The ransomware threat in 2026 has reached a new level: between July 2024 and June 2025, the BSI (Germany's Federal Office for Information Security) registered around 950 ransomware attacks on German companies and public authorities - and roughly 80 percent of them hit small and medium-sized enterprises. Anyone who believes that as a craft business, tax firm or machine builder in Leipzig they are too small for cybercriminals is dangerously mistaken. It is precisely these SMEs that are the preferred target today.
The reason is coolly economic: mid-sized companies often hold valuable data and solvent accounts, but rarely have a dedicated security team. Attacker groups such as Qilin and Akira have industrialized their methods in 2026. In this article, we show what the current threat landscape looks like, which entry points criminals exploit and which measures effectively protect your company.
The 2026 ransomware threat in numbers
The data is unambiguous. According to the Bitkom study "Wirtschaftsschutz 2025" (Economic Protection 2025), the German economy suffers total annual damage of around 289 billion euros from cyberattacks, data theft, espionage and sabotage. Roughly 202 billion euros of that stems directly from cyberattacks. 87 percent of all surveyed companies were affected within twelve months, and the share of companies hit by ransomware rose from 12 percent (2022) to 34 percent today.
In its most recent reporting period, the BSI registered an average of 119 new vulnerabilities per day - up 24 percent year on year. Of the 950 reported ransomware cases, 72 percent involved a data leak. So-called double extortion has thus become standard: data is not only encrypted but stolen beforehand, with the threat of publication.
For SMEs, this development is especially dangerous because it combines two levers. Even if a company can restore its data from backup and thus theoretically does not have to pay, it still faces the publication of sensitive customer, employee or business data. On top of the operational downtime, this puts reputational damage and a possible GDPR fine on the table. It is exactly this double pressure that the extortionists count on. Three quarters of all German companies with more than ten employees reported in the Bitkom survey that they had been attacked in the past year - so the question is no longer whether a company will be targeted, but when.
Qilin and Akira: the most active groups
In the first half of 2026, one group dominates the statistics: Qilin. Since its launch in October 2022, the ransomware-as-a-service platform has claimed more than 1,800 victims, over 500 of them in 2026 alone. In April 2026, with 128 victims in 30 days, Qilin accounted for around 15 percent of the total monthly volume. In June 2026, the group reported 18 new victims from the manufacturing and energy sectors within 24 hours.
Akira is also highly active. This group has specialized in abusing VPN access. Particularly critical: Akira exploits the SonicWall vulnerability CVE-2024-40766 and enters via SonicWall devices in 86 percent of confirmed Akira cases. The dwell time in the network is often just hours - in some cases less than an hour passes between initial access and encryption. On June 19, 2026, for instance, the German logistics company Berg Lilly became known as an Akira victim.
The short dwell time poses a particular challenge for SMEs. Classic detection, which relies on weeks of observing suspicious activity, no longer works here. When less than 60 minutes pass between the first successful login via a vulnerable VPN and network-wide encryption, there is hardly any time to react. That makes it all the more important to close the entry points from the outset instead of hoping to track down an attacker after the fact. Healthcare also remains a preferred target: Qilin alone counted over 168 confirmed victims in this sector by June 2026. In Germany, recent victims include the healthcare service provider Unimed, where at least 120,000 people were affected, including 54,000 patients of university hospitals in Baden-Württemberg.
How the attackers get into the network
The typical entry points have not fundamentally changed in 2026, but they are being exploited more professionally. Knowing them means you can close them deliberately:
- Unpatched VPN gateways and firewalls (such as SonicWall, unsecured remote access)
- Stolen or weak credentials without multi-factor authentication
- Phishing emails, increasingly AI-generated and barely recognizable as fakes
- Outdated, publicly reachable systems without current security updates
- Compromised service providers and supply chains as indirect access
The BSI has declared 2026 the "year of attack surface management": companies should inventory, assess and continuously monitor all reachable systems - from the cloud to the production line. What is not known cannot be protected.
Effective protective measures for SMEs
The good news: most attacks can be fended off with consistently applied basic measures. It does not take an enterprise budget - it takes discipline and clear responsibilities.
Actionable right away
- Multi-factor authentication on all external access points and email accounts
- Fast, documented patch management for VPN, firewall and servers
- Immutable backups kept separate from the network
- Network segmentation so an infection does not paralyze the entire company
- Regular, hands-on employee training against phishing
A tested emergency plan is also crucial. Anyone who knows in an emergency whom to call, which systems to isolate first and how to restore the backup shortens downtime from days to hours. It is exactly this preparation that determines whether an attack is a manageable incident or an existential threat.
Why SMEs in particular stand to benefit
A common misconception is that effective security is only possible with big budgets and a dedicated security team. The opposite is true: the measures with the greatest protective effect - MFA, patches, separated backups - are comparatively inexpensive and quick to implement. Studies show that companies with a lived zero-trust practice record around 50 percent fewer security incidents and respond to incidents significantly faster. For a Leipzig-based mid-sized company, this means the risk of an existence-threatening incident can be drastically reduced with manageable effort.
Getting the order right matters. Start with the measures that block the attackers' most common routes and build on them step by step. An external assessment helps close the biggest gaps first instead of getting lost in details. The result is a realistic roadmap that fits the company's budget and size.
Conclusion
The ransomware threat of 2026 is hitting SMEs with full force. Groups like Qilin and Akira operate in a highly professional, fast and automated manner. But the situation is not hopeless: MFA, clean patch management, immutable backups and trained employees close the most important entry points. In 2026, cybersecurity is no longer an IT project - it is a matter of business survival.
Want to know where your company is truly vulnerable? Cryon from Leipzig audits your infrastructure, closes security gaps and sets up resilient protection against ransomware - hands-on and tailored to SMEs. Get in touch and make your company resilient.
Is your company prepared for ransomware?
We audit your IT security, harden your systems and ensure reliable backups before things get serious.

