We use cookies to optimize your experience, analyze traffic, and personalize ads. Please choose whether you accept our use of non-essential cookies. Read More
Ransomware attacks hit a new record in Brazil, for the third consecutive month.
In August, 27 attacks were recorded in the country, compared to 26 in July. This is the highest number of occurrences in Brazil in 2026 so far, according to data from Ransomware.live, a data breach monitoring platform led by Cohesity. Globally, the trend was even more significant: there were 1,212 attacks in August, a 27% increase compared to the 955 recorded in July.
So far, the reading seems simple: ransomware is growing and companies need to protect themselves.
But there's a less obvious detail in this story.
While the volume of attacks is increasing in Brazil, the B2B market has moved in the opposite direction.
In July, the B2B sector led the ranking of the most affected segments, with 176 cases.
In August, it fell to third place, with 136 occurrences. A reduction of 22.3% in just one month. It was the only segment among the ten most affected to register a decrease during the period.
This does not mean that B2B has ceased to be a relevant target.
On the contrary. Even after the drop, there were 136 occurrences, behind only manufacturing, with 185, and technology, with 161.
The point is this: the overall growth of ransomware is not happening uniformly across sectors.
And this difference matters to those who make security decisions.
Read also: Cybersecurity and the evolution of cyberattacks
The data from August shows an interesting shift in the distribution of attacks.
Manufacturing grew by 21.7%, reaching 185 cases. Technology advanced 27.8%, to 161. Healthcare saw a 38.8%, reaching 118 cases. Financial services grew by 38%, while energy doubled, from 16 to 33 cases.
Retail and e-commerce also increased, although at a slower pace: 8.6%, reaching 76 cases.
In other words, the Brazilian record is happening within a scenario where different sectors are behaving in very different ways.
And that changes the question companies should be asking.
It's no longer enough to ask:
"Is ransomware on the rise?"
The most useful question is:
"What is causing certain sectors to remain exposed while others change position in the ranking?"
You may also be interested in: Black Friday fraud: how to protect your operation
There is a significant pitfall in interpreting this number.
A 22.3% reduction cannot be automatically interpreted as a sign that B2B companies are better protected.
The numbers from Ransomware.live track victims identified on data breach websites. Therefore, they help to identify known activity by criminal groups, but do not necessarily represent all attacks that have occurred.
Furthermore, ransomware is not just file encryption.
Current attacks can involve data theft, extortion, credential compromise, and disruption of critical systems. In some cases, the threat is less related to the value of a specific file and more to the ability to halt an entire operation.
This point is especially relevant for B2B companies.
An industry may have systems connected to production. A logistics company may depend on systems for routing and distribution. A supplier may be integrated into the environments of dozens of clients.
In these scenarios, the impact of an incident does not end in the directly affected environment.
He can cross the entire chain.
Perhaps the main conclusion from the August data is precisely this: there is no single interpretation of ransomware.
Brazil is on an upward trajectory. August was the third consecutive month of growth and placed the country in sixth position among the most affected in the world, tied with India, with 27 cases.
At the same time, B2B fell 22.3%, while sectors such as healthcare, technology, manufacturing, and financial services accelerated.
Looking only at the overall number can obscure these differences.
For IT and security, this means the discussion needs to move beyond the volume of attacks and focus on the ability to withstand them.
The question shouldn't just be whether the company can prevent an intrusion.
It is important to know:
Because, in the end, ransomware doesn't necessarily need to overcome the security layer.
He just needs to find a point where the company can no longer continue operating.
The decline in B2B sales in August is an interesting piece of data precisely because it prevents any easy conclusions.
Fewer incidents in a month do not necessarily mean less risk. Similarly, more incidents in another sector do not, by themselves, mean that all companies in that sector are equally vulnerable.
What the numbers show is that the scenario is changing rapidly.
And when ransomware spreads across sectors with increasingly digital and interdependent operations, security needs to be considered alongside continuity.
Prevention remains important.
But a mature company also needs to be able to answer a far less comfortable question: if ransomware manages to get in, how long can its operations remain operational?
That's when the conversation stops being just about cybersecurity and starts being about business resilience.
Transform Your Business with Skyone. Request a demo or schedule a call with our experts to discover how Skyone can accelerate your digital strategy.
Have a question? Talk to a specialist and get all your questions about the platform answered.