A marked surge in cyberattacks is hitting organizations globally this September 2026. Between the explosion of ransomware attacks targeting the economic fabric and massive leaks of confidential data via generative IA, the operational vulnerability of companies has reached a particularly critical level for their business continuity.
According to data consolidated by Check Point during the month of September 2026, organizations suffered an average of 2 803 cyberattacks per week, marking an increase of 16% over one month and a leap of 48% over one year. While the education sector remains the most targeted in absolute volume (6 656 weekly attacks) due to the start of the school year, it is the threat hanging over the private economic and financial fabric that is raising the most serious concerns among business leaders.
B2B services on the front line The threat with the most severe financial consequences remains ransomware: this malicious software is designed to block access to a computer system or encrypt sensitive data, before demanding a ransom payment to restore access or provide the decryption key. In September, 824 ransomware attacks were recorded globally, registering a meteoric rise of 53% over one year.
The business services sector is the preferred target of hackers, accounting for 31,3% of victims alone, far ahead of consumer goods (15,2%) and industry (11%). For cybersecurity experts and researchers, this massive targeting of B2B is explained by the desire of cybercriminals to strike key service providers in order to create a domino effect across their entire value chain.
By neutralizing a single IT or financial service provider, attackers compromise, by extension, the activity of dozens of client companies. Financial data leaks via generative IA Parallel to external attacks, internal data governance is emerging as a major risk factor with the massive adoption of artificial intelligence tools in companies.
One query out of 39 (i.e., 2,5%) addressed to generative IA platforms like ChatGPT, Claude, or Mistral presented a high risk of sensitive data leakage, affecting 89% of companies that regularly use these solutions. Even more worrying for financial management and auditors, 70% of organizations see their employees transmit financial data in their IA queries; 71% expose IT and network infrastructure data there; 68% share legal and regulatory information there.
In highly regulated sectors such as financial services, where the exposure rate to high-risk queries reaches 4,1%, the absence of usage policies and strict controls directly threatens business confidentiality and regulatory compliance. Email, the main entry point Regarding intrusions, email remains the preferred vector for cybercriminals.
In September, 1,1% of emails in circulation (i.e., one email out of 91) were identified as phishing attempts: this social engineering technique is used by cybercriminals to deceive a person into communicating confidential information. In 81% of phishing cases, the threat materialized in the form of malicious links designed to trap employees and steal their access credentials.
Prevention Faced with this volatile mix of threats combining ransomware attacks and emerging risks related to IA, the urgency of moving beyond fragmented defenses is becoming a strategic priority. To preserve their financial value, reputation, and operational continuity, companies are called upon to deploy preventive and centralized security architectures, combining global visibility, IA-driven automation, and rigorous governance of digital usage across all their channels.
Anselme Akéko Published on 09/10/26 11:15 The Editorial Staff
