India Tops Asia-Pacific Ransomware Claims in August 2026, Cyble Report Finds

Ransomware groups publicly claimed 24 Indian victims as global activity hit its highest monthly total of 2026, with little-known regional gangs outpacing global names across the region

India was the most targeted country in Asia-Pacific for ransomware in August 2026, according to The Ransomware Brief published by Cyble Research and Intelligence Labs (CRIL). Ransomware groups publicly claimed two dozen Indian victims out of the region’s 143. Worldwide, claimed victims reached 1,034, the highest monthly total recorded so far this year.

India finished ahead of Thailand (17), Taiwan (16) and Japan (11). Its count was more than double that of the Philippines and China, which tied at 10 each. Nearly one in six claimed victims in Asia-Pacific was an Indian organization.

The report finds that the region’s threat picture differs sharply from the global one. Qilin was the month’s most prolific group worldwide, with 147 claimed victims. Asia-Pacific was the only region where it did not lead. The Gentlemen claimed 20 victims in the region against Qilin’s 16. Two regional specialists, Krybit (13) and orova (12), together claimed more Asia-Pacific victims than Qilin, even though neither ranks in the global top five. CRIL notes that groups like these are routinely under-weighted by global threat models and by vendor coverage built around headline brands.

Globally, 88 ransomware groups were active during the month. The report highlights a campaign by Cl0p affiliates exploiting CVE-2026-12569 in PTC Windchill and FlexPLM, software used by manufacturing and engineering firms. The attackers steal blueprints, CAD files and supply-chain data instead of encrypting systems. That lets them evade endpoint controls designed to spot ransomware behavior, and more than 40 organizations have been publicly named. 

The report also flags continued exploitation of older, already-patched flaws. These include a two-year-old SonicWall SSL VPN vulnerability (CVE-2024-40766) used by the Akira group and Fortinet FortiOS vulnerabilities used by Gunra affiliates.

“India ranking first in Asia-Pacific is not just a regional league table. It tells us attackers see Indian organizations as worth the effort,” said Daksh Nakra, Senior Manager of Research and Intelligence at Cyble. “What stands out this month is who is doing the attacking and how they get in. Groups that barely register globally are out-claiming the biggest names in this region. Attackers are also walking in through vulnerabilities that were patched two years ago. Indian security teams should plan around the groups actually active here, and close the old doors before chasing the newest threat.” 

- Advertisement -

Disclaimer: The views expressed in this feature article are of the author. This is not meant to be an advisory to purchase or invest in products, services or solutions of a particular type or, those promoted and sold by a particular company, their legal subsidiary in India or their channel partners. No warranty or any other liability is either expressed or implied.
Reproduction or Copying in part or whole is not permitted unless approved by author.

LEAVE A REPLY

Please enter your comment!
Please enter your name here

Latest Articles

Share your details to download the Research Report 2026

Share your details to download the CISO Handbook 2026

Share your details to download the report 2026

Share your details to download the Cybersecurity Report 2025

Share your details to download the CISO Handbook 2025

Sign Up for CXO Digital Pulse Newsletters

Share your details to download the Research Report

Share your details to download the Coffee Table Book

Share your details to download the Vision 2023 Research Report

Download 8 Key Insights for Manufacturing for 2023 Report

Sign Up for CISO Handbook 2023

Download India’s Cybersecurity Outlook 2023 Report

Unlock Exclusive Insights: Access the article

Download CIO VISION 2024 Report

Share your details to download the report

Share your details to download the CISO Handbook 2024

Fill your details to Watch