Ransomware Attacks Surge 55% Across Europe in Early 2026, Black Kite Report Finds
A new report from cyber risk management firm Black Kite reveals a sharp rise in ransomware attacks targeting European organizations, with incidents increasing by 55.1% year-over-year in the first four months of 2026. The analysis, based on publicly disclosed incidents, recorded an average of 171 attacks per month, as detailed in the company’s 2026 European Cyber Risk Report, published on June 25.
Five countries bore the brunt of the attacks, accounting for 70% of all incidents: Germany (18%), the UK (17%), France (12%), Italy (12%), and Spain (10%). The Qilin ransomware emerged as the most prolific strain, responsible for 372 recorded attacks across 26 of the 31 countries analyzed more than double the next most common variant, Akira (159 incidents). SafePay ransomware, however, showed a targeted focus on Germany, particularly in industrial hubs like the Ruhr Valley and Bavaria, where manufacturing firms were heavily impacted.
Manufacturing was the hardest-hit sector, representing 28% of all ransomware incidents in Europe. The report highlighted the Jaguar Land Rover (JLR) attack in 2025 as a case study in the far-reaching consequences of such breaches, which forced 30,000 employees to reset passwords and became the costliest cyber incident in UK history.
Black Kite’s Chief Research and Intelligence Officer, Dr. Ferhat Dikbiyik, attributed the surge to three converging factors: accelerating ransomware activity, supply chain vulnerabilities, and stricter regulatory scrutiny on third-party risk. The report noted that over 30 ransomware incidents were linked to the August 2025 compromise of Swedish software supplier Miljödata, underscoring how cybercriminals increasingly exploit supply chain weaknesses to amplify their impact.
The findings emphasize that downstream effects where a single breach cascades through interconnected networks are now a defining feature of major ransomware campaigns. Researchers stressed the need for organizations to map risk concentration and monitor threat propagation to build resilience.
Source: https://www.infosecurity-magazine.com/news/increase-ransomware-europe/
Maple ITES Inc. cybersecurity rating report: https://www.rankiteo.com/company/maple-ites-inc
"id": "MAP1782398329",
"linkid": "maple-ites-inc",
"type": "Cyber Attack",
"date": "1/2026",
"severity": "100",
"impact": "5",
"explanation": "Attack threatening the organization's existence"
{'affected_entities': [{'industry': 'Manufacturing/Automotive',
'location': 'UK',
'name': 'Jaguar Land Rover (JLR)',
'type': 'Corporation'},
{'industry': 'Manufacturing',
'location': 'Ruhr Valley and Bavaria, Germany',
'type': 'Manufacturing firms'},
{'industry': 'Technology',
'location': 'Sweden',
'name': 'Miljödata',
'type': 'Software Supplier'}],
'attack_vector': 'Supply chain vulnerabilities',
'data_breach': {'data_encryption': 'Yes (ransomware-related)'},
'date_publicly_disclosed': '2026-06-25',
'description': 'A new report from cyber risk management firm Black Kite '
'reveals a sharp rise in ransomware attacks targeting European '
'organizations, with incidents increasing by 55.1% '
'year-over-year in the first four months of 2026. The analysis '
'recorded an average of 171 attacks per month, with five '
'countries (Germany, UK, France, Italy, Spain) accounting for '
'70% of all incidents. Manufacturing was the hardest-hit '
'sector, and the Qilin ransomware strain was the most '
'prolific.',
'impact': {'financial_loss': 'Costliest cyber incident in UK history (JLR '
'attack)',
'operational_impact': 'Forced 30,000 employees to reset passwords '
'(JLR attack)'},
'lessons_learned': 'Downstream effects of supply chain vulnerabilities are a '
'defining feature of major ransomware campaigns. '
'Organizations need to map risk concentration and monitor '
'threat propagation to build resilience.',
'motivation': 'Financial gain',
'post_incident_analysis': {'root_causes': ['Supply chain vulnerabilities',
'Accelerating ransomware activity',
'Stricter regulatory scrutiny on '
'third-party risk']},
'ransomware': {'data_encryption': 'Yes',
'ransomware_strain': ['Qilin', 'Akira', 'SafePay']},
'recommendations': 'Monitor third-party risk, enhance supply chain security, '
'and implement robust incident response plans.',
'references': [{'date_accessed': '2026-06-25',
'source': 'Black Kite 2026 European Cyber Risk Report'}],
'title': 'Ransomware Attacks Surge 55% Across Europe in Early 2026',
'type': 'Ransomware'}