- Comparitech Stack Report
- Posts
- Ransomware Roundup: H1 2026 stats on attacks, ransoms, and active gangs
Ransomware Roundup: H1 2026 stats on attacks, ransoms, and active gangs
⚡ Weekend Threat Brief
Medical billing breach puts 300,000 patients at risk
Medical billing company MCBS has disclosed a data breach affecting at least 309,309 people following unauthorized access to its network in September 2025. The exposed information includes names, Social Security numbers, dates of birth, addresses, medical histories, treatment and diagnosis details, health insurance information, and mental and physical health conditions. The ransomware group PEAR claimed responsibility shortly after the incident and alleged it stole 3.3 TB of data, although MCBS has not confirmed the claim. The number of affected individuals is expected to increase as additional states publish breach notifications. MCBS also has not announced free credit monitoring or identity theft protection for those impacted.
Takeaways:
Healthcare billing providers remain attractive targets because they store both medical and financial information.
Organizations should closely monitor third-party vendors that process sensitive patient data.
Breach response plans should include identity protection services and clear communication with affected individuals.
🎯 Tactical Playbook
Japan and the US deepen cyber alliance with focus on critical infrastructure
Japan and the United States used the 11th Japan-U.S. Cyber Dialogue to strengthen cooperation against growing cyber threats. Both governments agreed to expand cyber threat intelligence sharing, improve protection for critical infrastructure, align national cyber strategies, and increase cooperation against cybercrime across the Indo-Pacific. The discussions also covered artificial intelligence, trusted cloud infrastructure, post-quantum cryptography, and coordinated technical assistance for partner nations. The announcement signals that governments are moving beyond policy discussions toward operational collaboration and joint cyber defense.
Key Takeaways:
Organizations operating critical infrastructure should expect greater emphasis on threat intelligence sharing and resilience.
Security teams should begin planning for post-quantum cryptography as governments accelerate adoption efforts.
AI security, cloud security, and cross-border collaboration are becoming central priorities in national cybersecurity strategies.
🛡️ Research Watch
Ransomware Roundup: H1 2026 stats on attacks, ransoms, and active gangs
Comparitech's latest ransomware research recorded 4,217 ransomware attacks during the first half of 2026, averaging 23 attacks every day. That represents an 11 percent increase compared to the second half of 2025. The data also shows that ransomware groups continue to expand their operations while targeting organizations across healthcare, government, manufacturing, education, and other sectors. The report highlights that ransomware remains one of the most active cyber threats facing organizations worldwide.
🧩 Tool Tip of the Week
Use ManageEngine OpManager to validate network paths after an outage
After restoring a failed router, firewall, or WAN link, do not assume traffic is following the expected path. Use ManageEngine OpManager alongside traceroute to verify that packets are taking the correct route. Comparing traceroute results before and after a network change helps identify routing loops, unexpected hops, or latency introduced by configuration errors. Keeping baseline traceroute records also makes future troubleshooting much faster.
🗣️ Community Signal
The Surprising Challenge in Cyber: It's Not Just About Technical Skills! Technical knowledge is essential, but it's only part of what makes a successful cybersecurity professional. Communication, collaboration, and other soft skills are just as important for building a successful career in cybersecurity. - Mark Voorhies
🗳️ Your Take - The Results

|
Until Monday’s edition - Let’s keep that zero-day count at zero!