Organisations worldwide faced an average of 2,803 cyber attacks per week in September 2026, according to figures from Check Point reported by IT Security Guru. That is 16% higher than August and 48% higher than September last year. The numbers point to a clear pattern: rising ransomware and phishing attacks are putting more pressure on organisations and the people who work in them.
The source report is brief, so this post sticks to what it states and explains what it means in practical terms, including which of these risks a VPN actually addresses and which it does not.
What Check Point's September 2026 numbers show
The headline figure is an average of 2,803 attacks per week per organisation in September 2026. Two comparisons give it context:
- Up 16% on August 2026, a month-on-month increase.
- Up 48% on September 2025, a year-on-year increase.
The report ties the increase to ransomware and phishing, the two threat types highlighted in its findings. An average is not the same as what every organisation experiences, since some will see far more activity and others far less. Still, a rise of this size over a single year suggests attackers are scaling up their efforts rather than just reshuffling targets.
This also fits a broader trend we covered earlier. Our report on ransomware attacks doubling globally in July 2026 described a similar upward direction, and September's data suggests the pressure has not eased.
Why phishing and ransomware are driving the increase
Phishing and ransomware are closely linked. Phishing is often the first step: a convincing email, text, or message persuades someone to click a link, open an attachment, or enter their password on a fake login page. Once an attacker has a foothold or valid credentials, ransomware can follow, encrypting files and demanding payment.
This combination is attractive to criminals for a few reasons:
- Phishing is cheap to send in bulk and only needs to work on a small share of recipients.
- A single stolen password can open the door to an entire network.
- Ransomware gives attackers a direct way to turn access into money.
The damage is not abstract. Our coverage of a ransomware group behind breaches at ANC, SAA, and Pick n Pay shows how one group can hit many well-known institutions. Regional reports tell a similar story, including ransomware attacks surging across Gulf businesses in 2026.
What individuals can and can't do about it
It is easy to feel that a statistic about organisations has little to do with you. But employees, freelancers, and small business owners are often the entry point attackers look for. You cannot control a company's network, yet you can reduce the chance that you are the weak link.
What you can do:
- Turn on multi-factor authentication (MFA) for email, banking, cloud storage, and work accounts. A stolen password alone then becomes much less useful.
- Slow down on unexpected messages. Urgency, unusual payment requests, and unfamiliar links are common phishing signs.
- Use a password manager so every account has a unique password and you are less likely to type credentials into a fake page.
- Keep devices and apps updated, since attackers often exploit known flaws that patches already fix.
- Back up important files offline or in a separate location, so ransomware cannot hold your only copy hostage.
What you cannot do alone: patch your employer's servers, fix misconfigured systems, or stop a supplier from being breached. Those depend on organisations having sound security practices, which is why reporting suspicious messages to IT or security teams matters.
Where a VPN helps and where it doesn't
A VPN encrypts your internet traffic between your device and the VPN server and hides your IP address from the sites you visit. That is useful on public Wi-Fi and for limiting what your network provider can see. It is a privacy tool, and it has real value in that role.
But it does not address the main drivers in Check Point's findings:
- Phishing: A VPN does not stop you from clicking a malicious link or entering your password on a fake site. The message arrives and the page loads the same way with or without a VPN.
- Ransomware: A VPN does not remove malware already on your device or prevent a malicious attachment from running.
- Stolen credentials: If an attacker has your password, a VPN does not block them from logging in. MFA does.
In short, a VPN protects data in transit, while the attacks driving this increase usually succeed by tricking people or exploiting weak account security. Treat a VPN as one layer, not a substitute for MFA, updates, backups, and phishing awareness.
What This Means For You
The 48% year-on-year rise suggests attackers are more active, so basic habits matter more than before. If you work for an organisation, assume phishing attempts will reach you. If you run a small business, assume ransomware is a realistic risk, not a distant one. The good news is that the most effective defences are mostly low-cost and within your reach.
Actionable takeaways
- Enable MFA on your email and any account that holds money or sensitive data.
- Pause before clicking links or opening attachments you did not expect.
- Keep regular, separate backups of files you cannot afford to lose.
- Update your operating system, browser, and apps promptly.
- Use a VPN for privacy on untrusted networks, but do not rely on it against phishing or ransomware.
For concrete steps, read our guide on how to protect against ransomware's 72-hour threat. It is a practical starting point for responding to rising ransomware and phishing attacks before they reach you.




