Ransomware attacks surged 28% month-on-month in September, marking the first rebound in six months
NCC Group's latest report reveals that ransomware attacks rose by 28% month-on-month to 421 in September, the first increase in six months. North America and Europe accounted for three-quarters of the incidents, with the industrial sector suffering 29% of attacks. Despite an overall 5% decline in the third quarter, groups like Qilin and Akira remain highly active.

Key Takeaways
- Cybersecurity firm NCC Group said Monday that ransomware attacks rose 28% month-over-month in September to 421, marking the first monthly increase in six months.
- According to the report, three-quarters of the attacks occurred in North America and Europe, including a ransomware attack on a major European airport that forced airlines to operate manually, leading to flight delays and cancellations.
- "The rise in attacks in September may indicate that the downward trend we have seen recently has come to an end," Matt Hull, NCC's head of threat intelligence, said in a press release. "With the busy season for attackers approaching—Black Friday and Christmas are just around the corner—organizations cannot afford to let their guard down."
Deeper Dive
According to news reports, major companies such as Salesforce and Dell have reported ransomware attacks this year.
NCC's research shows that the industrial sector continued to bear the brunt of ransomware attacks last month, accounting for 29% of all attacks. The sector was also the most targeted in the third quarter, accounting for 30% of attacks.
These findings "clearly demonstrate that even as public attention remains focused on consumer-facing data breaches, the industrial sector remains a highly attractive target for cybercriminals," NCC said in the press release.
It was followed by the "consumer discretionary" sector—including automakers, retail companies, and leisure facilities—with 76 attacks in total; the financial sector rose to third place with 47 attacks. "The continued targeting of the financial sector highlights attackers' strategic focus on obtaining financial data and reflects the broader trend of ransomware activities pursuing monetary gains," the press release said.
NCC said total ransomware attacks fell 5% in the third quarter compared with the second quarter.
"Despite the decline, established threat actors such as Qilin, Akira, and INC Ransom maintained high levels of operational activity, underscoring their continued influence in the threat landscape," the report said.
Cyber risk management firm Resilience reported last month, based on internal insurance claims analysis, that the average cost of a single ransomware attack rose 17% in the first half of this year. Among Resilience's clients, the average insured loss from ransomware attacks in the first half of 2025 exceeded $1.18 million, compared with $1.01 million in the same period last year. Ransomware attacks accounted for 76% of incurred losses in the first half, compared with 46% in the same period last year.
Resilience's report said cybercriminals are using increasingly sophisticated extortion tactics, including AI-driven social engineering and "double extortion"—demanding payment to decrypt data and prevent public disclosure of the data. Evolving ransomware strategies also include stealing cyber insurance policies to better assess and set higher ransom demands.