GUEST RESEARCH: Check Point Research reveals a 22% year-on-year increase in global cyber attacks, a rise in phishing activity, and continued sensitive data exposure risks as enterprise GenAI use expands
Check Point Research, the threat intelligence arm of Check Point® Software Technologies Ltd., today released its Global Threat Intelligence insights for August 2026, revealing that organisations worldwide experienced an average of 2,422 cyber attacks per week, representing a 4% increase month on month and a 22% increase year on year. The findings point to a broad escalation in cyber risk, with attack volumes continuing their upward trend over the summer while ransomware, phishing and GenAI-related data exposure remained key enterprise security challenges. Together, these trends underline the need for a prevention-first security strategy that gives organisations consistent visibility and control across users, email, networks, cloud environments and AI tools.
“August’s data shows cyber risk expanding across several fronts at once,” said Omer Dembinsky, Data Research Manager at Check Point Research. “With attacks climbing, ransomware accelerating, phishing remaining a common entry point and GenAI creating a new route for data exposure, security teams cannot rely on fragmented defences. They need prevention-first protection that combines visibility, control and automation across network, cloud, endpoint, email and AI usage to stop threats before they disrupt operations or expose sensitive information.”
Education Faces the Highest Attack Volumes While Hospitality and Travel See a Summer Surge
Education remained the most targeted sector globally, with 5,354 weekly attacks per organisation, up 28% year on year. Government followed with 3,067 weekly attacks, while Hospitality, Travel and Recreation rose to third place with 3,056 weekly attacks, up 56%. This pattern reflects how attackers continue to focus on environments with large user bases, multiple access points and valuable data flows, where disruption can have an immediate operational impact.
Latin America Tops Regional Attack Volumes as Europe Posts the Fastest Growth
Latin America remained the most attacked region, with 3,577 weekly attacks per organisation, up 25% year on year. Europe recorded the fastest growth, rising 28% year on year, while Africa reached 3,335 weekly attacks and APAC 3,325. The increase in Europe shows that cyber pressure is not limited to traditionally high-volume regions but is spreading across mature digital economies where organisations operate complex, interconnected environments.
GenAI Adoption Accelerates, Keeping Sensitive Data Exposure on the Security Agenda
GenAI-related risk remained part of everyday business operations in August. High-risk GenAI prompts fell to their lowest level in several months, with one in every 43 prompts from enterprise networks posing a data exposure risk. At the same time, overall usage continued to climb, with the average user generating 106 prompts during the month, up from 95 in July and around 78 in June. The contrast suggests that while some organisations may be improving awareness or controls, the rapid expansion of GenAI use continues to increase the number of moments where sensitive information could be entered into tools without adequate governance.
The issue remained widespread: 86% of organisations using GenAI regularly were affected by high-risk prompt activity, while organizations used an average of seven different AI tools. This highlights a growing governance challenge, as the security risk is not only the use of GenAI itself, but the lack of visibility into what data is being shared, where it is going and whether it can be protected before exposure occurs.
Advertisement
Healthcare and Medical recorded the highest high-risk GenAI prompt exposure rate at 4%, followed by Software at 3.6% and Business Services at 3.5%. Latin America recorded the highest regional rate at 3.5%, above the global average of 2.3%. These differences point to the need for sector-specific AI governance, particularly in data-rich industries where employees may be more likely to handle sensitive, regulated or proprietary information.
Phishing Activity Rises as Malicious Links Dominate Email-Based Threats
Email remained a key attack vector, with one in every 112 emails classified as phishing, compared with one in every 128 in July. Links appeared in 72% of phishing emails, while 14% contained attachments. The continued dominance of links reflects how easy it is for attackers to scale social engineering campaigns, quickly adapt lures to current events or business processes, and direct users to credential harvesting or malware delivery sites. By industry, Associations and Nonprofits saw the highest rate at 1.87%, followed by Construction and Engineering at 1.74%. These sectors often depend on frequent external communications, donations, tenders, partners or suppliers, which can make it harder for users to distinguish between legitimate and malicious outreach.
Ransomware Victim Numbers Surge, with Business Services Bearing the Brunt
Ransomware activity continued to accelerate in August. A total of 1,042 ransomware attacks were reported, almost double the level recorded in August 2025 and 8% higher than in July. Business Services remained the most targeted industry, accounting for 36% of reported ransomware attacks, followed by Industrial Manufacturing at 13% and Consumer Goods and Services at 12%. The concentration in Business Services suggests attackers are continuing to prioritise organisations that sit at the centre of wider supply chains and can create broader downstream disruption.
Ransomware Landscape Shifts as Qilin Leads and Orova Breaks into the Top Three
Qilin was the most active ransomware group in August, responsible for 15% of published attacks, followed by The Gentlemen with 10%. Orova entered the top three for the first time, accounting for 4%. The movement among leading ransomware groups illustrates how the threat landscape remains fluid, with established actors maintaining pressure while newer or previously less visible groups can quickly gain prominence.
For enterprises, the August threat landscape reinforces the importance of moving from reactive detection to proactive prevention, supported by unified security controls that can reduce complexity while helping teams identify and block threats across increasingly distributed digital environments.
For more insights into August 2026 cyber threat trends, visit the Check Point Research Blog
Advertisement
Click Here For The Original Source.
