Check Point Research, the threat intelligence division of Check Point Software Technologies, has released its Global Threat Intelligence insights for July 2026, showing that organisations worldwide faced an average of 2,336 cyber attacks per week. The figure represents a 3% increase from June and a 16% rise compared with July 2025.
African organisations recorded an average of 3,237 weekly attacks per organisation, below Latin America’s 3,561 and the Asia-Pacific region’s 3,316. Within Africa, Angola was the most heavily targeted, with 5,714 weekly attacks per organisation, followed by Nigeria at 4,975, Kenya at 2,915 and South Africa at 2,195. Financial services, government and energy and utilities remained the top three most attacked sectors on the continent.
Lorna Hardie, Regional Director for Africa at Check Point Research, said the data shows cyber risk accumulating across multiple fronts simultaneously. Attack volumes are rising, ransomware has accelerated sharply, and generative AI exposure has become part of daily business activity.
Globally, the education sector remained the most targeted industry, averaging 4,848 weekly attacks per organisation, a 14% year-on-year increase. Government followed with 3,044 attacks, telecommunications with 2,927, while energy and utilities rose 20% to 2,759. Hospitality, travel and recreation entered the top five with 2,614 attacks, up 28%.
Generative AI risk has moved from theory to daily operational reality. In July, one in every 36 enterprise prompts carried a high risk of sensitive data leakage. Eighty-eight percent of organisations regularly using generative AI tools were affected by high-risk prompt activity, and 22% of all prompts contained potentially sensitive information. Organisations used an average of eight generative AI tools, with users generating 95 prompts each on average. Personal data was the most commonly exposed category, appearing in 70% of organisations, followed by financial data and network and IT infrastructure at 68% each.
Email remained a high-volume risk channel. One in every 128 emails, or 0.78%, was classified as phishing, while a further 20% fell into unwanted or risky categories such as graymail, spam and suspicious messages. Africa recorded the highest phishing rate globally at one in every 106 emails, followed by North America at one in every 117, reinforcing email’s role as a common starting point for credential theft, malware delivery and business email compromise.
The clearest shift in July came from ransomware. Reported attacks reached 964, up 49% from June and 87% compared with July 2025. This marked a decisive break from the first half of 2026, when monthly ransomware activity averaged around 672 incidents. Business services remained the most affected sector, accounting for 32.5% of reported victims, followed by industrial manufacturing at 14.4% and consumer goods and services at 13.4%.
North America accounted for 45% of reported ransomware incidents, Europe 28% and Asia-Pacific 17%. At country level, the United States dominated with 39.4% of reported attacks, followed by Germany, Canada, the United Kingdom and Italy.
The ransomware landscape continues to shift. The Gentlemen and Qilin were the most prevalent groups in July, each responsible for 14% of published attacks. DeadLock ranked third with 10% and 97 reported victims, highlighting ongoing changes in the ransomware ecosystem.