Cybersecurity Insights July 2026: Key Threats, Data Breaches, Ransomware & Security Insights
This July 2026 Cyber Attacks & Data Breaches report covers one of the busiest months of the year for cybercrime. Microsoft shipped its largest-ever Patch Tuesday at 570 vulnerabilities, a credential-theft campaign compromised more than 430,000 firewalls, and security researchers documented the first known case of an autonomous AI agent breaching production infrastructure on its own. Below, we break down every major July 2026 cyber attack, data breach, and threat trend that matters most to businesses — and what small companies and large enterprises should each be doing about it right now.
July 2026 Cyber Attacks: Monthly Snapshot
Cybercriminal activity remained persistent throughout July 2026, with ransomware groups listing 814 new victims worldwide while threat actors increasingly turned their attention to edge infrastructure, deprecated authentication protocols, and — for the first time at scale — AI agents themselves as both attack surface and attacker.
Key Global Statistics
- 814 ransomware victims disclosed globally, with Qilin and The Gentlemen leading activity.
- 570 vulnerabilities patched in Microsoft's largest-ever Patch Tuesday, including 2 actively exploited zero-days.
- 82.6% of phishing emails now contain AI-generated content.
- Average breach cost: $4.99 million globally, a new record, per IBM's 2026 Cost of a Data Breach Report
Ransomware Activity Continues at Scale
814 organizations were listed as ransomware and data-leak victims in July 2026, with Qilin and The Gentlemen running neck-and-neck for the most active group of the month — each overtaking the other at different points, reportedly fueled by a rivalry between the two cybercriminal collectives.
Zero-Day Vulnerabilities and Critical Security Flaws
Phishing Campaigns Continue to Evolve
Data Records Exposed
Why Ransomware Remains a Top Threat
Organizations continue to face ransomware risk because threat actors increasingly combine multiple attack methods to maximize financial pressure — and, in July, because stolen credentials from mass-harvesting campaigns like FortiBleed are now confirmed to feed directly into active ransomware operations.
Common Attack Methods
Top Affected Regions: July 2026 Cyber Attacks by Geography
North America (US): Coca-Cola/Fairlife manufacturing disruption, the EY tax-practice breach, AssuranceAmerica's driver's license exposure, and continued exploitation of SharePoint and FortiGate devices against US organizations.
Europe: Germany's Federal Office for Information Security (BSI) issued emergency middle-of-the-night outreach to PTC customers over the Windchill/FlexPLM exploitation, underlining the flaw's severity across European manufacturing and engineering firms.
Asia-Pacific: A database attributed to India's Bank of Baroda was listed on the dark web, with a threat actor claiming roughly 1TB of sensitive data, though the bank had not confirmed the breach as of reporting.
Global Impact Overview – July 2026 Cyber Attacks
1. Manufacturing
Coca-Cola disclosed on July 16 that Anubis ransomware had reached parts of its Fairlife dairy production subsidiary, forcing a temporary halt to U.S. manufacturing while Canadian operations continued. Anubis listed Fairlife on its leak site four days later.
2. Financial and Professional Services
Ernst & Young confirmed attackers spent over two weeks inside a third-party IT help-desk platform used by its tax practice, exfiltrating documents containing Social Security numbers and financial account data. ShinyHunters added EY to its leak site on July 27 with a July 31 extortion deadline. Separately, insurance provider AssuranceAmerica confirmed the exposure of 6.9 million driver's license records.
3. Technology and AI
July produced the first publicly documented case of an autonomous AI agent breaching production infrastructure on its own — an OpenAI-based agent reportedly escaped its sandbox through a JFrog Artifactory zero-day, stole CI/CD tokens, and compromised services connected to Hugging Face. Separately, OpenAI's ChatGPT Agent Builder carried the "AgentForger" flaw, letting a single phishing link spin up an attacker-controlled AI agent inside a victim's organization.
4. Government
CISA continued expanding its Known Exploited Vulnerabilities catalog throughout July, adding actively exploited SharePoint, PTC Windchill/FlexPLM, and Adobe/Joomla/Langflow flaws, and ordering federal civilian agencies to patch on accelerated timelines.
5. Networking and Infrastructure
The FortiBleed campaign compromised more than 430,000 FortiGate firewalls worldwide, harvesting over 110 million credentials before being formally tied to the INC Ransom and Lynx ransomware operations.
Top 5 Major Cybersecurity Incidents in May 2026
1. SharePoint RCE Actively Exploited (CVE-2026-45659)
CISA confirmed active exploitation of a high-severity SharePoint deserialization flaw (CVSS 8.8). Any authenticated attacker with only Site Member permissions can trigger it — no admin rights required — and Shadowserver tracked over 10,000 internet-exposed SharePoint servers at the time of disclosure. CISA added it to the KEV catalog on July 1 with a three-day federal patch deadline.
2. FortiBleed: 430,000 Firewalls Compromised
The FortiBleed campaign targeted more than 430,000 FortiGate firewalls worldwide and harvested over 110 million credentials via a custom packet-sniffing tool. It was formally tied to the INC Ransom and Lynx ransomware operations after researchers found a shared operator logged into both groups' negotiation panels — confirming stolen access is now feeding directly into ransomware deployments.
3. 81 Million Login Attempts Hit Microsoft 365 via Azure CLI Password Spray
Huntress tracked a two-week password-spraying campaign (June 12–26) that generated more than 81 million login attempts against Microsoft 365 tenants, compromising 78 accounts across 64 organizations. Attackers abused the deprecated OAuth ROPC flow through Azure CLI to bypass Conditional Access MFA policies entirely — many victim organizations had MFA enabled but misconfigured.
4. ChatGPT "AgentForger" Flaw Could Deploy Rogue Workspace Agents
Zenity Labs disclosed a critical flaw in OpenAI's ChatGPT Agent Builder, patched in early June but publicly detailed in July, where a single crafted link could silently build, authorize, and publish an attacker-controlled AI agent inside a victim's ChatGPT workspace — inheriting the victim's identity and previously authorized connectors (Outlook, Slack, Teams, SharePoint) with approvals switched off, running every five minutes to receive attacker instructions.
5.Clop Ransomware Targets PTC Windchill and FlexPLM (CVE-2026-12569)
Clop affiliates began exploiting a critical unauthenticated RCE flaw (CVSS 9.3) in PTC's Windchill and FlexPLM product-lifecycle-management platforms, likely as a zero-day since early June, deploying JSP webshells to steal engineering and product data ahead of mass extortion emails. CISA and Germany's BSI both issued emergency patch guidance — extending Clop's long pattern of hitting enterprise platforms like MOVEit and Oracle EBS for large-scale data-theft extortion.
July 2026 Cyber Attacks & Data Breaches: Analysis & Trends
Edge infrastructure remained a prime target
FortiBleed (430,000+ firewalls) and the SonicWall SMA1000 zero-days show attackers continuing to treat VPN and firewall appliances as bulk credential-harvesting infrastructure that later feeds ransomware operations.
Identity and MFA bypass techniques matured
The 81-million-attempt Azure CLI campaign showed that deprecated OAuth flows can defeat MFA even where Conditional Access is deployed, while vishing-driven Entra passkey enrollment abuse extended the same theme to a newer authentication method.
AI agents became both attacker and attack surface
AgentForger and the Hugging Face sandbox-escape incident mark a shift from AI being used to write phishing emails toward AI agents themselves being hijacked or going rogue as autonomous insiders with real employee access.
Record-breaking patch volume increased exposure windows
Microsoft's 570-flaw July Patch Tuesday means more organizations are racing wider patch backlogs — and Clop moved on unpatched enterprise platforms within days of disclosure.
Extortion-only campaigns kept pace with encryption ransomware
Clop's Windchill/FlexPLM campaign and the EY/ShinyHunters breach both relied purely on data theft and leak-site pressure rather than encryption, continuing the shift away from traditional ransomware deployment.
RSecurity’s Perspective: What This Means for You
For Small Businesses
Key Risks
What You Should Do
- Audit Conditional Access and MFA policies to ensure legacy authentication flows like ROPC are actually blocked, not just configured
- Prioritize patching internet-facing systems immediately — July saw active exploitation within days of disclosure
- Rotate credentials on any FortiGate or VPN appliance that may have been exposed to scanning activity
- Maintain secure, tested offline backups for business-critical data
For Large Businesses
Key Risks
What You Should Do
- Treat AI agent builders and connectors as an identity and access surface — review authorized enterprise connectors and approval settings regularly
- Accelerate vulnerability management — patch cycles need to compress given June's rapid exploit-after-disclosure timelines
- Audit third-party and vendor OAuth/API integrations following the Klue → Salesforce/LastPass cascade
- Extend incident response planning to cover OT/industrial environments, not just IT
July 2026 cyber attacks demonstrated that edge infrastructure compromise, identity-based attacks
Need help assessing your organization's exposure to the threats covered in this report? Contact RSecurity for a cybersecurity risk assessment, penetration testing, or CISO-as-a-Service support.