What happened
Comparitech's tracking shows ransomware attacks hit a record 997 globally in August 2026. Attacks on businesses specifically climbed from 692 in July to 861 in August — a 24% jump in a single month.
The sector detail is striking: healthcare attacks rose 30% (from 53 to 69), attacks on utility companies doubled (from 5 to 10), and law firms (+52%), tech companies (+42%) and finance companies (+40%) all saw significant increases. Education and food & beverage were the only sectors to decline.
Why it matters to your business
Ransomware volume at record levels matters because the attack economics increasingly favour smaller targets. Professional services, legal practices and finance firms — the exact profile of most South African SMEs — saw some of the sharpest increases. Attackers know these businesses hold valuable data and often lack dedicated security staff.
The doubling of attacks on utilities is also a warning about operational disruption: attackers are comfortable targeting systems that businesses physically depend on. When your line-of-business server is encrypted, the question is no longer whether you have security — it's whether you can be back up within hours.
What you should do
Assume breach, plan recovery. Immutable, off-site backups that ransomware cannot encrypt are the single most effective control.
Patch relentlessly. Ransomware groups like Medusa monitor vulnerability announcements and target organisations that haven't patched — patch management closes that window.
Watch remote access. The August wave included attackers exploiting remote-management tools — VPNs and RMM software need MFA and strict access control.
Test your recovery quarterly. A backup you've never restored is a hope, not a plan. Server Backup bundles include quarterly disaster-recovery testing for exactly this reason.
Source: Industrial Cyber / Comparitech