In brief: German companies recorded an average of 1,723 cyberattacks per week in July 2026 (+40 percent year-on-year), while ransomware groups such as “the Gentlemen” and “Qilin” as well as risky GenAI usage are further intensifying the threat landscape.
Check Point Research recorded an average of 1,723 cyberattacks per week for German companies in July 2026 – an increase of 40 percent compared to the previous year. At the same time, ransomware activity is growing significantly worldwide, and risky GenAI usage is becoming a fixed part of everyday business operations.
According to current figures from Check Point Research, German companies recorded an average of 1,723 cyberattacks per week and organization in July 2026, an increase of 40 percent year-on-year. In Austria, the figure was even higher at 2,314 weekly attacks (+34 percent), while in Switzerland attack numbers rose by 35 percent to an average of 1,489 per week. As a result, the entire DACH region is at a historically high level.
Patrick Fetter, Lead Sales Engineer and Cyber Security Evangelist at Check Point Software, continues to cite ransomware as the driving force. The groups “the Gentlemen” and “Qilin” were particularly active in July. “The Gentlemen” specifically exploits exposed, internet-connected devices such as VPNs and firewalls as an entry point and encrypts the entire network within a few hours of gaining access. Affiliates linked to the RaaS group Qilin rely on double extortion tactics. According to Fetter, critical infrastructure (KRITIS) operators, educational institutions, and hardware providers are particularly at risk in Germany. Worldwide, the number of reported ransomware victims rose to 964 cases in July – an increase of 49 percent compared to June 2026 and 87 percent compared to July 2025. In addition to “the Gentlemen” and “Qilin” (each accounting for 14 percent of claimed attacks), the group “DeadLock” stood out with 10 percent (97 victims). By sector, education and research remained the most heavily affected worldwide, with an average of 4,848 attacks per week.
Also relevant for CISOs is the growing shift of risk into the area of generative AI. According to the analysts, one in every 36 prompts in July posed a high risk of sensitive corporate data leakage. Around 88 percent of companies that regularly use GenAI tools were affected by high-risk queries; overall, 22 percent of all examined prompts contained potentially confidential information. The inputs most frequently contained personal data (70 percent of cases), financial data (68 percent), and information on network and IT infrastructure (68 percent). On average, companies used eight different GenAI applications in parallel – an indication of pronounced shadow IT in this area.
Classic attack vectors remain equally relevant: one in every 128 emails in July was classified as phishing. Omer Dembinsky, Data Research Manager at Check Point Research, sums up the situation as one in which cyber risks are accumulating simultaneously across multiple fronts – rising attack volumes, increasing ransomware activity, and GenAI hazards as part of daily business operations. For security leaders, this creates the need to no longer limit protective measures to the network or email in isolation, but to integrate user behavior, data flows, and AI workflows into a shared, prevention-oriented security concept.
Source: www.it-daily.net · Published August 14, 2026
Lumi AI News — AI-assisted curation in accordance with Art. 50 EU AI Act. Paraphrasing and classification by Lumi News Pipeline v1.8.3.