuing their upward trend while ransomware, phishing and GenAI-related data exposure remained key enterprise security challenges. Together, these trends underline the need for a prevention-first security strategy that gives organisations consistent visibility and control across users, email, networks, cloud environments and AI tools.
Latin America Tops Regional Attack Volumes as Europe Posts the Fastest Growth
Latin America was the most attacked region, with 3,577 weekly attacks per organisation, up 25% year on year. Europe recorded the fastest growth in attack volumes, rising 28% year on year, while Africa reached 3,335 weekly attacks (up from 3, 237 in July 2026) and APAC 3,325 (3,316 in July 2026). The increase in Europe shows that cyber pressure is not limited to traditionally high-volume regions but is spreading across mature digital economies where organisations operate complex, interconnected environments.
Africa’s Energy & Utilities sector most targeted
Africa’s Energy & Utilities sector was the most targeted in August, followed by financial services and Government institutions.
“This should be a red flag to all concerned,” says Lorna Hardie, Regional Director: Africa for Check Point Software. The Energy & Utilities sector is the heartbeat of any country’s economy, and ensuring its cyber security should be a matter of priority for all concerned.
“Furthermore, August’s data shows cyber risk expanding across several fronts at once,” Hardie said. “With attacks climbing, ransomware accelerating, phishing remaining a common entry point and GenAI creating a new route for data exposure, security teams cannot rely on fragmented defences. They need a prevention-first protection approach that combines visibility, control and automation across network, cloud, endpoint, email and AI usage to stop threats before they disrupt operations or expose sensitive information.”
Education Faces the Highest Attack Volumes While Hospitality and Travel See a Summer Surge
Education remained the most targeted sector globally, with 5,354 weekly attacks per organisation, up 28% year on year. Government followed with 3,067 weekly attacks, while Hospitality, Travel and Recreation rose to third place with 3,056 weekly attacks, up 56%. This pattern reflects how attackers continue to focus on environments with large user bases, multiple access points and valuable data flows, where disruption can have an immediate operational impact.
GenAI Adoption Accelerates, Keeping Sensitive Data Exposure on the Security Agenda
GenAI-related risk remained part of everyday business operations in August. High-risk GenAI prompts fell to their lowest level in several months, with one in every 43 prompts from enterprise networks posing a data exposure risk. At the same time, overall usage continued to climb, with the average user generating 106 prompts during the month, up from 95 in July and 78 in June. The contrast suggests that while some organisations may be improving awareness or controls, the rapid expansion of GenAI use continues to increase the number of moments where sensitive information could be entered into tools without adequate governance.
The issue remained widespread: 86% of organisations using GenAI regularly were affected by high-risk prompt activity, while organisations used an average of seven different AI tools. This highlights a growing governance challenge, as the security risk is not only the use of GenAI itself, but the lack of visibility into what data is being shared, where it is going and whether it can be protected before exposure occurs.
Healthcare and Medical recorded the highest high-risk GenAI prompt exposure rate at 4%, followed by Software at 3.6% and Business Services at 3.5%. Latin America recorded the highest regional rate at 3.5%, above the global average of 2.3%. These differences point to the need for sector-specific AI governance, particularly in data-rich industries where employees may be more likely to handle sensitive, regulated or proprietary information.
Phishing Activity Rises as Malicious Links Dominate Email-Based Threats
Email remained a key attack vector, with one in every 112 emails classified as phishing, compared with one in every 128 in July. Links appeared in 72% of phishing emails, while 14% contained attachments. The continued dominance of links reflects how easy it is for attackers to scale social engineering campaigns, by pivoting lures quickly to current events or business processes and leading users to credential harvesting or malware delivery sites. By industry, Associations and Nonprofits saw the highest rate at 1.87%, followed by Construction and Engineering at 1.74%. These sectors often depend on frequent external communications, donations, tenders, partners or suppliers, which can make it harder for users to distinguish between legitimate and malicious outreach.
Ransomware Victim Numbers Surge, with Business Services Bearing the Brunt
Ransomware activity continued to accelerate in August. A total of 1,042 ransomware attacks were reported, almost double the level recorded in August 2025 and 8% higher than in July. Business Services remained the most targeted industry, accounting for 36% of reported ransomware attacks, followed by Industrial Manufacturing at 13% and Consumer Goods and Services at 12%. The concentration in Business Services suggests attackers are continuing to prioritize organisations that sit at the centre of wider supply chains and can create broader downstream disruption.
Ransomware Landscape Shifts as Qilin Leads and Orova Breaks into the Top Three
Qilin was the most active ransomware group in August, responsible for 15% of published attacks, followed by The Gentlemen with 10%, and then Orova, which entered the top three for the first time. The movement among leading ransomware groups illustrates how the threat landscape remains fluid, with established actors maintaining pressure while newer or previously less visible groups can quickly gain prominence.
“For enterprises, the August threat landscape reinforces the importance of moving from reactive detection to proactive prevention, supported by unified security controls that can reduce complexity while helping teams identify and block threats across increasingly distributed digital environments,” Hardie concludes.
For more insights into August 2026 cyber threat trends, visit the Check Point Research Blog.


