A report published on June 25, 2026, by third-party cyber risk firm Black Kite reveals a dramatic escalation in ransomware activity across Europe. In the first four months of 2026, publicly disclosed ransomware incidents surged by 55.1% compared to the same period in the previous year, averaging 171 attacks per month. The report, titled "2026 European Cyber Risk Report," identifies a heavy concentration of attacks in Western Europe, with Germany, the UK, France, Italy, and Spain collectively representing almost 70% of all victims. The manufacturing industry bore the brunt of these attacks, accounting for 28% of incidents. The Qilin ransomware gang was named the most active threat actor, while the SafePay group demonstrated a highly targeted campaign against German organizations. The findings point to supply chains as a primary attack vector and underscore the growing pressure on organizations from regulations like NIS2 and DORA.
The report paints a picture of a rapidly intensifying and evolving ransomware landscape in Europe. Key trends include:
While the report focuses on statistics rather than technical details, the trends align with common ransomware TTPs. The emphasis on supply chain attacks suggests threat actors are increasingly using techniques like T1199 - Trusted Relationship to compromise smaller, less secure suppliers to gain access to larger, primary targets. This is often more effective than attempting to breach the hardened perimeter of a large enterprise directly.
The core of any ransomware attack is T1486 - Data Encrypted for Impact. Modern groups like Qilin and Akira also heavily employ double extortion tactics, which involves data exfiltration (T1567.002 - Exfiltration Over Web Service: Exfiltration to Cloud Storage) before encryption. The threat of publishing stolen data on a leak site adds immense pressure on victims to pay.
The high volume of attacks suggests the widespread use of the Ransomware-as-a-Service (RaaS) model, where developers lease their malware to affiliates who carry out the attacks. This model lowers the barrier to entry and allows for a massive scaling of operations, contributing to the observed surge.
The 55% surge in ransomware attacks has profound economic and operational impacts across Europe.
Security teams may want to hunt for the following general ransomware precursor patterns:
process_namepowershell.exe, wmic.exe, vssadmin.execommand_line_patternvssadmin.exe delete shadows /all /quietnetwork_traffic_patternLarge outbound data transfersevent_id4625 (Windows Security Log)D3-DTP - Domain Trust Policy)D3-MFA - Multi-factor Authentication)D3-SU - Software Update)Analysis of the Black Kite report emphasizes a strategic pivot by ransomware groups to target third-party suppliers and IT service providers for supply chain attacks.
This update provides further analysis of the Black Kite report, highlighting the strategic shift by ransomware groups to compromise third-party suppliers and IT service providers as a primary vector for supply chain attacks. New hunting hints include monitoring VPN logs, psexec.exe usage, and unusual RDP/SMB traffic. Additional mitigation advice emphasizes implementing the principle of least privilege. The report reinforces the 55.1% surge in European ransomware attacks and the continued prominence of the Qilin group, offering a slightly different perspective on the same core findings.
UK authorities launch 'Don't Pay' campaign as ransomware attacks spike, with 323 incidents reported to City of London Police between April 2025 and March 2026, predominantly affecting SMEs and manufacturing.
New data from the City of London Police reveals 323 ransomware incidents reported by UK organizations, primarily SMEs and the manufacturing sector, between April 2025 and March 2026. This represents a 50% year-on-year increase in reported losses. In response, UK authorities have launched a 'Don't Pay' campaign, advising businesses against paying ransoms due to risks like non-recovery, funding criminals, and potential legal repercussions under UK GDPR, Terrorism Act, and sanctions. The campaign emphasizes proactive measures like robust backups, MFA, patch management, and incident response planning.
Q2 2026 report confirms manufacturing as top ransomware target, Qilin's continued dominance, and Europe's escalating threat with 66.6% YoY increase.
A ZeroFox Q2 2026 report updates ransomware trends, confirming manufacturing as the primary target due to high operational downtime costs. The Russian-language Qilin group maintained its position as the most active threat actor for the fourth consecutive quarter, responsible for 295 incidents in Q2. While overall attacks saw a slight 8.5% quarterly decrease, the year-over-year figures show a significant 50.7% increase globally, indicating a sustained long-term growth trend. Europe is highlighted as a rapidly growing target region, experiencing a 66.6% year-over-year increase in incidents, reinforcing its escalating threat landscape. The report also identifies other active groups like The Gentlemen, DragonForce, Akira, and LockBit.
Black Kite publishes its '2026 European Cyber Risk Report' detailing the surge in ransomware attacks.

Cybersecurity professional with over 10 years of specialized experience in security operations, threat intelligence, incident response, and security automation. Expertise spans SOAR/XSOAR orchestration, threat intelligence platforms, SIEM/UEBA analytics, and building cyber fusion centers. Background includes technical enablement, solution architecture for enterprise and government clients, and implementing security automation workflows across IR, TIP, and SOC use cases.
CyberNetSec.io uses automation to assist source monitoring, deduplication, observable extraction, and structured intelligence generation. Published analysis follows human-defined editorial standards and adds defensive context including MITRE ATT&CK, D3FEND, STIX, and Sigma where applicable. Read our editorial policy.
Help others stay informed about cybersecurity threats
Every tactic, technique, and sub-technique used in this threat has been identified and mapped to the MITRE ATT&CK framework for consistent, actionable threat language.
Observables and indicators of compromise (IOCs) have been extracted and cataloged. Risk has been assessed and correlated with known threat actors and historical campaigns.
Detection rules, incident response steps, and D3FEND-aligned mitigation strategies are included so your team can act on this intelligence immediately.
Structured threat data is packaged as a STIX 2.1 bundle and can be visualized as an interactive graph — relationships between actors, malware, techniques, and indicators.
Sigma detection rules are derived from the threat techniques in this article and can be converted for deployment across any major SIEM or EDR platform.