The global public sector is facing an unprecedented escalation in cyber-hostilities, with new data revealing that ransomware attacks on government departments and agencies have reached a frequency of one successful breach every single day. According to an exhaustive analysis conducted by cybersecurity researchers at Comparitech, the first six months of 2026 saw a total of 187 government organizations worldwide fall victim to ransomware incidents. This figure represents a sharp 13% increase from the 165 attacks recorded during the second half of 2025, signaling a persistent and worsening trend in the targeting of critical public infrastructure.
The research, which was published on July 16, 2026, highlights a grim milestone for digital governance. By documenting 187 incidents across 182 days, the study confirms that the average number of ransomware attacks against government bodies has effectively transitioned from a sporadic threat to a daily occurrence. These attacks do not merely represent digital inconveniences; they often result in the total encryption of essential systems, the suspension of public services, and the exposure of sensitive citizen data.
The Strategic Targeting of Public Infrastructure
Government agencies have long been viewed as "white whales" for cybercriminal syndicates, and the H1 2026 data reinforces why this sector remains a primary focus. Unlike private corporations, which may have more flexibility in how they handle downtime, government entities provide essential services—ranging from healthcare and emergency response to social security and tax administration—that the public relies upon for daily survival.
"From weeks-long disruptions due to system encryption to extensive data breaches, governments are the ideal target for hackers," noted Rebecca Moody, head of data research at Comparitech. The logic behind this targeting is rooted in the high stakes of service restoration. When a local municipality’s emergency dispatch system or a national tax office’s database is held hostage, the pressure to pay a ransom for a decryption key increases exponentially. For many administrators, the prospect of months of manual service restoration is often weighed against the cost of a ransom, even when official policy strictly forbids negotiating with cybercriminals.
Furthermore, the volume of sensitive data held by these organizations is staggering. Personal identifiable information (PII), including social security numbers, biometric data, and financial records, provides threat actors with significant leverage. In many cases, groups now employ "double extortion" tactics—not only encrypting the data to stop operations but also threatening to leak the stolen information on the dark web if payment is not received.
Geographic Distribution: The United States as a Primary Focal Point
The Comparitech study provides a detailed breakdown of the geographic distribution of these attacks, revealing that the United States remains the most targeted nation by a significant margin. During the first half of 2026, the U.S. accounted for 31% of all recorded ransomware attacks against government entities.
Industry analysts suggest that the disparity between the U.S. and other nations is likely a byproduct of several factors. Firstly, the sheer size of the U.S. population and the complexity of its decentralized government structure—comprising thousands of local, county, and state agencies—provide an expansive attack surface. Secondly, the perceived wealth of U.S. institutions makes them attractive targets for high-value ransom demands.
While the U.S. bore the brunt of the activity, other nations were not spared. Germany followed with 7% of the recorded incidents, while Spain and Italy both accounted for 4% each. The remaining attacks were distributed across a wide array of nations, suggesting that while Western infrastructure is a priority, ransomware is a truly global contagion affecting governments of all sizes and economic standings.
Financial Dynamics and the $100,000 Threshold
One of the more nuanced findings of the H1 2026 report is the stabilization of ransom demands. The mean ransom demand to government agencies during this period stood at approximately $100,000. This figure is lower than the multimillion-dollar demands often seen in the private sector, specifically in industries like manufacturing or finance.

Security experts believe this reflects a calculated strategy by cybercriminals. By keeping demands relatively low, attackers increase the likelihood that a government agency, which is funded by taxpayers and subject to strict public oversight, will find a way to pay without triggering a massive political scandal or an intensive federal investigation. A $100,000 payment may be viewed as a "manageable" loss compared to the millions of dollars in economic productivity lost during a prolonged system outage.
However, there were notable exceptions to this rule. The most significant outlier in the first half of 2026 was a staggering $3.1 million ransom demand issued to the Land and Agricultural Development Bank of South Africa. Following a devastating cyber-attack in January 2026, the bank found its systems paralyzed. In a display of resilience, the organization refused to comply with the attackers’ demands. While this decision protected public funds from being funneled to criminals, the consequences were severe: the bank’s systems were not fully restored until April, resulting in a three-month period of operational chaos that impacted the nation’s agricultural sector.
Profiling the Perpetrators: The Groups Behind the Screen
The first half of 2026 saw the emergence of both new and familiar names in the ransomware landscape. According to the research, the most active groups targeting government sectors were:
- The Gentlemen (10%): A relatively new group that has gained notoriety for its sophisticated social engineering tactics and its focus on high-impact public sector targets.
- Qilin (9%): Known for its "Ransomware-as-a-Service" (RaaS) model, Qilin has been linked to several high-profile attacks on healthcare and municipal services across Europe and North America.
- LockBit (7%): Despite numerous international law enforcement efforts to dismantle its infrastructure, LockBit remains a persistent threat, showcasing an ability to reorganize and deploy new variants of its encryption software.
These groups often exploit well-publicized vulnerabilities that have remained unpatched by overstretched IT departments. The "Gentlemen," in particular, have been noted for their professionalized approach, sometimes even providing a "customer support" experience for victims to facilitate the payment and decryption process.
Public Confirmation vs. Shadow Breaches
A significant challenge in tracking the true scope of the ransomware crisis is the discrepancy between confirmed and unconfirmed reports. Of the 187 recorded incidents in H1 2026, only 89 (just over 47%) were publicly confirmed by the affected organizations.
This gap highlights a "transparency deficit" in the public sector. Many agencies fear the political fallout or the potential for a loss of public trust that follows the admission of a successful breach. Others may be restricted from speaking due to ongoing law enforcement investigations. However, this lack of disclosure can be counterproductive, as it prevents other organizations from learning about the specific tactics, techniques, and procedures (TTPs) being used by attackers, thereby hindering collective defense efforts.
Chronology of a Crisis: Key Milestones in H1 2026
- January 2026: The attack on the Land and Agricultural Development Bank of South Africa marks the year’s first major government-related breach, setting a high-stakes tone for the months to follow.
- February 2026: A series of coordinated attacks hit several mid-sized municipalities in the U.S. Midwest, leading to the first discussions of a "daily" attack average.
- March 2026: LockBit resurfaces with a new encryption tool, specifically targeting European administrative offices.
- April 2026: The South African bank successfully restores services without paying the ransom, providing a case study in long-term recovery.
- May 2026: Attacks in Germany spike, leading to a call for increased federal funding for state-level cybersecurity.
- June 2026: The H1 total hits 187, officially surpassing the previous half-year’s record and confirming a 13% growth trend.
The Path to Resilience: Proactive Cyber Defense
As the frequency of attacks reaches an all-time high, the emphasis for government agencies has shifted from mere prevention to "cyber resilience." Rebecca Moody emphasizes that the best way to avoid falling victim is a proactive defense strategy. This includes keeping systems updated, patching vulnerabilities immediately upon discovery, and maintaining robust, off-site, and air-gapped backups.
Furthermore, employee training remains a critical pillar of defense. Since many ransomware attacks begin with a single phishing email, a workforce that is trained to recognize and report suspicious activity can serve as a vital human firewall.
The implications of the H1 2026 data are clear: ransomware is no longer a "black swan" event for government agencies; it is a standard operational risk. As threat actors continue to professionalize and scale their operations, the public sector must respond with equal vigor. The transition to a "one attack per day" reality suggests that the window for reactive measures has closed, and the era of mandatory, high-level proactive defense has begun. Failure to adapt will not only result in financial loss but will continue to erode the fundamental reliability of the services that modern society depends upon.
