Infosecurity

One Government Agency Hit by Ransomware Every Day: New Data Shows a Relentless Surge

Published

on

Attack Frequency Reaches a New Milestone

Ransomware is no longer a periodic threat for public-sector organizations — it’s a daily reality. New data from cybersecurity researchers at Comparitech shows that, on average, one government agency somewhere in the world has its systems encrypted and services crippled every single day.

The study, published on July 16, tracked ransomware incidents targeting government bodies between January and June 2026. It recorded 187 attacks over 182 days — a pace that works out to just over one per day. That marks a 13% jump from the 165 attacks logged in the second half of 2025.

Of those 187 incidents, only 89 — roughly half — were publicly acknowledged by the affected organizations. The rest either went undisclosed or remained unconfirmed at the time of reporting.

Why Governments Are Prime Targets

Government agencies hold a toxic combination of assets: vast troves of sensitive citizen data and systems that the public depends on daily. When ransomware locks up a municipal billing system or a state health portal, the pressure to restore services fast is immense.

“From weeks-long disruptions due to system encryption to extensive data breaches, governments are the ideal target for hackers,” said Rebecca Moody, head of data research at Comparitech.

That pressure often translates into a higher likelihood that the victim will pay the ransom. Attackers know this. A city hall can’t afford to be offline for a month while IT teams rebuild from scratch — so the calculus for paying up shifts dramatically.

The United States Leads as the Most Frequent Target

The geographic distribution of attacks is lopsided. The US absorbed 31% of all ransomware incidents against government agencies during the six-month period. No other country came close.

Germany was the second-most targeted nation, accounting for just 7% of attacks. Spain and Italy each registered 4%. The gap between the US and the rest of the world is partly explained by population size — more government bodies means more attack surfaces — but it also reflects the aggressive focus of ransomware groups on high-value English-speaking targets.

Ransom Demands: A Calculated Gamble

The median ransom demand during the period sat at $100,000. That figure is relatively modest compared to the multimillion-dollar demands seen in the private sector. The logic is straightforward: ask for too much from a taxpayer-funded entity, and the chance of payment plummets.

Still, outliers exist. The most extreme case was a $3.1 million demand directed at the Land and Agricultural Development Bank of South Africa following a January 2026 attack. The bank refused to pay, and its systems were only fully restored in April. The perpetrator of that attack remains unknown.

Known Threat Groups and Their Methods

While some attackers fly under the radar, many incidents can be traced to established ransomware crews. The most active groups between January and June 2026 were:

  • The Gentlemen — responsible for 10% of attacks
  • Qilin — linked to 9% of incidents
  • LockBit — accounted for 7%

These groups frequently exploit well-known, publicly disclosed vulnerabilities. They move fast once a patch is available — often faster than government IT departments can deploy it.

How Agencies Can Fight Back

Prevention, Comparitech argues, comes down to fundamentals. Moody outlined a set of measures that are unglamorous but effective: keep systems updated, patch vulnerabilities as soon as they are flagged, perform regular backups, and invest in continuous employee training.

“Making sure employees are regularly trained and are on high alert at all times are crucial to mitigating the risks of attacks,” she said.

That last point matters more than many realize. A single phishing email opened by a busy clerk can undo months of security work. For agencies already stretched thin, the cost of proactive defense is far lower than the cost of a recovery operation that takes weeks — or, in the case of the South African bank, months.

The takeaway is sobering: ransomware is not going away, and government networks remain in the crosshairs. The question is not whether another agency will be hit tomorrow. It’s whether they’ll be ready when it happens.

Leave a Reply

Your email address will not be published. Required fields are marked *

Trending

Exit mobile version