
Cybersecurity teams entered the second half of 2026 with little sign of relief. Global organisations faced an average of 2,336 cyber attacks per week in July, up 3 per cent from June and 16 per cent from a year earlier, according to new data from Check Point Research.
The figures point to a threat environment that is not merely growing in volume, but widening in scope. Traditional attack channels such as email remain persistent, ransomware groups appear to have regained momentum, and generative AI tools are creating fresh data leakage risks inside companies faster than many security policies can catch up.
Also Read: Southeast Asia’s cyber boom is fuelled by fear—and AI
For Southeast Asian startups and digital businesses, the findings land at an uncomfortable moment. The region’s companies are adopting AI, cloud software and cross-border digital operations at speed, often with lean security teams and fragmented tooling. That combination can create the kind of gaps attackers look for: exposed credentials, unmonitored data flows, vulnerable suppliers and employees using new tools before governance catches up.
“July’s data shows that cyber risk is accumulating across multiple fronts at once,” said Omer Dembinsky, Data Research Manager at Check Point Research. “Attack volumes continue to rise, ransomware has accelerated sharply, and GenAI exposure is now part of daily business activity.”
Education and government remain in the firing line
The education sector remained the most attacked globally, with an average of 4,848 weekly attacks per organisation in July, a 14 per cent increase year on year. Government followed with 3,044 attacks, while telecommunications recorded 2,927.
The prominence of education is not surprising. Schools, universities and training institutions often hold large volumes of personal data, run sprawling IT networks, and operate with uneven cybersecurity budgets. In Southeast Asia, where governments have pushed digital learning platforms, online admissions and student management systems, these institutions can be attractive targets for both data theft and disruption.
Energy and utilities also saw a sharp increase, rising 20 per cent year on year to 2,759 weekly attacks per organisation. Hospitality, travel and recreation entered the top five with 2,614 attacks, up 28 per cent.
That matters for Southeast Asia, where tourism has rebounded strongly since the pandemic and travel operators have become deeply dependent on digital booking, payment and identity systems. A breach in this sector can quickly spill across customers, payment providers, loyalty programmes and third-party booking platforms.
APAC remains one of the world’s most attacked regions
Latin America recorded the highest attack volume in July, with 3,561 weekly attacks per organisation, up 19 per cent year on year. Asia Pacific followed closely at 3,316 attacks, ahead of Africa at 3,237.
Europe stood out for the pace of increase, rising 18 per cent year on year to 2,051 attacks per organisation. North America saw a 9 per cent increase to 1,613.
For Southeast Asia, APAC’s high ranking reflects a familiar structural issue. The region is home to fast-growing digital economies, but cybersecurity maturity varies widely between markets and sectors. A fintech in Singapore, an e-commerce platform in Indonesia, a logistics company in Vietnam and a hospital network in the Philippines may all be part of the same digital supply chain, but operate under different standards, budgets and regulatory pressures.
Also Read: What AI safety researchers actually worry about
This unevenness is a particular concern for startups. Many young companies rely on cloud platforms, software-as-a-service tools and outsourced development teams from day one. These choices help them scale quickly, but also widen the attack surface if access controls, vendor reviews and incident response plans are treated as later-stage concerns.
GenAI turns into a daily data risk
Perhaps the most modern risk in Check Point’s July data concerns generative AI. The research found that one in every 36 enterprise prompts carried a high risk of sensitive data leakage. Among organisations that regularly use GenAI, 88 per cent were affected by high-risk prompt activity.
The issue is not simply that employees are experimenting with chatbots. It is what they are putting into them. Check Point found that 22 per cent of prompts contained potentially sensitive information. Personal data appeared in 70 per cent of affected organisations, while financial data and network or IT infrastructure information each appeared in 68 per cent.
On average, organisations used eight GenAI tools, with users generating 95 prompts. In practical terms, this means employees may be feeding customer records, internal financial details, source code, contracts, credentials or system architecture into tools that were not approved or monitored by security teams.
For Southeast Asian startups, the risk is acute because GenAI has moved quickly from novelty to workflow. Founders use it to draft investor updates, developers use it to debug code, sales teams use it to summarise customer calls, and operations teams use it to process documents. Without clear rules, a productivity tool can become an unintentional data export channel.
The challenge is to govern AI use without blocking it outright. Companies will need policies that define what can and cannot be entered into public tools, technical controls to detect sensitive data in prompts, and safer enterprise-grade AI environments for teams that need to work with confidential information.
Email remains the old reliable route for attackers
Even as AI creates new risks, email continues to do what it has always done for attackers: provide a cheap, scalable entry point.
Check Point found that one in every 128 emails, or 0.78 per cent, was classified as phishing in July. Another 20 per cent fell into unwanted or risky categories such as graymail, spam and suspicious messages. Africa had the highest phishing rate, at one in every 106 emails, followed by North America at one in every 117.
Phishing remains effective because it targets people rather than systems. A single fake invoice, delivery notice, password reset request or investor email can be enough to trigger credential theft, malware installation or business email compromise.
In Southeast Asia, where companies often work across languages, currencies and jurisdictions, the room for deception is wide. A fraudulent supplier email or payment instruction can be difficult to spot when teams are already managing regional vendors, remote staff and multiple messaging channels.
Ransomware breaks from its earlier pattern
The clearest shift in July was ransomware. Reported ransomware attacks reached 964, up 49 per cent from June and 87 per cent compared with July 2025. That marked a break from the first half of 2026, when monthly activity averaged around 672 incidents.
Business services accounted for 32.5 per cent of reported victims, followed by industrial manufacturing at 14.4 per cent and consumer goods and services at 13.4 per cent. North America remained the most affected region, accounting for 45 per cent of incidents, while Europe followed at 28 per cent and APAC at 17 per cent.
The United States dominated the country-level victim count with 39.4 per cent of reported attacks, ahead of Germany, Canada, the United Kingdom and Italy.
Ransomware data based on published victims can undercount the real scale of incidents, as not every attack is disclosed or listed by criminal groups. Still, the July jump suggests attackers are finding enough success to sustain and expand operations.
The most active groups in July were The Gentlemen and Qilin, each responsible for 14 per cent of published attacks. DeadLock followed with 10 per cent and 97 reported victims, underlining how fluid the ransomware ecosystem remains as groups rebrand, fragment or compete for targets.
Also Read: Thailand is suddenly on the frontline of a new ransomware wave
For founders and operators, the takeaway is blunt: cybersecurity is no longer just an enterprise IT problem. It is a business continuity issue. As attack volumes rise and AI reshapes both productivity and exposure, companies that treat security as an afterthought may find that the cost of catching up arrives all at once.
The post Education, energy and travel sectors face rising cyber attack volumes appeared first on e27.
