
Ransomware groups publicly claimed 24 Indian victims as global activity hit its highest monthly total of 2026, with little-known regional gangs outpacing global names across the region
India was the most targeted country in Asia-Pacific for ransomware in August 2026, according to The Ransomware Brief published by Cyble Research and Intelligence Labs (CRIL). Ransomware groups publicly claimed two dozen Indian victims out of the region’s 143. Worldwide, claimed victims reached 1,034, the highest monthly total recorded so far this year.
India finished ahead of Thailand (17), Taiwan (16) and Japan (11). Its count was more than double that of the Philippines and China, which tied at 10 each. Nearly one in six claimed victims in Asia-Pacific was an Indian organization.
The report finds that the region’s threat picture differs sharply from the global one. Qilin was the month’s most prolific group worldwide, with 147 claimed victims. Asia-Pacific was the only region where it did not lead. The Gentlemen claimed 20 victims in the region against Qilin’s 16. Two regional specialists, Krybit (13) and orova (12), together claimed more Asia-Pacific victims than Qilin, even though neither ranks in the global top five. CRIL notes that groups like these are routinely under-weighted by global threat models and by vendor coverage built around headline brands.
Globally, 88 ransomware groups were active during the month. The report highlights a campaign by Cl0p affiliates exploiting CVE-2026-12569 in PTC Windchill and FlexPLM, software used by manufacturing and engineering firms. The attackers steal blueprints, CAD files and supply-chain data instead of encrypting systems. That lets them evade endpoint controls designed to spot ransomware behavior, and more than 40 organizations have been publicly named.Â
The report also flags continued exploitation of older, already-patched flaws. These include a two-year-old SonicWall SSL VPN vulnerability (CVE-2024-40766) used by the Akira group and Fortinet FortiOS vulnerabilities used by Gunra affiliates.
“India ranking first in Asia-Pacific is not just a regional league table. It tells us attackers see Indian organizations as worth the effort,” said Daksh Nakra, Senior Manager of Research and Intelligence at Cyble. “What stands out this month is who is doing the attacking and how they get in. Groups that barely register globally are out-claiming the biggest names in this region. Attackers are also walking in through vulnerabilities that were patched two years ago. Indian security teams should plan around the groups actually active here, and close the old doors before chasing the newest threat.”Â




