NCC Group observed a record 502 ransomware attacks in July, up from 198 in July 2022, and tied the Cl0p ransomware-as-a-service gang to 171 attacks in July 2023
Context & Ripple Effects
NCC Group had already recorded a March peak of 459 attacks, a jump it associated with exploitation of Fortra’s GoAnywhere MFT. July’s 502 count extends that pattern rather than looking like an isolated spike.
The attribution of 171 July incidents to Cl0p gives the overall increase a clear concentration point: a ransomware-as-a-service operator was tied to a substantial share of the observed activity.
First-order effects
- Organizations and defenders faced a markedly higher observed ransomware volume than a year earlier, while Cl0p became the most prominent named contributor in this dataset.
- The July tally makes Cl0p’s activity a priority for incident-response and threat-monitoring teams assessing their immediate exposure.
Second-order effects
- A surge concentrated around a named ransomware-as-a-service group raises the value of tracking the access routes and exploitation patterns associated with that group, rather than treating ransomware as a uniform risk.
- The increased attack tempo is consistent with the pressure later reflected in higher reported victim losses and ransom demands, increasing the financial stakes for affected organizations and their insurers.
Third-order effects
- If repeated monthly peaks persist, ransomware risk will be shaped increasingly by scalable criminal-service ecosystems and concentrated operators, not only by isolated attacks.
- The broader pattern points toward ransomware becoming a more persistent operational and financial risk; later reporting of record 2023 ransomware payments suggests that higher activity can translate into systemic economic impact.
The trend: Ransomware is becoming a higher-volume, service-driven threat in which a small number of operators can account for a meaningful share of observed attacks.