An evaluation by Bitdefender reveals a rise in ransomware attacks claimed by cybercriminals during the first six months of 2026. Germany experienced a near-doubling of monthly reported cases between January and June. Alongside evolving attack methods, small and medium-sized businesses are increasingly targeted.

The threat posed by ransomware attacks on companies and organizations in the DACH region remains elevated. According to a recent analysis by IT security firm Bitdefender, ransomware groups claimed responsibility for 4,641 attacks globally in the first half of 2026. This represents a slight increase compared to the same period in the previous year, which recorded 4,381 incidents. Analysts identified Qilin, The Gentlemen, and Akira as the most active ransomware families worldwide.

In global rankings based on claimed incidents, Germany ranks fourth. With 176 reported attacks in the first half of 2026, the country trails the United States (1,989 cases), Canada (201 cases), and the United Kingdom (190 cases). Switzerland ranks 20th globally with 35 victims, while Austria ranks 25th with 29 recorded cases. Despite lower absolute numbers compared to the US, attacks in Switzerland and Austria frequently lead to severe operational disruptions for affected organizations.

Within Germany, claimed successful attacks grew steadily over the six-month period. While 22 successful attacks were claimed in January 2026, that number rose to 42 in June 2026.

Regarding affected industries, clear trends emerge across the DACH region. The most frequently targeted sectors include manufacturing, construction, technology, finance, and healthcare. In Germany, the distribution differs slightly: retail replaced financial services in the top five affected industries, recording ten attacks compared to five in finance.

Security experts report that the technical sophistication of attack methods continues to advance. The increased use of automated tools, infostealers, and specialized malware enables attackers to bypass Endpoint Detection and Response (EDR) mechanisms. This facilitates initial unauthorized access and the exploitation of network vulnerabilities.

Consequently, both established and emerging ransomware groups are broadening their target scopes. In addition to large enterprises, small and medium-sized enterprises (SMEs) are increasingly targeted. Supply chain attacks and exploits targeting the network edge remain significant challenges for cybersecurity teams.

To mitigate these risks effectively, experts recommend a layered defense approach. Key measures include mapping and reducing the digital attack surface and implementing robust Identity and Access Management (IAM) to prevent credential compromise. Organizations also require detection mechanisms that enable rapid response and remediation. Leveraging threat intelligence allows teams to adapt incident response strategies, while regular, integrity-tested backups ensure critical systems can be restored.

Automated tooling is driving an increase in ransomware threats. Attacks are expanding beyond large corporations to target small and medium-sized businesses. Effective defense requires proactive surface management, strict access controls, and verified backup protocols.

By Carolina Heyder

Carolina Heyder is a business analyst and moderator with extensive experience in the German and international IT market. She has worked for many years at renowned European trade publishers such as WEKA Fachmedien, Vogel IT Medien, Springer, and Aspencore. She creates content for both web and print media and is an expert in front of the microphone and camera. Thanks to her fluency in German, English, and Spanish, as well as her Chilean roots, she brings a global and intercultural perspective to topics such as cybersecurity, artificial intelligence, digital transformation, sustainability, and other key areas of the IT sector.

Leave a Reply

Your email address will not be published. Required fields are marked *

WordPress Cookie Notice by Real Cookie Banner