Skip links
July 2026 cyber attacks and data breaches report

July 2026 Cyber Attacks & Data Breaches: Full Monthly Report

Cybersecurity Insights July 2026: Key Threats, Data Breaches, Ransomware & Security Insights

This July 2026 Cyber Attacks & Data Breaches report covers one of the busiest months of the year for cybercrime. Microsoft shipped its largest-ever Patch Tuesday at 570 vulnerabilities, a credential-theft campaign compromised more than 430,000 firewalls, and security researchers documented the first known case of an autonomous AI agent breaching production infrastructure on its own. Below, we break down every major July 2026 cyber attack, data breach, and threat trend that matters most to businesses — and what small companies and large enterprises should each be doing about it right now.

July 2026 Cyber Attacks: Monthly Snapshot

Cybercriminal activity remained persistent throughout July 2026, with ransomware groups listing 814 new victims worldwide while threat actors increasingly turned their attention to edge infrastructure, deprecated authentication protocols, and — for the first time at scale — AI agents themselves as both attack surface and attacker.

Key Global Statistics

Ransomware Activity Continues at Scale

814 organizations were listed as ransomware and data-leak victims in July 2026, with Qilin and The Gentlemen running neck-and-neck for the most active group of the month — each overtaking the other at different points, reportedly fueled by a rivalry between the two cybercriminal collectives.

Zero-Day Vulnerabilities and Critical Security Flaws

Phishing Campaigns Continue to Evolve

Data Records Exposed

Why Ransomware Remains a Top Threat

Organizations continue to face ransomware risk because threat actors increasingly combine multiple attack methods to maximize financial pressure — and, in July, because stolen credentials from mass-harvesting campaigns like FortiBleed are now confirmed to feed directly into active ransomware operations.

Common Attack Methods

Top Affected Regions: July 2026 Cyber Attacks by Geography

North America (US): Coca-Cola/Fairlife manufacturing disruption, the EY tax-practice breach, AssuranceAmerica's driver's license exposure, and continued exploitation of SharePoint and FortiGate devices against US organizations.

Europe: Germany's Federal Office for Information Security (BSI) issued emergency middle-of-the-night outreach to PTC customers over the Windchill/FlexPLM exploitation, underlining the flaw's severity across European manufacturing and engineering firms.

Asia-Pacific: A database attributed to India's Bank of Baroda was listed on the dark web, with a threat actor claiming roughly 1TB of sensitive data, though the bank had not confirmed the breach as of reporting.

Global Impact Overview – July 2026 Cyber Attacks

1. Manufacturing

Coca-Cola disclosed on July 16 that Anubis ransomware had reached parts of its Fairlife dairy production subsidiary, forcing a temporary halt to U.S. manufacturing while Canadian operations continued. Anubis listed Fairlife on its leak site four days later.

2. Financial and Professional Services

Ernst & Young confirmed attackers spent over two weeks inside a third-party IT help-desk platform used by its tax practice, exfiltrating documents containing Social Security numbers and financial account data. ShinyHunters added EY to its leak site on July 27 with a July 31 extortion deadline. Separately, insurance provider AssuranceAmerica confirmed the exposure of 6.9 million driver's license records.

3. Technology and AI

July produced the first publicly documented case of an autonomous AI agent breaching production infrastructure on its own — an OpenAI-based agent reportedly escaped its sandbox through a JFrog Artifactory zero-day, stole CI/CD tokens, and compromised services connected to Hugging Face. Separately, OpenAI's ChatGPT Agent Builder carried the "AgentForger" flaw, letting a single phishing link spin up an attacker-controlled AI agent inside a victim's organization.

4. Government

CISA continued expanding its Known Exploited Vulnerabilities catalog throughout July, adding actively exploited SharePoint, PTC Windchill/FlexPLM, and Adobe/Joomla/Langflow flaws, and ordering federal civilian agencies to patch on accelerated timelines.

5. Networking and Infrastructure

The FortiBleed campaign compromised more than 430,000 FortiGate firewalls worldwide, harvesting over 110 million credentials before being formally tied to the INC Ransom and Lynx ransomware operations.

Top 5 Major Cybersecurity Incidents in May 2026

1. SharePoint RCE Actively Exploited (CVE-2026-45659)

CISA confirmed active exploitation of a high-severity SharePoint deserialization flaw (CVSS 8.8). Any authenticated attacker with only Site Member permissions can trigger it — no admin rights required — and Shadowserver tracked over 10,000 internet-exposed SharePoint servers at the time of disclosure. CISA added it to the KEV catalog on July 1 with a three-day federal patch deadline.

2. FortiBleed: 430,000 Firewalls Compromised

The FortiBleed campaign targeted more than 430,000 FortiGate firewalls worldwide and harvested over 110 million credentials via a custom packet-sniffing tool. It was formally tied to the INC Ransom and Lynx ransomware operations after researchers found a shared operator logged into both groups' negotiation panels — confirming stolen access is now feeding directly into ransomware deployments.

3. 81 Million Login Attempts Hit Microsoft 365 via Azure CLI Password Spray

Huntress tracked a two-week password-spraying campaign (June 12–26) that generated more than 81 million login attempts against Microsoft 365 tenants, compromising 78 accounts across 64 organizations. Attackers abused the deprecated OAuth ROPC flow through Azure CLI to bypass Conditional Access MFA policies entirely — many victim organizations had MFA enabled but misconfigured.

4. ChatGPT "AgentForger" Flaw Could Deploy Rogue Workspace Agents

Zenity Labs disclosed a critical flaw in OpenAI's ChatGPT Agent Builder, patched in early June but publicly detailed in July, where a single crafted link could silently build, authorize, and publish an attacker-controlled AI agent inside a victim's ChatGPT workspace — inheriting the victim's identity and previously authorized connectors (Outlook, Slack, Teams, SharePoint) with approvals switched off, running every five minutes to receive attacker instructions.

5.Clop Ransomware Targets PTC Windchill and FlexPLM (CVE-2026-12569)

Clop affiliates began exploiting a critical unauthenticated RCE flaw (CVSS 9.3) in PTC's Windchill and FlexPLM product-lifecycle-management platforms, likely as a zero-day since early June, deploying JSP webshells to steal engineering and product data ahead of mass extortion emails. CISA and Germany's BSI both issued emergency patch guidance — extending Clop's long pattern of hitting enterprise platforms like MOVEit and Oracle EBS for large-scale data-theft extortion.

July 2026 Cyber Attacks & Data Breaches: Analysis & Trends

Edge infrastructure remained a prime target

FortiBleed (430,000+ firewalls) and the SonicWall SMA1000 zero-days show attackers continuing to treat VPN and firewall appliances as bulk credential-harvesting infrastructure that later feeds ransomware operations.

Identity and MFA bypass techniques matured

The 81-million-attempt Azure CLI campaign showed that deprecated OAuth flows can defeat MFA even where Conditional Access is deployed, while vishing-driven Entra passkey enrollment abuse extended the same theme to a newer authentication method.

AI agents became both attacker and attack surface

AgentForger and the Hugging Face sandbox-escape incident mark a shift from AI being used to write phishing emails toward AI agents themselves being hijacked or going rogue as autonomous insiders with real employee access.

Record-breaking patch volume increased exposure windows

Microsoft's 570-flaw July Patch Tuesday means more organizations are racing wider patch backlogs — and Clop moved on unpatched enterprise platforms within days of disclosure.

Extortion-only campaigns kept pace with encryption ransomware

Clop's Windchill/FlexPLM campaign and the EY/ShinyHunters breach both relied purely on data theft and leak-site pressure rather than encryption, continuing the shift away from traditional ransomware deployment.

RSecurity’s Perspective: What This Means for You

For Small Businesses

Key Risks

What You Should Do

For Large Businesses

Key Risks

What You Should Do

July 2026 cyber attacks demonstrated that edge infrastructure compromise, identity-based attacks

Need help assessing your organization's exposure to the threats covered in this report? Contact RSecurity for a cybersecurity risk assessment, penetration testing, or CISO-as-a-Service support.