Decoding the world of cybersecurity

Europe accounts for quarter of ransomware claims

NCC Group recorded 579 European ransomware victims during the second quarter, while industrial organisations, edge infrastructure, and trusted software environments remained prominent targets.

Europe accounts for quarter of ransomware claims
Summary
  • Europe accounted for 579 of NCC Group’s 2,229 recorded ransomware attacks during the second quarter.
  • Industrial organisations represented 30% of the quarterly total.
  • The review identifies corporate VPNs, internet-facing edge systems, and trusted software environments as recurring routes into organisations.

Europe accounted for more than a quarter of recorded ransomware activity during the second quarter of 2026, while industrial organisations remained the most frequently claimed victims globally.

NCC Group recorded 2,229 ransomware attacks during the quarter, up 3% from 2,165 in the first three months of the year. Its June dataset included 665 attacks, of which 153 were associated with European organisations.

Across the full quarter, Europe represented 579 attacks, or 26% of the total. North America remained the most heavily affected region with 980, although Europe’s share shows that visible ransomware exposure remains substantial outside the larger US market often reflected in criminal leak-site reporting.

Industrial organisations accounted for 30% of all recorded attacks during the quarter and 183 incidents in June. Consumer discretionary businesses and information technology followed, concentrating activity around organisations with physical operations, distributed suppliers, valuable commercial data, and limited tolerance for disruption.

Qilin was the most active named ransomware operation in NCC’s dataset for the fifth consecutive quarter, accounting for 301 victims. The group has also been connected to intrusions in which attackers exploited Palo Alto Networks GlobalProtect systems before deploying ransomware.

The figures come from NCC’s June threat review rather than an official census. Ransomware datasets commonly draw on criminal leak sites, incident intelligence, and public disclosures, so they can omit organisations that pay before publication, incidents that are never disclosed, and compromises where attribution remains unresolved.

Criminal claims may also exaggerate access, data theft, or operational impact. The dataset is best read as a measure of visible activity and recurring behaviour rather than a complete total of successful intrusions.

Industrial recovery extends beyond encrypted endpoints

NCC’s review identifies corporate virtual private networks and other internet-facing edge systems as recurring targets. These products occupy a valuable position because they must accept external traffic while providing routes to internal services once authentication or software controls fail.

Industrial organisations carry an additional recovery burden. An intrusion may interrupt scheduling, warehousing, logistics, engineering, maintenance, procurement, or production support even where operational technology is not directly encrypted. Dependencies between corporate identity, enterprise resource planning, remote access, and plant operations can convert an IT compromise into physical delay.

Supply chain compromise also features in the review. Rather than approaching every organisation independently, attackers can target development environments, trusted dependencies, managed services, or widely deployed infrastructure. A single supplier compromise may provide access, credentials, or malicious code across several customers.

European regulatory regimes increasingly require evidence that these dependencies have been identified and tested. NIS2, DORA, and national resilience frameworks place greater weight on incident management, supplier oversight, continuity, executive responsibility, and timely reporting.

A recovery plan confined to restoring encrypted workstations cannot address identity compromise, corrupted configuration, unavailable suppliers, stolen data, or loss of confidence in software and backups. Organisations need evidence on recovery time, identity restoration, manual workarounds, clean-room capability, supplier failure, and the integrity of systems returned to service.

The relatively modest 3% quarterly increase does not represent a low or stable risk. Attack volume remains high, leading operators continue to obtain access, and industrial victims remain heavily represented. Similar totals between quarters can still contain more severe individual outages and greater dependence on concentrated technology providers.

Europe’s 579 visible attacks represent hundreds of separate failures in prevention, access control, supplier assurance, or recovery, alongside an unknown number of incidents that never reached a public leak site.

×