AI could materially change ransomware economics without forcing companies to rebuild their security architecture. NCC Group’s assessment is that automation can reduce the effort and expertise needed to run parts of a campaign while increasing speed and scale. Matt Hull, Vice President of Cyber Intelligence and Response at NCC Group, also points to increasingly convincing phishing, social engineering and other malicious content. NCC Group sells cybersecurity and incident-response services, so it has a commercial interest in organizations investing in stronger security capabilities.
AI may change ransomware economics
The distinction matters for executives deciding where to spend money and management attention. Hull describes AI as changing the “speed and scale” of cyber attacks and allowing attackers to automate more of their work. NCC Group’s assessment points to autonomous tools handling more stages from initial compromise through extortion. Attackers could then perform familiar criminal tasks faster and with less specialist effort.
July’s ransomware data measures current activity. The forward-looking question is how automation could change the resources required to run campaigns. If autonomous systems handle more stages of an attack, criminals with less expertise or labor may be able to attempt campaigns that once required greater human capability. That mechanism underpins NCC Group’s concern about greater scale.
Ransomware is already operating at high volume, and risk is concentrated
NCC Group recorded 894 ransomware cases in July, up 22% from June and the highest monthly total recorded so far that year. The figure was still 19% below the record of 1,099 attacks in February 2025. These figures show the scale and month-to-month movement in observed ransomware activity. They should be considered separately from NCC Group’s forecast about how AI may affect future campaigns.
Activity was geographically concentrated. North America accounted for 41% of July attacks and Europe for 29%, putting the two regions together at 70%. For executives operating across either region, these figures indicate where a large share of observed ransomware activity occurred. They also provide context for assessing exposure across business operations.
Industrials represented 28% of attacks during the month, the largest sector share. NCC Group described ransomware groups as continuing to focus on organizations with complex operations and broad supplier networks. That characterization comes from a cybersecurity provider that benefits commercially when organizations buy security and response services. For management teams, the practical question is whether they understand critical operations and supplier dependencies well enough to assess the business effect of an incident.
A project in mind?
Schedule a 30-minute meeting with us.
Senior experts helping you move faster across product, engineering, cloud & AI.
AI could lower the capability barrier
Ransomware activity in July was concentrated among several named groups. The Gentlemen accounted for 15% of all July attacks, rising to 138 incidents from 88 in June. Qilin ranked second, while Deadlock accounted for 9% of incidents.
NCC Group’s assessment is that autonomous tools could automate more stages between gaining initial access and carrying out extortion. A criminal who previously lacked the expertise or labor to execute parts of that process could potentially delegate more work to AI systems. This could broaden the pool of criminals able to attempt credible campaigns at scale. It remains a forecast about how attacker capabilities may develop.
Hull also says AI lets attackers create increasingly convincing phishing, social engineering and other malicious content. If producing and adapting such content requires less human effort, attackers could increase the volume of interactions while making them more persuasive. That would put more pressure on employees and security teams assessing suspicious activity. It also explains why speed matters on both sides of an incident.
Cyber crime depends on attacker time, expertise and effort as well as technical opportunity. Automation that reduces those requirements could make some campaigns easier to execute and free established operators to apply human expertise elsewhere. NCC Group’s forecast therefore concerns how attackers organize their work as much as any individual AI capability. Executives can prepare for that scenario while treating current ransomware totals and forecasts about AI as separate evidence.
Established security controls face greater time pressure
More capable automation changes the conditions under which existing defenses operate. Hull recommends strong identity and access controls, good vulnerability management, visibility across the environment, and the ability to detect and respond quickly. These recommendations come from NCC Group, which provides cybersecurity services in these areas. They correspond to the attack stages NCC Group expects AI to accelerate: gaining access, exploiting weaknesses, operating inside an environment and carrying out extortion.
Identity and access controls become more consequential as malicious requests become more convincing. Reliable access rules can limit what authenticated users can reach and what they can do after a successful social-engineering attempt. This reduces dependence on employees identifying every malicious communication before acting on it. Strong access governance creates another barrier between a persuasive request and sensitive systems.
Vulnerability management addresses a separate part of the attack path. If automation lets attackers move through targets and attack processes faster, long remediation cycles can give them more time to exploit known weaknesses. Leadership therefore needs a clear link between technical remediation and business importance. Security teams need to identify weaknesses, understand which systems matter most and drive timely corrective action.
Visibility across the environment determines how quickly defenders can understand activity. If attack stages happen faster, delayed discovery leaves less opportunity to intervene before an attacker progresses. Security leaders need enough information from relevant systems to detect activity while action can still affect the outcome. The operational question is how quickly that information becomes a decision.
Detection and response face the same time pressure. Hull emphasizes the ability to “detect and respond quickly when something goes wrong.” If AI compresses the time and labor required for parts of a campaign, slow escalation can leave less time for investigation and intervention. Organizations need clear ownership and response processes that turn an alert into action.
Employee awareness also changes as generated content improves. Hull argues that employees need to understand what threats look like, recognize when something feels wrong and have a simple way to report it. Reporting processes are therefore a core part of awareness programs because employees need a clear path to escalate suspicious activity. The goal is to support judgment as malicious communications become increasingly convincing.
AI can also support defenders. Hull says AI can help security teams process information faster and identify potentially malicious activity. That use can shorten signal review and bring relevant information to analysts sooner. Hull also emphasizes the need to understand what represents a genuine threat, keeping human judgment involved in consequential security decisions.
The implementation challenge is operational discipline under greater time pressure. An AI security capability still depends on access governance, asset visibility and response processes that turn information into action. Leaders can test those controls against the conditions NCC Group describes: faster malicious activity, more convincing communications and less time for analysts to separate meaningful signals from routine activity. This turns a forecast about AI into a concrete test of existing security operations.
Faster decisions raise the value of evidence discipline
Pressure for faster decisions cannot lower the standard for evidence. CRPxO claimed responsibility for 36 victims in July, or about 4% of the total, but NCC Group said those claims had not been confirmed and cited inconsistent evidence over whether the group was behind the attacks. An attacker’s claim and a confirmed incident carry different evidentiary weight. Forecasts about future AI capabilities are a third category and should be identified as forecasts.
NCC Group also examined Operational Relay Box networks used in China-linked cyber operations, which route activity through compromised devices and infrastructure. That routing matters when security teams assess where malicious activity originated and who may be responsible. The example concerns attribution, while AI-enabled speed creates separate pressure for quicker operational decisions. Security teams may need to act quickly while remaining precise about what is observed, claimed or inferred.
That distinction should carry into executive reporting. Boards and management teams making risk or investment decisions need to know whether a number reflects verified activity, an actor’s own claim or an assessment of an emerging capability. Clear evidence labels help leaders make time-sensitive decisions without turning uncertainty into certainty. As new AI-enabled techniques develop, that discipline keeps operational urgency separate from confidence in attribution or forecasts.
Main highlights
- AI may change ransomware economics: AI could reduce the time, expertise and labor needed for ransomware campaigns, allowing attackers to operate faster and at greater scale. Leaders should assess whether existing defenses can keep pace without assuming entirely new security architecture is required.
- Ransomware risk is already high and concentrated: NCC Group recorded 894 ransomware cases in July, with 70% occurring in North America and Europe and 28% affecting industrials. Executives should use geographic, sector and supplier exposure to prioritize resilience planning.
- AI could lower the capability barrier: Automation may let less-skilled criminals execute more stages of ransomware campaigns while helping established groups scale. Security teams should prepare for higher attack volumes and increasingly convincing phishing and social engineering.
- Existing controls face greater time pressure: Strong identity controls, vulnerability management, environment visibility and rapid detection and response become more important as attacks accelerate. Leaders should test how quickly these controls turn suspicious activity into effective action.
- Faster decisions require evidence discipline: Security teams must distinguish confirmed incidents from attacker claims, attribution assessments and forecasts while responding quickly. Executive reporting should clearly label evidence and uncertainty so urgency does not become false certainty.
A project in mind?
Schedule a 30-minute meeting with us.
Senior experts helping you move faster across product, engineering, cloud & AI.


