Global cyberattacks increased by 10% compared to the previous month and by 17% year-on-year in June, while ransomware attacks increased by 33%, with The Gentlemen emerging as the most active ransomware group worldwide.
Η Check Point Research (CPR), Check Point Software Technologies Ltd.'s cyber threat intelligence division has released its latest figures. Global Threat Intelligence Report for June 2026, according to which organizations worldwide accepted on average 2.270 cyberattacks per week, registering an increase 10% compared to May and 17% compared to June 2025.
Following a relative lull in May, June saw a resurgence of intense malicious activity, with attacks increasing across nearly all geographies and industries. Rather than being limited to specific markets or industries, the increase was seen across the board, suggesting that attackers significantly broadened their scope of targets.
“The June data reflects a generalized resumption of malicious activity rather than an isolated outbreak,” said Omer Dembinsky, Data Research Manager at Check Point Research. “Cybercriminals are expanding their operations across more regions and industries, while ransomware groups continue to reorganize and increase their capabilities. The emergence of the group The gentlemen at the top of the global rankings demonstrates how quickly new “players” can evolve into significant international threats. Organizations need a cybersecurity strategy with a holistic approach prevention-first, leveraging Artificial Intelligence capabilities that protect networks, users, data and AI workflows before attacks cause real impact.”
Education, Public Sector and Telecommunications remain the main targets
The industry of Education maintained its position as the most targeted sector worldwide, with 4.816 attacks per organization per week, showing an increase 16 % compared to June 2025. Educational institutions' open networks, constant device switching, and limited security resources continue to make them particularly attractive targets.
He followed Public sectorwith 2.836 attacks per week (+5% on an annual basis), while in third place were Telecommunicationswith 2.835 attacks (+13%). These three sectors continue to account for a disproportionately large percentage of global offensive activity, confirming a trend that has remained consistent in recent months.
Increased attacks in all geographical regions – Latin America first
Η Latin America remained the region with the most cyberattacks, recording an average of 3.501 attacks per organization per week, increased by 27 % compared to June 2025.
The area followed Asia-Pacific (APAC) with 3.060 attacks (+5%), while the Africa recorded 3.008 attacks, recording a 9% decrease year-on-year, but remaining among the regions with the greatest offensive activity worldwide.
A significant increase was also shown by Europe (+22%) and the North America (+14%), confirming that June's rise was not limited to a single market, but reflects an overall escalation of the global cyberthreat landscape.
Risks from GenAI use remain high – Higher exposure in Healthcare and Telecommunications
The use of applications Generative AI (GenAI) continued to be a significant source of risk for businesses. According to Check Point Research, one in 26 prompts submitted by corporate networks to GenAI tools posed a high risk of sensitive data leakage, corresponding to global exposure rate 3,9%.
High-risk activity detected in 85% of organizations who systematically use GenAI tools, while additionally 27% of prompts contained potentially sensitive information. On average, each organization used seven different GenAI tools in the last month, while each user submitted 78 prompts.
Η Latin America presented the highest exposure rate (5,2%), significantly above the global average, while the Europe found in 3,9 %, aligned with the international average.
At the sector level, the greatest exposure was shown by Health and Medical Services (5,7%), the Telecommunications and Business Services (5,1%), as well as the industry Information Technology (4,1%).
Personal data was the most common type of sensitive information identified (80% of affected organizations), followed by network and infrastructure data, legal and regulatory material, financial data, and employee records, demonstrating that risks from GenAI impact multiple business functions.
Ransomware attacks are on the rise – Business services are mainly targeted
Attacks ransomware amounted to 646 cases in June, showing an increase 33 % compared to the corresponding month of 2025.
The branch of Business Services remained the most affected, representing the 31 % of the publicized victims, while the following were Consumer Goods and Services (16%) and h Βιομηχανική Παραγωγή (14%).
At the same time, Public sector continued to increase its share of ransomware victims, from 4,0% in April on 5,4% in June.
It is also noteworthy that the area Asia-Pacific (APAC) showed a significant increase in the number of victims, surpassing Europe and now occupying second place behind North America.
The Gentlemen team displaces Qilin from the top
The most significant development of June concerns the ransomware ecosystem. The team The gentlemen emerged as the most active ransomware group worldwide, responsible for 17 % of publicized attacks, surpassing the qilin, which was limited to 11 %.
At the same time, the lockbit recorded an impressive return, increasing its share of 1% in May on 7% in June, taking third place.
The Gentlemen's rapid rise highlights the potential of new business models Ransomware-as-a-Service (RaaS) to expand rapidly through affiliates, pre-existing access to target networks, and increasingly sophisticated techniques for avoiding detection.
For more information on cyber threat trends in June 2026, visit Check Point Research blog.
Although the press releases will range from very select to rare, I said I'd pass...because sometimes the editors hide.



