International Cyber Expo International Cyber Expo
  • About Us
Thursday, 8 October, 2026
IT Security Guru
International Cyber Expo
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us
No Result
View All Result
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us
No Result
View All Result
IT Security Guru
No Result
View All Result

Global cyber attacks up 48% as ransomware and phishing climb, Check Point finds

by Guru Writer
October 8, 2026
in News
Global cyber attacks up 48% as ransomware and phishing climb, Check Point finds
Share on FacebookShare on Twitter

Organisations worldwide faced an average of 2,803 cyber attacks per week in September 2026, up 16% on August and 48% on the same month last year, according to new data from Check Point Research.

The figures point to sustained growth rather than a one-off spike. Weekly attacks per organisation have climbed 36% in five months, from 2,055 in May.

UK organisations faced an average of 1,920 attacks per week, a 50% increase year on year. Europe recorded the fastest growth of any region, with attacks up 61%, while Latin America faced the highest volume at 3,813 weekly attacks per organisation, followed by Africa (3,701) and APAC (3,593).

“September’s data shows cyber risk increasing in both volume and breadth,” said Barnaby Nickels, regional manager for exposure management (UKI & North EU) at Check Point.

Education hit hardest as term begins

Education was again the most targeted sector, averaging 6,656 weekly attacks per organisation. That is up 59% year on year and 24% on August, the second-highest monthly rise of any industry, as students, staff and parents reconnected to institutional networks at the start of the academic year. Telecommunications ranked second globally with 3,483 weekly attacks (up 29%), followed by Government with 3,443 (up 37%).

The picture was similar in the UK, where Education and Government were the two most targeted sectors, followed by Media & Entertainment, Energy & Utilities and Software.

The Gentlemen tops ransomware rankings

A total of 824 ransomware attacks were published on double-extortion groups’ leak sites in September, 53% more than in September 2025. The Gentlemen was the most prolific group, responsible for 13% of published attacks, ahead of Qilin (9%) and Akira (5%). A further 80 extortion groups also posted victims during the month.

The Gentlemen is a fast-growing ransomware-as-a-service (RaaS) operation founded in mid-2025. It operates as both a RaaS provider and an initial access broker, and supports Windows, Linux and ESXi environments.

Business Services accounted for 31.3% of reported victims, followed by Consumer Goods & Services (15.2%) and Industrial Manufacturing (11.0%). Because business services providers often hold data or system access on behalf of multiple clients, a single incident can spread well beyond the organisation first hit. North America accounted for 46% of reported incidents, Europe 25% and APAC 17%.

Phishing more frequent, and mostly link-based

One in every 91 emails (1.1%) was classified as phishing in September, up from 1 in 112 (0.89%) in August. Malicious links remained the main delivery method, appearing in 81% of phishing emails, while 11% carried attachments and the rest relied on social engineering alone.

Associations & Nonprofits saw the highest phishing rate at 2.17%, or 1 in 46 emails, roughly double the global average. Construction & Engineering followed at 2.05% (1 in 49) and Real Estate, Rentals & Leasing at 1.38% (1 in 72). North America was the most affected region, with 1 in 79 emails classified as malicious.

GenAI prompts exposing infrastructure details

Enterprise GenAI use continued to expand, with the average user generating 131 prompts in September and each organisation using an average of eight tools. One in every 39 prompts posed a high risk of sensitive data leakage, affecting 89% of organisations that regularly use GenAI. A further 14% of prompts contained potentially sensitive information.

Network and IT infrastructure data was the most commonly exposed category, observed in prompts at 71% of organisations. This includes hardware and network configurations and IP addresses, details that could give attackers valuable insight into an internal environment. It was followed by financial data (70%), legal and regulatory data (68%), employee and HR data (62%) and personally identifiable information (60%).

By industry, Business Services had the highest high-risk prompt rate at 1 in 20, followed by Financial Services (1 in 25) and Healthcare & Medical (1 in 29).

“With attacks rising across every region, phishing becoming more frequent, ransomware remaining elevated and GenAI use expanding alongside sensitive-data exposure, security teams cannot rely on fragmented defences. They need prevention-first protection that combines visibility, control and automation across network, cloud, endpoint, email and AI usage to stop threats before they disrupt operations or expose sensitive information,” concludes Nickels.

The full September 2026 report is available here: https://blog.checkpoint.com/research/september-2026-cyber-threat-landscape-global-attacks-jump-48-as-phishing-and-genai-data-exposure-rise/

ShareTweet
Previous Post

Filigran announces speakers for first THREAD event

Recent News

Global cyber attacks up 48% as ransomware and phishing climb, Check Point finds

Global cyber attacks up 48% as ransomware and phishing climb, Check Point finds

October 8, 2026
Filigran event

Filigran announces speakers for first THREAD event

October 8, 2026
Core to Cloud Appoints David Brown as Managing Director

Core to Cloud Appoints David Brown as Managing Director

October 8, 2026
Marc de Beaucorps, Co-founder and CEO of Finovox

Digital IDs and the AI threat: verification must evolve, not just digitise

October 8, 2026

Eskenzi PR banner ad

The IT Security Guru offers a daily news digest of all the best breaking IT security news stories first thing in the morning! Rather than you having to trawl through all the news feeds to find out what’s cooking, you can quickly get everything you need from this site!

Our Address: 10 London Mews, London, W2 1HY

Follow Us

© 2015 - 2026 IT Security Guru - Website Managed by Dessol

  • About Us
Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}
No Result
View All Result
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us

© 2015 - 2026 IT Security Guru - Website Managed by Dessol