Ransomware in Europe 2026: What the New Numbers Mean for Switzerland

Stefan Röthlisberger
Founder & CEO, IRONATE
A new cyber risk report focused exclusively on Europe delivers a remarkable data foundation: 2,066 publicly known ransomware incidents across 31 countries over 16 months (source: 2026 Europe Cyber Risk Report, Black Kite). The core message is uncomfortable: ransomware is accelerating, it is concentrating, and it increasingly reaches organizations through their suppliers. This article puts the numbers in context and translates them into the perspective of Swiss companies.
An acceleration, not a gradual climb
The real finding is not the total, but its shape over time. The report splits the reporting period into three phases: 648 incidents in the first half of 2025, 734 in the second half, and already 684 in the first four months of 2026 alone. Because that last phase covers only four months instead of six, the monthly average is the more honest metric, and it jumps: from 108 incidents per month (H1 2025) to 122 (H2 2025) to 171 (January through April 2026).
In the direct year-over-year comparison, January through April 2026 against January through April 2025, the increase is 55.1%. The report aptly describes the curve as a "recent step up rather than a gradual climb": an abrupt shift, not a slow swell.
This shape matters more for defense than any single number. A threat that doubles calls for a different response than one that tips abruptly. Experience in the Swiss market matches the picture: the Swiss Federal Office for Cybersecurity (BACS/NCSC) likewise reports a persistently high, increasingly targeted and complex threat level for 2025.
Geography: the threat concentrates instead of spreading
One might assume that more incidents also mean a wider spread. The opposite is true. Five countries, Germany, the United Kingdom, France, Italy and Spain, account for 68.5% of all incidents in the full period. In early 2026 that share even rose to 71.2% (versus 68.7% in the same window of 2025). Roughly three quarters of the additional incidents in 2026 fell on precisely these "Big Five". Germany leads with 370 incidents (17.9%).
For Switzerland, the regional reading is decisive. The report groups Germany, Austria and Switzerland into the DACH region, one of the most active in Europe with 511 incidents. The most striking group there is SafePay, a specialist that directs 56.7% of its activity at Germany. Anyone based in the DACH region does not sit at the edge of events, but at their center.
Switzerland in detail: 80 incidents and the Radix case
The 80 Swiss incidents from the report cover only publicly known cases. BACS paints a complementary picture from its own reports: over the full year 2025, 104 voluntary ransomware reports came in (versus 92 in 2024). In the second half of 2025, 57 ransomware incidents were registered under the new reporting obligation for critical infrastructures, around 9% of all reportable incidents. The dominant group in Switzerland was Akira, whose activity intensified further in the second half of the year, among other things through exploited SonicWall vulnerabilities (CVE-2024-40766) for which the vendor patch had not been applied consistently.
The most memorable Swiss case of 2025 shows the supplier pattern in miniature: the Radix foundation, which provides services to several federal agencies, was hit by the Sarcoma group. Around 1.3 TB of stolen data was published on the leak site on June 29, 2025, including data from the federal administration, even though the attackers never had direct access to federal systems. The damage ran through a service provider. We dedicate a separate article to this mechanism: supply chain ransomware under NIS2, DORA and the revDSG.
In Switzerland, ransomware today is almost always coupled with data exfiltration. Paying the ransom and restoring from backup does not solve the data protection problem: a breach of data security under the revised Swiss Data Protection Act (revDSG, Art. 24) remains subject to the reporting obligation as soon as personal data has been exfiltrated.
Sectors: where ransomware strikes in Europe
The industry distribution confirms a trend we have been observing for years. Manufacturing is by far the most affected sector with 576 incidents (27.9%), followed by professional, scientific and technical services with 368 incidents (17.8%). Together, these two sectors account for 45.7% of all incidents. Notably, the 576 manufacturing incidents are spread across 78 subindustries, with not a single one exceeding 7.1%. There is no safe niche.
The most dangerous finding hides at the subindustry level: Computer Systems Design and Related Services, in other words IT service providers, is the most attacked subindustry in Europe with 5.4% of all incidents, and the trend is rising (from 27.5% to 38.4% within professional services between H1 2025 and early 2026). This is more than a statistic: an IT service provider sits, by definition, inside its customers' processes. Whoever hits it potentially hits everyone it serves.
An independent source supports the direction, albeit with a different methodology: the ENISA Threat Landscape 2025 (4,875 verified EU incidents, July 2024 through June 2025) calls ransomware the most impactful threat and ranks manufacturing first for ransomware demands at 14.9%. Public administration is ENISA's most targeted sector across all incident types at 38.2%, reflecting the high share of state-aligned espionage and hacktivist DDoS waves. The percentages from the report and from ENISA are not directly comparable (different time windows and counting methods), but the ranking matches.
The most active groups: generalists and specialists
The report distinguishes two profiles. Qilin is the generalist: 372 incidents in 26 of 31 countries, without exceeding 18.5% in any single market, widely scattered prey. Akira follows with 159 incidents. SafePay, by contrast, is the specialist: 80 European incidents, 56.7% of them in Germany.
The broader market confirms the order of magnitude. The Microsoft Digital Defense Report 2025 notes that at least 52% of all attacks with a known motive are financially driven by extortion or ransomware, versus only 4% espionage, and that attackers sought to steal data in 80% of the incidents examined. Accompanying industry data counts a record level of 124 active, named ransomware and extortion groups for 2025 (up 46% from 2024), with Qilin alone reaching around 1,044 victims globally.
| Group | Incidents (Europe) | Profile |
|---|---|---|
| Qilin | 372 | Generalist, active in 26 of 31 countries |
| Akira | 159 | Perimeter devices, leading in Switzerland |
| SafePay | 80 | Specialist, 56.7% in Germany |
Do victims still pay? The second trend
In parallel with the rising frequency, the economics are shifting. The Verizon Data Breach Investigations Report 2025 finds ransomware in 44% of all analyzed data breaches (up 37% year over year), and especially at small and midsize businesses (88% of SMB breaches versus 39% at large enterprises). At the same time, fewer and fewer victims pay: 64% of affected organizations paid no ransom (versus 50% two years earlier), and the median payment fell to around USD 115,000. Sophos confirms the direction with falling ransom demands (median down 56% to USD 1.20 million) and lower recovery costs (down 44% to USD 1.53 million).
The message is not "ransomware is easing off". It is: backups and refusing to pay work, but data theft has become the real currency of pressure. Whoever fails to detect exfiltration loses that leverage, no matter how good the backups are.
What the numbers mean for defense
Three observations from the report translate directly into architecture decisions. First: if attackers steal data in 80% of cases and disable EDR before detonation (as we showed in our analysis of EDR killers), you need an observation layer that works independently of the endpoint. Second: if Akira enters through unpatched SonicWall devices, the exposed, unpatched attack surface is the actual problem. Third: if initial access increasingly runs through compromised identities and suppliers, behavior, not just signatures, must be monitored.
Frequently asked questions
How many ransomware incidents were there in Europe in 2025 and 2026?
The report (Black Kite) documents 2,066 publicly known incidents in 31 countries between January 2025 and April 2026. The monthly rate rose from 108 (H1 2025) to 171 (Jan through Apr 2026), an increase of 55.1% over the prior-year period.
How strongly is Switzerland affected?
The report counts 80 Swiss incidents. BACS registered a total of 104 voluntary ransomware reports in 2025 (2024: 92) and 57 incidents in H2 2025 under the reporting obligation for critical infrastructures. The dominant group was Akira.
Which sector is hit hardest?
Manufacturing at 27.9% (576 incidents), followed by professional and technical services at 17.8%. The most attacked subindustry is IT service providers (Computer Systems Design, 5.4%), because as suppliers they expose numerous customers.
Why is endpoint protection alone not enough?
Modern ransomware exfiltrates data and disables endpoint protection before encryption. Lateral movement, C2 communication and data exfiltration run over network and identity. NDR, DNS filtering and UEBA provide the independent visibility that still works when the endpoint is compromised.
Which ransomware groups are most active in Europe?
Qilin (372 incidents, 26 of 31 countries), Akira (159) and SafePay (80, of which 56.7% in Germany). In Switzerland, Akira dominated, among other things via unpatched SonicWall vulnerabilities.
summarize Summary / Key Takeaways
- check_circleThe analyzed Europe Cyber Risk Report (source: Black Kite) counts 2,066 ransomware incidents in 31 countries (Jan 2025–Apr 2026), with an increase of 55.1% in early 2026.
- check_circleThe threat is concentrating: five countries account for 68.5% of the incidents, the DACH region counts 511. Switzerland records 80 incidents.
- check_circleManufacturing (27.9%) and professional services (17.8%) are hit hardest; IT service providers are the most attacked subindustry and a systemic supply chain risk.
- check_circleIn Switzerland, Akira dominated via unpatched SonicWall devices; the Radix case shows the supplier pattern. Data exfiltration keeps incidents subject to the reporting obligation even with backups in place (revDSG).
- check_circleDefense needs visibility beyond the endpoint: NDR, DNS Shield, UEBA and RECON cover network, DNS, identity and attack surface.
Sources & References
- • Black Kite: 2026 Europe Cyber Risk Report, blackkite.com/report/2026-europe-cyber-risk-report (Volume, Geography, Sectors, Methodology)
- • Black Kite / PR Newswire (June 2026): "Ransomware Incidents Rose 55% Year-Over-Year in Early 2026", prnewswire.com
- • Help Net Security: Black Kite European Cyber Threats Report, helpnetsecurity.com
- • BACS/NCSC (Swiss Federal Office for Cybersecurity): Halbjahresbericht 2025/2 (semi-annual report), ncsc.admin.ch
- • BleepingComputer: "Switzerland says government data stolen in ransomware attack" (Radix / Sarcoma), bleepingcomputer.com
- • ENISA Threat Landscape 2025, enisa.europa.eu
- • Microsoft Digital Defense Report 2025, blogs.microsoft.com
- • Verizon 2025 Data Breach Investigations Report, verizon.com
- • Sophos: The State of Ransomware 2025, sophos.com
See what is really happening on your network
IRONATE NDR, DNS Shield, UEBA and RECON deliver the detection and visibility layers against modern ransomware. Swiss sovereignty, on-premises, compliant with the Swiss Data Protection Act (FADP).
Request a free consultation arrow_forward