Ransomware Attacks and Operational Disruptions — July 2026
35
July 2026
Security & Stability
A structured record of 35 confirmed ransomware attacks causing operational disruption to businesses and public sector organisations in July 2026. Each event captures the victim organisation, sector, attack vector where disclosed, the ransomware group claimed or confirmed responsible, and the operational impact. Coverage focuses on attacks with publicly confirmed disruption, not unverified claims or near-misses.
Ransomware attacks on companies causing operational disruption in July 2026
CISOs and enterprise security teams use this data to track active ransomware campaigns and assess their organisation's exposure to the same threat actors. Cyber insurance underwriters monitor attack frequency and severity to inform pricing and coverage decisions. Incident response firms and threat intelligence providers use attack data to brief clients and update detection playbooks.
1719
<div style="overflow-x:auto;width:100%"><table class="catchall-table"><thead><tr><th style="min-width:40px">#</th><th style="min-width:240px">Event</th><th style="min-width:140px;white-space:nowrap">Ransom Demand Amount</th><th style="min-width:140px;white-space:nowrap">Operational Disruption</th><th style="min-width:140px;white-space:nowrap">Recovery Time</th><th style="min-width:140px;white-space:nowrap">Data Exfiltrated</th><th style="min-width:140px;white-space:nowrap">Ransomware Group</th><th style="min-width:140px;white-space:nowrap">Ransom Demand Currency</th><th style="min-width:140px;white-space:nowrap">Location</th><th style="min-width:140px;white-space:nowrap">Systems Affected</th><th style="min-width:140px;white-space:nowrap">Affected Company</th><th style="min-width:140px;white-space:nowrap">Attack Date</th><th style="min-width:120px;white-space:nowrap">Source</th></tr></thead><tbody><tr><td>1</td><td style="min-width:240px">Anubis ransomware attack on Coca-Cola's Fairlife</td><td style="min-width:140px">1</td><td style="min-width:140px">production suspended and temporarily halted at facilities</td><td style="min-width:140px">Majority of production resumed by July 27, full production by July 29</td><td style="min-width:140px">true</td><td style="min-width:140px">Anubis ransomware group</td><td style="min-width:140px">USD</td><td style="min-width:140px">United States</td><td style="min-width:140px">production-linked systems, servers, Nutanix systems</td><td style="min-width:140px">Fairlife</td><td style="min-width:140px">2026-07-16</td><td style="white-space:nowrap"><a href="https://nationalcybersecurity.com/ransomware-group-threatening-to-leak-data-stolen-from-coca-colas-fairlife-hacking-cybersecurity-infosec-comptia-pentest-ransomware" target="_blank" rel="nofollow">https://nationalcybersecurity.com/ransomware-group-threatening-to-leak-data-stolen-from-coca-colas-fairlife-hacking-cybersecurity-infosec-comptia-pentest-ransomware</a></td></tr><tr><td>2</td><td style="min-width:240px">IBM Report on Canadian Data Breach Costs and Operational Disruption</td><td style="min-width:140px">7,110,000</td><td style="min-width:140px">operational downtime creates immediate, catastrophic economic consequences, service disruptions, disruption of services, operational disruptions, longer service interruptions</td><td style="min-width:140px">205 days (almost seven months) to identify and contain</td><td style="min-width:140px">true</td><td style="min-width:140px">ransomware syndicates</td><td style="min-width:140px">CAD</td><td style="min-width:140px">Canada</td><td style="min-width:140px">critical infrastructure sectors like energy, transportation, technology and even retail</td><td style="min-width:140px">Canadian organizations</td><td style="min-width:140px">2026-07-01</td><td style="white-space:nowrap"><a href="https://article.wn.com/view/2026/07/08/Understanding_cyber_resilience_in_the_age_of_internal_threat" target="_blank" rel="nofollow">https://article.wn.com/view/2026/07/08/Understanding_cyber_resilience_in_the_age_of_internal_threat</a></td></tr><tr><td>3</td><td style="min-width:240px">RansomHouse Cyberattack on Nichirei</td><td style="min-width:140px">0</td><td style="min-width:140px">warehouse operations and frozen food shipments disrupted, system outage</td><td style="min-width:140px">within the week</td><td style="min-width:140px">true</td><td style="min-width:140px">RansomHouse</td><td style="min-width:140px"></td><td style="min-width:140px">Japan</td><td style="min-width:140px">warehouse operations, frozen food shipments, systems, victim server</td><td style="min-width:140px">Nichirei</td><td style="min-width:140px">2026-07-21</td><td style="white-space:nowrap"><a href="https://ground.news/article/the-hacker-group-ransomhouse-claims-responsibility-for-the-attack-on-nichirei-they-regularly-use-ransomware" target="_blank" rel="nofollow">https://ground.news/article/the-hacker-group-ransomhouse-claims-responsibility-for-the-attack-on-nichirei-they-regularly-use-ransomware</a></td></tr><tr><td>4</td><td style="min-width:240px">Ransomware attack on Drancy town hall</td><td style="min-width:140px">0</td><td style="min-width:140px">Public services complicated, slowed down, degraded. Online services for rental permits, planning authorizations, and family portal unavailable.</td><td style="min-width:140px">several weeks</td><td style="min-width:140px">true</td><td style="min-width:140px"></td><td style="min-width:140px">BTC</td><td style="min-width:140px">Drancy, Seine-Saint-Denis</td><td style="min-width:140px">municipal systems, IT infrastructure, online services (rental permit, planning authorizations, family portal), and telephone system.</td><td style="min-width:140px">Mairie de Drancy</td><td style="min-width:140px">2026-07-03</td><td style="white-space:nowrap"><a href="https://actulocale365.fr/la-mairie-de-drancy-victime-dune-cyberattaque-les-donnees-des-habitants-probablement-compromises" target="_blank" rel="nofollow">https://actulocale365.fr/la-mairie-de-drancy-victime-dune-cyberattaque-les-donnees-des-habitants-probablement-compromises</a></td></tr><tr><td>5</td><td style="min-width:240px">Ryuk Ransomware Attack Disrupts US Companies with $15M Bitcoin Extortion</td><td style="min-width:140px">15,000,000</td><td style="min-width:140px">disrupted hundreds of corporate systems</td><td style="min-width:140px"></td><td style="min-width:140px">no</td><td style="min-width:140px">Ryuk</td><td style="min-width:140px">USD</td><td style="min-width:140px">United States</td><td style="min-width:140px">hundreds of corporate systems</td><td style="min-width:140px">Michigan firm that paid 200 bitcoin (over $1.1 million) to regain access</td><td style="min-width:140px">2026-07-11</td><td style="white-space:nowrap"><a href="https://pluang.com/en/news-feed/peretas-ransomware-mengaku-bersalah-setelah-skema-ekstorsi-bitcoin-15juta" target="_blank" rel="nofollow">https://pluang.com/en/news-feed/peretas-ransomware-mengaku-bersalah-setelah-skema-ekstorsi-bitcoin-15juta</a></td></tr><tr><td>6</td><td style="min-width:240px">Bank of Baroda Data Leak by Triple X Ransomware</td><td style="min-width:140px">0</td><td style="min-width:140px">Data leak from an employee's email account</td><td style="min-width:140px"></td><td style="min-width:140px">true</td><td style="min-width:140px">Triple X ransomware group</td><td style="min-width:140px"></td><td style="min-width:140px">India</td><td style="min-width:140px">employee's email account</td><td style="min-width:140px">Bank of Baroda</td><td style="min-width:140px">2026-07-24</td><td style="white-space:nowrap"><a href="https://www.bankinfosecurity.com/bank-baroda-breach-tests-disclosure-readiness-a-32335" target="_blank" rel="nofollow">https://www.bankinfosecurity.com/bank-baroda-breach-tests-disclosure-readiness-a-32335</a></td></tr><tr><td>7</td><td style="min-width:240px">University of Alicante Ransomware Attack</td><td style="min-width:140px">0</td><td style="min-width:140px">systems disconnected, certain services deactivated, UACloud, remote access, and electronic administration suspended, legal deadlines suspended, causing inconvenience for exam recovery</td><td style="min-width:140px">seven days for most essential services, full normality expected in coming days</td><td style="min-width:140px">false</td><td style="min-width:140px"></td><td style="min-width:140px"></td><td style="min-width:140px">Alicante</td><td style="min-width:140px">secondary servers, UACloud (intranet), remote access for workers, electronic administration, priority platforms</td><td style="min-width:140px">University of Alicante</td><td style="min-width:140px">2026-07-02</td><td style="white-space:nowrap"><a href="https://www.informacion.es/alicante/2026/07/06/universidad-alicante-descarta-robo-datos-132169514.html" target="_blank" rel="nofollow">https://www.informacion.es/alicante/2026/07/06/universidad-alicante-descarta-robo-datos-132169514.html</a></td></tr><tr><td>8</td><td style="min-width:240px">French Equestrian Federation Cyberattack</td><td style="min-width:140px">0</td><td style="min-width:140px">unauthorized access to data tied to its licensed members, service disruptions, mass access resets or emergency procedure changes.</td><td style="min-width:140px"></td><td style="min-width:140px">true</td><td style="min-width:140px"></td><td style="min-width:140px"></td><td style="min-width:140px">France</td><td style="min-width:140px">member data, account identifiers, contact details and administrative information used to manage licenses, insurance, competition entries and other federation business.</td><td style="min-width:140px">French Equestrian Federation</td><td style="min-width:140px">2026-07-11</td><td style="white-space:nowrap"><a href="https://www.europe-infos.fr/english/9639/french-equestrian-federation-says-member-data-may-have-been-exposed-in-cyberattack-claimed-as-political-message" target="_blank" rel="nofollow">https://www.europe-infos.fr/english/9639/french-equestrian-federation-says-member-data-may-have-been-exposed-in-cyberattack-claimed-as-political-message</a></td></tr><tr><td>9</td><td style="min-width:240px">Qilin Ransomware Attack on Danone</td><td style="min-width:140px">1</td><td style="min-width:140px"></td><td style="min-width:140px"></td><td style="min-width:140px">true</td><td style="min-width:140px">Qilin ransomware gang</td><td style="min-width:140px"></td><td style="min-width:140px">Paris</td><td style="min-width:140px">internal servers</td><td style="min-width:140px">Danone</td><td style="min-width:140px">2026-07-17</td><td style="white-space:nowrap"><a href="https://privacyneedle.com/news/global-food-giant-danone-faces-cyberattack" target="_blank" rel="nofollow">https://privacyneedle.com/news/global-food-giant-danone-faces-cyberattack</a></td></tr><tr><td>10</td><td style="min-width:240px">Sumner County Schools Ransomware Attack Delays School Year</td><td style="min-width:140px">0</td><td style="min-width:140px">delaying the start of the 2026-27 school year and rescheduling student registration</td><td style="min-width:140px"></td><td style="min-width:140px">true</td><td style="min-width:140px"></td><td style="min-width:140px"></td><td style="min-width:140px">Sumner County</td><td style="min-width:140px">network</td><td style="min-width:140px">Sumner County Schools</td><td style="min-width:140px">2026-07-20</td><td style="white-space:nowrap"><a href="https://techora.ru/news/kiberintsident-v-shkolakh-okruga-samner-perenes-2026-07-23" target="_blank" rel="nofollow">https://techora.ru/news/kiberintsident-v-shkolakh-okruga-samner-perenes-2026-07-23</a></td></tr><tr class="row-locked"><td>11</td><td style="min-width:240px">Unitel Cyberattack Disrupts Services in Angola</td><td style="min-width:140px">326,500,000</td><td style="min-width:140px">disrupted voice, mobile data, and internet services nationwide, causing inconvenience to citizens and businesses with obstacles in billing and communications</td><td style="min-width:140px"></td><td style="min-width:140px"></td><td style="min-width:140px"></td><td style="min-width:140px">USD</td><td style="min-width:140px">Luanda, Angola</td><td style="min-width:140px">technology infrastructure, remote access platform, network, Data Center, billing platform</td><td style="min-width:140px">Unitel</td><td style="min-width:140px">2026-07-28</td><td style="white-space:nowrap"><a href="https://rna.ao/rna.ao/2026/07/29/apesar-do-corte-no-sistema-da-unitel-alguns-postos-de-identifficacao-trabalham-com-normalidade" target="_blank" rel="nofollow">https://rna.ao/rna.ao/2026/07/29/apesar-do-corte-no-sistema-da-unitel-alguns-postos-de-identifficacao-trabalham-com-normalidade</a></td></tr><tr class="row-locked"><td>12</td><td style="min-width:240px">Metro Mondego Ransomware Attack and Data Exfiltration</td><td style="min-width:140px">0</td><td style="min-width:140px">Internal systems affected, potential unauthorized access to personal data of passengers, employees, and other entities.</td><td style="min-width:140px"></td><td style="min-width:140px">true</td><td style="min-width:140px"></td><td style="min-width:140px"></td><td style="min-width:140px">Lousã and Coimbra</td><td style="min-width:140px">internal systems</td><td style="min-width:140px">Metro Mondego</td><td style="min-width:140px">2026-07-06</td><td style="white-space:nowrap"><a href="https://sapo.pt/artigo/ransomware-o-que-se-sabe-sobre-o-ataque-a-metro-mondego-e-que-dados-pessoais-podem-estar-em-causa-6a674e33bfcd461eb23740f8" target="_blank" rel="nofollow">https://sapo.pt/artigo/ransomware-o-que-se-sabe-sobre-o-ataque-a-metro-mondego-e-que-dados-pessoais-podem-estar-em-causa-6a674e33bfcd461eb23740f8</a></td></tr></tbody></table></div>
<h3>What evidence is required for an event to be included?</h3><p>An event is recorded when there is confirmed operational disruption attributable to a ransomware attack — such as system outages, service interruptions, or official company/government acknowledgement of an incident.</p><h3>Are suspected attacks without confirmation included?</h3><p>No. Unconfirmed reports or attributions without at least one official acknowledgement from the affected organisation, a regulator, or law enforcement are excluded.</p><h3>Which sectors are most represented?</h3><p>Healthcare, government, financial services, and critical infrastructure tend to generate the most confirmed ransomware disclosures due to mandatory breach reporting requirements in many jurisdictions.</p><h3>How often is this dataset updated?</h3><p>We rerun this dataset once a month. You can create your own dataset that updates as frequently as every one hour on <a href="https://platform.newscatcherapi.com/catchall">platform.newscatcherapi.com/catchall</a></p>