Global Cyber Attacks Rose 48 Percent in September

Organizations faced a significant increase in weekly attacks driven by rising phishing and AI data risks.

Updated on Oct. 8, 2026 in Cybersecurity

Bold flat-color editorial illustration of a complex metallic network lattice, representing rising global cybersecurity vulnerabilities.
Global cyber attacks surged 48 percent year-on-year in September 2026, with organizations facing an average of 2,803 attacks each week. AI Illustration. Upload story photo >

Live Poll

Do you trust that businesses are doing enough to protect your data from cyber attacks?

Global cyber attacks surged 48% year-on-year in September 2026, with organizations facing an average of 2,803 attacks each week. Ransomware activity also saw a notable increase, rising 53% compared to the same period last year.

Why it matters

The sharp rise in incidents highlights growing vulnerabilities in digital infrastructure as attackers increasingly leverage phishing and Generative AI prompts. Educational institutions were particularly targeted as students and staff reconnected to networks.

Phishing emails affected one in 91 messages with 81% containing malicious links, while one in every 39 GenAI prompts presented a high risk for sensitive data leakage.

The players

The Gentlemen

This ransomware group was responsible for 13% of all published attacks in September 2026.

The details

The education sector faced the highest pressure with 6,656 weekly attacks per organization, while 824 ransomware attacks were identified on leak sites. The Gentlemen ransomware group was identified as responsible for 13% of these published attacks.

Timeline

  1. September 2025 served as the baseline for the 48% year-on-year increase in global attacks.

  2. Organizations faced 2,055 weekly cyber attacks in May 2026.

  3. The average number of weekly attacks rose to 2,416 in August 2026.

  4. Weekly attacks reached 2,803 per organization by September 2026.

The Tech Race

These findings update the threat landscape identified by the September 2026 Check Point Research threat report. The surge underscores a pivot toward automated exploitation techniques that challenge legacy perimeter defense strategies.

Users should exercise extreme caution with email attachments and embedded links, which remain the primary vector for delivering malicious content. Additionally, employees should avoid entering internal infrastructure data into external Generative AI tools to prevent potential information leaks.

The takeaway

The rapid rise in attacks suggests that traditional email security filters are becoming less effective against modern phishing tactics. Organizations must adopt stricter data handling policies for AI tools to mitigate the risk of accidental exposure.

Further reading

For more information on current digital threats, visit the Cybersecurity section.

More information

View the full September 2026 cyber threat report for detailed methodology and findings.

Live Poll

Do you trust that businesses are doing enough to protect your data from cyber attacks?