Skip to main content

H1 2026 Threat Landscape: The Ransomware Surge and Your Risk Posture

5 min read
CISO Daily
H1 2026 Threat Landscape: The Ransomware Surge and Your Risk Posture

The first half of 2026 has produced the highest recorded volume of ransomware activity since tracking began. Incident counts are up 30% compared to the same period in 2025, which itself was a record year. For European organisations, the increase is sharper: 55% year-on-year, with supply chains identified as the primary attack path. This briefing summarises the key findings for board and executive audiences and identifies what they mean for risk decisions over the next six months.

The Numbers in Context

Two data points anchor the scale of current activity. Qilin, the most active ransomware group in the world as of mid-2026, claimed 18 victims in a single 24-hour period on June 11. This is not an isolated spike — Qilin has accumulated an estimated 1,448 confirmed attacks over the past twelve months across energy, utilities, manufacturing, and healthcare.

NightSpire, a newer group that emerged in early 2026, claimed 175 victims across 28 industries in Q1 2026 alone. Their targeting has recently expanded to local government, adding public sector entities to a victim list previously dominated by commercial organisations. Both groups operate the standard ransomware-as-a-service (RaaS) model: a core team maintains the encryption tooling and leak site infrastructure, while a distributed network of affiliates conduct intrusions and negotiate payments.

The 30% increase in overall activity is not primarily a function of new groups entering the market. It reflects existing groups operating at higher tempo, driven by a maturing affiliate ecosystem, proven initial access broker supply chains, and the continued availability of unpatched internet-facing systems as entry points.

The European Picture

Black Kite’s first Europe-focused ransomware report, published in June 2026, documents the regional divergence from global trends. The 55% year-on-year increase across 31 European countries analysed reflects a combination of factors: NIS2 enforcement has incentivised disclosure, making actual incident counts more accurate; Qilin specifically has been linked to incidents in 26 of the 31 countries studied; and the density of interconnected supply chains in European manufacturing and logistics creates propagation paths unavailable in more fragmented markets.

For organisations subject to NIS2, this matters beyond the direct incident risk. Under NIS2, essential and important entities have 72-hour initial notification obligations and face fines of up to €10 million or 2% of global annual turnover for significant failures. Management bodies are directly liable — not just the information security function. A ransomware incident that disrupts operations for more than a few hours is likely a notifiable event under NIS2 for essential entities.

What Is Driving the Surge

Supply chain access. The European data specifically identifies supply chains as the primary attack path. This means attackers are not primarily breaking in through direct exploitation of the victim’s internet-facing systems. They are compromising a vendor, partner, or software provider first, then using that access to pivot. Organisations that have invested heavily in perimeter hardening but have limited visibility into third-party access paths face elevated residual risk.

Access broker maturity. Initial access brokers — criminal actors who specialise in gaining and selling verified footholds into corporate networks — have professionalised. KongTuke (published June 25) is a current example: a dedicated access broker deploying its own fileless backdoor tooling and selling confirmed access to Qilin, Akira, Black Basta, and others. The barrier to executing a ransomware attack is lower than ever for affiliates who can purchase rather than develop initial access.

Unpatched edge devices. Analysis of intrusion paths continues to show that unpatched VPN gateways, remote access appliances, and mail transfer agents account for a disproportionate share of initial access events. The Cisco Unified CM SSRF added to the CISA Known Exploited Vulnerabilities catalogue on June 25 is a current example of the vulnerability class.

Board-Level Implications

Insurance renewal. Underwriters are adjusting premiums and terms in response to the current activity levels. Organisations facing renewals in Q3 2026 should expect questions about MFA coverage across remote access, offline backup capabilities, and incident response retainer arrangements. Inadequate answers to any of these materially affect terms and, in some cases, coverage availability.

Risk quantification accuracy. Boards using industry-average breach costs in risk models built pre-2024 are working with figures that understate current exposure. The sustained 30% year-on-year increase compounds over the three-to-five-year investment horizons of most cyber programmes. A programme sized to historical averages is undersized for current and forward threat levels.

Third-party risk programme prioritisation. Given that supply chain access is the dominant European intrusion path, organisations whose third-party risk programmes are primarily compliance-oriented (attestation collection, questionnaire management) rather than visibility-oriented (contractual right to audit, continuous monitoring, credential hygiene requirements for vendor remote access) face a specific and currently elevated exposure.

  1. Test offline backup restoration — not just backup existence, but restoration under simulated incident conditions. The majority of organisations that paid ransom in 2025 did so because restoration was slower than they had planned, not because backups didn’t exist.

  2. Review third-party remote access — identify all vendor and partner accounts with remote access to internal systems, verify MFA is enforced for all of them, and confirm access is revocable within hours rather than days.

  3. Validate incident response playbooks — ransomware IR playbooks written before 2025 predate several current TTPs including fileless tooling, double-extortion negotiation tactics, and data exfiltration before encryption. Tabletop against a 2026 scenario.

  4. Brief the board on NIS2 notification obligations — if your organisation is subject to NIS2, ensure the board understands their personal liability under Article 20, the 72-hour notification clock, and the operational circumstances that trigger it.