Skip to content
File security for Windows systems — since 2003

How FileSure Would Have Stopped the July 2026 Ransomware Surge

• By Gene Allen

894 Attacks. One Mechanism They All Depend On.

July 2026 saw ransomware attacks hit 894 incidents — the highest monthly total of the year, according to NCC Group’s Threat Intelligence Report. The Gentlemen ransomware group alone claimed over 300 victims in twelve months. A new player called CRPxO emerged with 36 attacks in July. And perhaps most concerning, an autonomous AI agent named Jadepuffer successfully executed an end-to-end ransomware intrusion without human involvement.

The industry response focuses on AI-enhanced detection, faster signature updates, and better threat intelligence. All of that misses the point.

Every single one of those 894 attacks — whether orchestrated by The Gentlemen, a new gang trying to build credibility, or an autonomous AI — required the same thing: writing encrypted versions of files to disk. That’s not a technique. That’s how ransomware works. There’s no way around it.

Why Signature-Based Detection Keeps Failing

Traditional antivirus and EDR tools work by recognizing threats they’ve already seen. A researcher finds a new ransomware variant, analyzes it, creates a signature, pushes an update, and your security tool learns to block it. That process takes time — hours or days. The window between a new ransomware release and when your antivirus can detect it is exactly when attacks happen.

Jadepuffer proves the problem. An AI agent can generate and deploy ransomware variants faster than any signature database can update. The Gentlemen scaled to 300+ victims in a year by moving faster than defenses could adapt. CRPxO, even if half their claims are exaggerated, still represents another group exploiting the signature gap.

You can’t win a race where the other side sets the pace.

FileSure Blocks Ransomware Before It Encrypts Anything

FileSure Defend operates at the Windows kernel level via a filter driver. It intercepts file operations — open, read, write, delete, create, rename — before they complete. You define rules: which users, which programs, which machines can perform which operations on which files.

A typical ransomware prevention rule:

  • File name filter: * (all files)
  • Operations: Write, Rename/Move
  • Programs excluded: Authorized backup software, approved applications
  • Drive type: Hard drives, network drives, removable drives
  • Result: Unauthorized programs cannot write or rename files. Ransomware payload lands via phishing email, tries to encrypt files, and every write operation is blocked at the kernel level.

The ransomware never executes its encryption routine because it can’t write the encrypted files to disk. Your files are never touched. No signature required. No waiting for a vendor update. Works on ransomware variants that appeared this morning the same way it works on ones from five years ago.

For organizations dealing with bulk encryption attempts that bypass initial prevention, FileSure also supports threshold-based detection:

  • Threshold: 20 file modifications within 60 minutes
  • Result: Normal user activity (saving documents, editing spreadsheets) stays well below 20 operations per hour. Ransomware modifying hundreds of files per minute crosses the threshold within seconds. Subsequent operations are blocked. Damage is contained to the files modified before the threshold fired.

The Real Defense Is Controlling What’s Allowed

The article quotes NCC’s Matt Hull: “Getting the fundamentals right remains incredibly important: strong identity and access controls, good vulnerability management, visibility across your environment and the ability to detect and respond quickly.”

That’s all true. But there’s a more fundamental control: deciding what programs are allowed to do to your files in the first place.

FileSure doesn’t try to recognize ransomware. It doesn’t chase signatures. It doesn’t depend on AI-enhanced detection keeping pace with AI-generated attacks. It controls file operations at the kernel level, on every Windows system you have — including legacy systems that modern endpoint tools won’t even install on.

Whether the attack came from The Gentlemen, CRPxO, Jadepuffer, or a group that doesn’t exist yet, the mechanism is the same. Control the mechanism, and you stop the attack.

Ready to stop playing whack-a-mole with ransomware signatures? Start a free 21-day trial of FileSure Defend at bystorm.com. Full functionality, no credit card required. See it block a simulated ransomware attack in under three minutes.


Source: Ransomware attack volumes hit ‘high-water-mark’ in July | Computer Weekly

Category: Ransomware

Tags: ransomware, the gentlemen, jadepuffer, ai ransomware, kernel filter driver, file system security, zero-day protection, crpxo

Gene Allen

Written by

Gene Allen

Gene Allen is a Windows file security expert with over 20 years of experience developing kernel-level solutions that protect enterprise data from ransomware, unauthorized access, and data loss. As founder of ByStorm Software, he architected FileSure — a patented file auditing and security platform trusted by 200+ organizations across healthcare, financial services, and government. Gene holds two U.S. patents in file system security and access control.

Ready to protect your organization?

Start your free 21-day trial today. No credit card required.

Start Your Free 21-Day Trial