
African organisations averaged 3 237 cyber attacks per week in July,
against a global average of 2,336, while ransomware victims surged 87%
and GenAI data exposure became an everyday enterprise risk
Johannesburg, SA – August 13, 2026 – Check Point Research, the
threat intelligence arm of Check Point® Software Technologies Ltd.,
today released its Global Threat Intelligence insights for July 2026,
revealing that organisations worldwide experienced an average of 2,336
cyber attacks per week, representing a 3% increase month on month and a
16% increase year on year.
African organisations recorded 3,237 attacks per week, topped by Latin
America at 3,561 weekly attacks per organisation, and APAC at 3,316. In
the region, Angola was particularly hard hit with 5,714 weekly attacks
per organisation, followed by Nigeria at 4,975, Kenya at 2,915 and South Africa at 2,195.
July’s cyber threat landscape was shaped by pressure across multiple
fronts. Financial Services, Government and Energy & Utility sectors
continued to take a pummeling, being the top three most attacked
industries on the continent.
Global attack volumes continued to climb, ransomware activity broke from
the more stable pattern seen earlier in the year, and GenAI exposure
became a clearer operational risk as employees used more tools and
generated more prompts across the enterprise
“July’s data shows that cyber risk is accumulating across multiple
fronts at once,” said Lorna Hardie, Regional Director: Africa at Check
Point Research. “Attack volumes continue to rise, ransomware has
accelerated sharply, and GenAI exposure is now part of daily business
activity. Organisations need prevention-first, AI-driven security that
protects networks, users, data and AI workflows before attacks can cause
impact.”
Education Remains the Most Targeted Industry as Energy and Hospitality Rise
In July, Education remained the most targeted sector globally, averaging
4,848 weekly attacks per organisation, up 14% year on year. Government
followed with 3,044 attacks, Telecommunications with 2,927, while Energy
and Utilities rose 20% to 2,759 and Hospitality, Travel and Recreation
entered the top five with 2,614 attacks, up 28%.
GenAI Risk Moves from Theory to Daily Business Reality
GenAI-related exposure became a daily business issue in July: one in
every 36 enterprise prompts carried a high risk of sensitive data
leakage, 88% of regular GenAI-using organisations were affected by
high-risk prompt activity, and 22% of prompts contained potentially
sensitive information.
Organisations used an average of eight GenAI tools, with users
generating 95 prompts on average. Personal data was the most common
sensitive category exposed, appearing in 70% of organisations, followed
by financial data and network and IT infrastructure at 68% each.
Email Remains a Key Entry Point for Cyber Risk
Email also remained a high-volume risk channel: one in every 128 emails,
or 0.78%, was classified as phishing, while a further 20% fell into
unwanted or risky categories such as graymail, spam and suspicious
messages. Africa recorded the highest phishing rate, at one in every 106
emails, followed by North America at one in every 117, reinforcing
email’s role as a common starting point for credential theft, malware
delivery and business email compromise.
Ransomware Breaks the Pattern as Reported Victims Surge
The clearest shift in July came from ransomware. Reported attacks
reached 964, up 49% from June and 87% compared with July 2025. This
marked a decisive break from the first half of 2026, when monthly
ransomware activity averaged around 672 incidents. Business Services
remained the most affected sector, accounting for 32.5% of reported
victims, followed by Industrial Manufacturing at 14.4% and Consumer
Goods and Services at 13.4%.
North America remained the most affected region, accounting for 45% of
reported ransomware incidents. Europe followed at 28%, while APAC
accounted for 17%. At country level, the United States continued to
dominate the victim count with 39.4% of reported attacks, followed by
Germany, Canada, the United Kingdom and Italy.
The Gentlemen and Qilin Lead as the Ransomware Landscape Shifts
The Gentlemen and Qilin were the most prevalent ransomware groups in
July, each responsible for 14% of published attacks. DeadLock ranked
third with 10% and 97 reported victims, highlighting continued shifts in
the ransomware ecosystem.
For more insights into July 2026 cyber threat trends, visit the Check
Point Research Blog. [1]
About Check Point Software Technologies
Check Point Software Technologies Ltd. [7] is a global cyber security
leader protecting more than 100,000 organisations worldwide. Its mission
is to secure enterprises’ AI transformation. With a prevention-first
approach and an open ecosystem architecture, Check Point helps
organisations block advanced threats, prioritise exposures, and automate
security operations across complex digital environments. The unified
architecture simplifies protection across hybrid networks, multi-cloud
environments, digital workspaces, and AI systems. Structured around four
strategic pillars, Hybrid Mesh Network Security, Workspace Security,
Exposure Management, and AI Security, Check Point delivers consistent
protection and visibility across multivendor environments, enabling
organisations to reduce risk, improve efficiency, and accelerate
innovation without increasing complexity.





