In July 2026, UK organisations experienced a staggering average of 1,597 cyber attacks per week for each entity, marking a significant 26% increase compared to the previous year. This alarming statistic was revealed in recent research published by Check Point Research, a branch dedicated to threat intelligence under Check Point Software Technologies. While the rise in attacks within the UK is notable, it is essential to highlight that the weekly attack volume remains below the global average of 2,336 attacks faced by organisations worldwide.
This troubling trend is part of Check Point Research’s Global Threat Intelligence report for July 2026, which underscores a growing concern in the realm of cybersecurity. The report indicates a multifaceted escalation of cyber risks that encompass heightened attack volumes, a marked acceleration in ransomware incidents, and an increase in data exposure resulting from the widespread adoption of generative AI tools in enterprise environments.
Specifically, five key sectors emerged as prime targets for cybercriminals within the UK during July: Education, Energy & Utilities, Software, Government, and Media & Entertainment. This targeting reflects a strategic focus by attackers on industries that handle sensitive personal data, maintain critical national infrastructure, or present expansive and diverse attack surfaces. As the threat landscape evolves, these sectors must fortify their defenses to protect against potential breaches.
On a global scale, the frequency of cyber attacks continues to rise. In July, organisations worldwide encountered an average of 2,336 cyber attacks per week, which represents a 3% month-on-month increase and a 16% year-on-year increase. The Education sector retained its position as the primary target globally, averaging 4,848 attacks per organisation—a 14% rise from the prior year. Following Education, the Government sector witnessed 3,044 attacks, with Telecommunications close behind at 2,927 weekly attacks. The Energy and Utilities sector also reported a significant uptick in incidents, showcasing a 20% increase to 2,759 attacks. Notably, the Hospitality, Travel, and Recreation industries entered the global top five with 2,614 attacks, likely influenced by heightened activity during the summer travel season.
Regionally, Latin America was noted for having the highest volume of attacks, with an average of 3,561 weekly attacks per organisation—a substantial 19% increase year-on-year. The Asia-Pacific (APAC) region followed closely behind, experiencing 3,316 attacks, while Europe reported an impressive 18% year-on-year growth in attack frequency to 2,051 attacks per organisation. North America, in contrast, showed a more modest increase of 9%, bringing its average to 1,613 weekly attacks.
One of the most significant developments in July was the extraordinary rise in ransomware incidents. The number of reported victims surged to 964 globally, reflecting an 87% increase year-on-year and a 49% rise from the previous month. This marked a notable departure from the first half of 2026, where the monthly average for ransomware incidents hovered around 672. Among the sectors most severely affected, Business Services accounted for 32.5% of the reported victims, followed by Industrial Manufacturing at 14.4% and Consumer Goods and Services at 13.4%.
In terms of regional impacts, North America remained the epicenter for ransomware, accounting for 45% of reported incidents. Europe followed at 28%, with the APAC region contributing 17%. At the national level, the United States led the pack with 39.4% of reported ransomware attacks, followed by Germany, Canada, the United Kingdom, and Italy.
Two prominent ransomware groups, the Gentlemen and Qilin, were responsible for the majority of attacks in July, each contributing to 14% of all reported incidents. Following closely behind was the DeadLock group, which captured 10% of the attention with 97 reported victims, demonstrating the ongoing volatility within the ransomware landscape.
The report from Check Point also highlighted a significant risk associated with generative AI tools. It revealed that one out of every 36 prompts issued from enterprise networks carried a high risk of exposing sensitive data. Alarmingly, 88% of organisations that frequently employed generative AI reported high-risk interactions during the month of July. On average, organisations utilized eight generative AI tools, with individual users generating approximately 95 prompts.
In terms of sensitive data, personal information was the most commonly exposed category, surfacing in 70% of the organisations surveyed. Financial data and network and IT infrastructure details followed closely behind, each appearing in 68% of the organisations.
Email continued to serve as a major risk vector, with one in every 128 emails—approximately 0.78%—classified as phishing in July. Additionally, another 20% of emails fell into categories considered unwanted or risky, such as graymail, spam, and suspicious messages.
Barnaby Nickels, the regional sales manager for UKI and North EU at Check Point Software, highlighted the urgency of the situation by stating, “July’s data shows that cyber risk is accumulating across multiple fronts at once.” He emphasised that as attack volumes continue to rise, organisations must adopt a prevention-first, AI-driven approach to security. This means taking proactive measures to safeguard networks, users, data, and AI operations before any attacks can inflict damage.
For organisations within the UK, the rising threat landscape serves as a crucial reminder to bolster their security measures across various layers, including network, cloud, endpoint, email, and AI use, rather than relying on any single point of defense. As front-line defenders, security teams must remain vigilant and adaptive to effectively counter the ongoing and evolving challenge of cyber threats.

