Key Takeaways
- Most ransomware attacks are carried out to embarass organizations, rather than just for financial gain, according to ZeroFox’s Vice President of Intelligence
- North American-based organizations were the most targeted by ransomware groups in Q2 2026, and the manufacturing and construction were also widely targeted
- Organizations should focus on their fundamentals, says cyber expert, but some forces are beyond their control
Adam Darrah, Vice President of Intelligence at ZeroFox, says most ransomware attacks are about building notoriety and embarassing organizations, rather than just for financial gain.
North American-based organizations were the most targeted by malicious actors in ZeroFox’s latest ransomware report, and industries including manufacturing and construction were hit the hardest.
Darrah says organizations should consolidate cybersecurity fundamentals to protect themselves, although admitted the firepower of nation-backed groups could be too difficult to stop in the long run.
Most Ransomware Attacks are About Embarassing Organizations Over Taking Their Money
ZeroFox’s Q2 2026 Ransomware Wrap-Up found five attack collectives were responsible for nearly half (49.5%) of all global ransomware and digital extortion (R&DE) attacks in Q2 of 2026.
Adam Darrah, Vice President of ZeroFox, spoke to Tech.co exclusively about how R&DE attacks are primarily about embarassing and panicking organizations, rather than financial gain, based on the findings of the report.
This just in! View
the top business tech deals for 2026 👨💻
“What [the findings] suggests is that it’s less about financial incentive and more about appearing bigger, better, scarier. They want the civilized, law-abiding class to be scared and to be embarassed,” Darrah told us.
Manufacturing, Supply Chain, Technology Among Industries at Risk
The report identified a total of 1,885 separate R&DE incidents in Q2 of 2026, an increase in year-on-year incidents from Q2 2025 and Q2 2024, suggesting incidents around this quarter are on the rise. Notably, attacks on North American-based organizations made up nearly 45% of all incidents reported. According to Darrah, these numbers are the result of the geopolitical conflict between America and Iran.
Overall, the manufacturing industry experienced the highest number of R&DE incidents in this quarter, accounting for nearly 20% of all incidents. This too, Darrah says, is connected to the shutdown of the Strait of Hormuz, and a desire from ransomware groups gain notoriety.
“Ransomware groups, especially those aligned either as a fellow traveler or as a direct associate of a military security apparatus, they like doing a couple of things. They love notoriety, they love being obedient to their overlords, they love money,” Darrah explains. “But they also love sitting back and watching civilized, law-abiding people and organizations squirm and be uncomfortable and to watch that pain.”
Similarly, R&DE targeting patterns have shifted away from the retail sector, and have instead turned towards the technology industry. Darrah again notes this is another way of embarassing important organizations.
“There’s a lot of prestige with what’s happening in the world right now in terms of AI,” Darrah says. “I think there’s probably a bit of prestige in going after technology firms, the people associated with that, to embarass the company and the victims.”
While Darrah notes developments in AI have also made the threat landscape more unpredictable, he does say some ransomware groups are still using older technologies, and are yet to convert to AI. In this case, businesses should protect themselves from all kinds of threats.
What Should Businesses Be Worried About?
“I think businesses should be most worried about worrying too much,” Darrah says, suggesting businesses may be overcomplicating the issue. “I think we overthink the latest and greatest, and we take our eye off the fundamentals. And if you concentrate on the fundamentals, that is going to significantly decrease your risk.”
Darrah urges businesses to focus on strong password policies, a culture of reporting suspicious emails, and patching, among other best cybersecurity practices.
However, there are some vulnerabilities businesses can’t avoid. Businesses today are frequently outsourcing to clouds and third-party providers, and yes, they make our lives easier, but if they are breached, it becomes a problem. Darrah says this “affects people who are doing everything they’re supposed to do. They have all their policies… But if that third party gets hit, it’s like your brand is still dragged through the mud.”
“The interconnectivity of the world just makes it ultra likely that somebody is going to be touched by this plague,” he adds.
Moreover, sometimes organizations are targeted by much larger and more sophisticated groups than they can realistically handle. Particularly if they are backed by nations like Russia or China.
“I think we put a lot of pressure on people who love their job and who care very deeply, and we’re telling this person, defend against Russia, defend us against China,” Darrah says. In these cases, the outcomes can be much harder to prevent against, and understandably so.