Ransomware in 2026: trends, tactics and how to protect yourself
Ransomware in 2026: encryption-free extortion, RaaS fragmentation after LockBit's takedown and supply-chain attacks. Verified data and practical defence.

On this page
2026: the year of industrialised extortion
Ransomware in 2026 no longer resembles that of 2021. The groups that run it have professionalised to the point of adopting structures reminiscent of SaaS providers — with "customer support" to negotiate payment, affiliate programmes and profit-sharing — and have widely adopted double, and in the most aggressive cases triple, extortion: data encryption, public leaking if payment isn't made and, at the harshest end, DDoS attacks or direct contact with the victim's customers and employees to maximise pressure [1][3].
This article updates our trend analysis with verifiable data from primary sources — ENISA, Coveware/Veeam, CCN-CERT, Sophos and the Verizon DBIR — and replaces figures that in the previous version we could not trace to a public source with corroborated data, or with generic, figure-free wording where the underlying data depends on internal information not yet consolidated.
What the verified 2026 data shows
According to ENISA's Threat Landscape 2025 report, which analyses 4,875 incidents recorded between July 2024 and June 2025, ransomware remains the most impactful cybercrime tool in the EU, present in 81.1% of the cybercrime incidents analysed, although volume fell 11% compared with the previous period — a figure that should be read alongside the rise of encryption-free extortion, which is not always counted as "classic" ransomware [1].
In the same period, 82 active ransomware variants were identified targeting EU organisations, with Akira (11.6%), SafePay (10.1%) and Qilin (7.5%) the most widely deployed [1]. In the manufacturing sector, traditionally one of the hardest hit, Akira, Qilin and FOG together account for 79.5% of attacks with an identified ransomware strain [1].
On the economic impact, Coveware's (now part of Veeam) quarterly reports document strong volatility in ransom payments, largely explained by one-off operations targeting specific sectors such as law firms. This volatility reflects the operational reality: average payments are skewed by a small number of highly targeted attacks, while most actual payments are more modest [2]. The overall trend shows a decline in the global share of organisations that actually pay following an attack, and among exfiltration-only attacks (without encryption), only a minority of victims end up paying [2].
In Spain, CCN-CERT confirms in its trend report that the double- and triple-extortion model has become the dominant one in 2025-2026. Spanish organisations have recorded a marked increase in threat activity in recent years, according to industry sources [3]. CCN-CERT itself documents how, following LockBit's disruption, affiliates have redistributed towards RansomHub, Play, Akira, 8Base and new brands that emerged in 2025-2026 [3].
Key trends
1. Supply-chain attacks
The most relevant pattern remains the compromise of managed service providers (MSPs) and monitoring software: a single entry point is amplified across dozens or hundreds of end clients. The precedent that set the trend — the 2021 Kaseya attack — remains the industry's reference case; what we observe in 2026 is the mature version of that same pattern, now also targeting cloud and identity providers.
2. Fragmentation of ransomware-as-a-service (RaaS)
The international police operation Operation Cronos, led by the UK's National Crime Agency together with the FBI, Europol and agencies from other countries, seized control of LockBit's infrastructure in February 2024 [9]. This was followed by the FBI's disruption of ALPHV/BlackCat that same year. The result has not been the disappearance of ransomware as a business, but its fragmentation: affiliates redistributed towards smaller, more agile groups — RansomHub, Play, Akira, 8Base, among others — that rebrand frequently to make tracking by law enforcement harder [3][9].
3. Encryption-free extortion
Encrypting a victim's systems takes time, leaves clear forensic artefacts and triggers EDR alerts fairly readily. Exfiltrating data and threatening to publish it is faster, cheaper to operate and harder to detect with traditional tools focused on encryption. Coveware documents how groups such as Silent Ransom, and collectives linked to Scattered Spider, use social engineering against the help desk to gain direct access to SaaS accounts, without needing to deploy malware — a vector that classic backup and recovery tools are not designed to stop [2].
4. AI-assisted social engineering
The Verizon 2026 DBIR confirms a significant shift in pattern: the report notes that mobile devices show click-through rates 40% higher than traditional email phishing vectors, and documents growing use of pretexting (the attacker poses as a support agent, a supplier or IT staff and guides the victim in real time towards a damaging action) as a social-engineering technique preceding ransomware and extortion attacks [14]. Combined with the use of LLMs to generate personalised context about the victim (LinkedIn profiles, prior breaches), social engineering is undergoing significant changes in its effectiveness, although the exact combined impact of GenAI in this area is not yet backed by consolidated figures from independent sources.
Dominant entry vectors (2026 DBIR data)
The Verizon 2026 DBIR marks a turning point: for the first time in the report's 19-year history, vulnerability exploitation overtook credential abuse as the most common initial access vector, reaching 31% of the breaches analysed [14], versus 13% for credential abuse [14]. Ransomware, overall, appears in 48% of the breaches Verizon analysed globally (up from 44% in the previous report) [14].
The operational takeaway is clear: vulnerability management and patching of exposed devices (VPNs, firewalls, edge appliances) have become, alongside credential control, the first line of defence — ahead, even, of email filtering.
Regulatory framework: what is changing (and what isn't) in Spain
- ENS (Real Decreto 311/2022): for Spanish public administrations and their suppliers, the Esquema Nacional de Seguridad (ENS, Spain's National Security Framework) remains the mandatory reference framework, with specific continuity and recovery measures that are directly applicable against a ransomware incident [11].
- DORA (Regulation (EU) 2022/2554): for financial entities, DORA has been in full application since 17 January 2025, with serious cybersecurity incident-notification obligations that explicitly include ransomware attacks [12].
- NIS2: the Directive (EU) 2022/2555 (NIS2) has applied at EU level since October 2024, but Spain has not completed its national transposition. According to press sources, the draft Cybersecurity Coordination and Governance Bill (Anteproyecto de Ley de Coordinación y Gobernanza de la Ciberseguridad) was approved by the Council of Ministers on 14 January 2025; as of this update, it remains in parliamentary procedure. The exact status of the process can be confirmed via the initiatives search tool at congreso.es. In any case, until the national law enters into force, Spanish entities not already subject to ENS or DORA do not yet have a ransomware incident-notification regime fully enforceable to the standard of NIS2 — which does not reduce the operational risk, nor is it a reason to postpone preparation.
Defence strategy for 2026
Layer 1 — Prevention
- Phishing-resistant MFA: CISA explicitly recommends FIDO2/WebAuthn or PKI-based standards over SMS or TOTP codes, which remain vulnerable to adversary-in-the-middle proxies [6].
- Vulnerability management on edge devices: since vulnerability exploitation is now the most frequent initial access vector, the patching cycle for VPNs, firewalls and exposed appliances must be measured in hours, not weeks [14].
- Privileged identity management: PAM with session recording and periodic review of elevated-privilege access.
- Email security and anti-pretexting training: DMARC in enforced mode, attachment sandboxing and specific training against fraudulent help-desk calls, not just phishing emails.
Layer 2 — Detection
- EDR with response capability deployed across all endpoints, including servers — not just user workstations.
- Network telemetry: NDR or, at minimum, visibility of east-west traffic within the perimeter itself.
- Honeytokens in Active Directory and code repositories, particularly useful against the silent reconnaissance that precedes exfiltration.
Layer 3 — Response
- Validated ransomware runbook, tested through tabletop exercises at least twice a year.
- Backups following the 3-2-1-1-0 rule: three copies, two different types of media, one off-site copy, one immutable or air-gapped copy, and zero errors verified through real restore testing [13]. The immutable copy is what makes the difference against an attacker who already operates with administrator privileges — the typical scenario in a modern ransomware incident.
- Pre-drafted communications for customers, regulators and employees, reviewed with the legal team before the incident happens, not during it.
The question every security lead must be able to answer immediately: "If we detect encryption across 300 endpoints this afternoon, how many hours until we're operating at 80% capacity?" If the answer isn't immediate and measurable with data from a real exercise, the continuity plan isn't ready.
Practical steps for the next four weeks
- Inventory internet-exposed edge devices (VPNs, firewalls, remote-access portals) and confirm they're on the latest vendor-supported version.
- Migrate MFA for privileged accounts (domain administrators, backup access, cloud console) to FIDO2/WebAuthn, following CISA's guidance [6].
- Verify that at least one backup copy is immutable and run a documented test restore within the next two weeks.
- Review the help-desk protocol for phone-based MFA or password reset requests — a critical social-engineering vector that the 2026 DBIR documents as growing [14].
- Update the ransomware runbook to explicitly incorporate the encryption-free exfiltration scenario, which requires a different response protocol (focused on breach communication, not system recovery).
- Confirm with your cyber-insurance broker which exclusions apply in the event of payment and what documentation is required before an incident is covered.
To pay or not to pay?
The official position of the authorities is unanimous: do not pay. INCIBE states it without nuance — "do not pay the ransom under any circumstances" — and points to the No More Ransom platform, developed by Europol and the Dutch police, as the first port of call for cost-free recovery [7][8]. The FBI and CISA in the US maintain the same recommendation.
The operational reality, however, is more nuanced and worth knowing with data:
- Paying does not guarantee full recovery. According to Sophos, paying the ransom is no guarantee of complete data recovery — a significant operational risk that must be weighed when making this decision [4].
- Paying does not prevent the leak in a significant proportion of double/triple-extortion cases: payment halts publication, but does not remove the copy the attacker has already exfiltrated.
- Paying can trigger OFAC sanctions risk if the group receiving payment is on the US Treasury's Specially Designated Nationals (SDN) sanctions list — the Treasury Department expects organisations to take "meaningful steps" on defence before considering payment as a last resort, and views early notification to the authorities favourably as a mitigating factor [5].
- Cyber-insurance coverage for ransom payments is becoming increasingly restrictive and, under most current policies, requires prior evidence of minimum controls (MFA, backup, EDR) for cover to apply.
Conclusion
Ransomware in 2026 is a mature business in full reconfiguration: the takedown of major operators such as LockBit and ALPHV has not reduced the risk, it has fragmented it across smaller, harder-to-track actors, while vulnerability exploitation overtakes phishing as the main entry point. Defending against it requires the same maturity the attacker brings: an EDR and an isolated backup copy are not enough. What's needed is a programme that combines vulnerability management, identity control, detection with response capability and a continuity plan tested through real exercises — and, for Spanish public administrations and financial entities, aligned with the obligations already in force under ENS and DORA, without waiting for NIS2's transposition to complete its parliamentary journey. Organisations that treat ransomware as a recurring operational risk — not an isolated incident — will be the ones best placed to withstand the next attack.
Sources
- [1] ENISA, Threat Landscape 2025 (octubre 2025) — https://www.enisa.europa.eu/sites/default/files/2026-01/ENISA%20Threat%20Landscape%202025_v1.2.pdf
- [2] Coveware by Veeam, Ransomware Payment Trends Q2 2026 — https://www.veeam.com/blog/cyber-extortion-payment-trends-q2-2026.html
- [3] CCN-CERT (CNI), Ciberespionaje, hacktivismo y ransomware: tácticas, técnicas y procedimientos de las principales ciberamenazas — https://www.ccn-cert.cni.es/es/seguridad-al-dia/novedades-ccn-cert/13034-ciberespionaje-hacktivismo-y-ransomware-el-ccn-cert-advierte-de-las-tacticas-tecnicas-y-procedimientos-de-las-principales-ciberamenazas.html
- [4] Sophos, The State of Ransomware 2025 — https://www.sophos.com/en-us/press/press-releases/2025/06/nearly-half-companies-opt-pay-ransom-sophos-report-finds
- [5] U.S. Department of the Treasury, OFAC, Updated Advisory on Potential Sanctions Risks for Facilitating Ransomware Payments (21 sept. 2021) — https://ofac.treasury.gov/recent-actions/20210921
- [6] CISA, Implementing Phishing-Resistant MFA (fact sheet) — https://www.cisa.gov/sites/default/files/publications/fact-sheet-implementing-phishing-resistant-mfa-508c.pdf
- [7] INCIBE, Ransomware: no pagues un rescate por tu información — https://www.incibe.es/protege-tu-empresa/blog/tematicas-ransomware-no-pagues-rescate-tu-informacion
- [8] No More Ransom (Europol / Politie Países Bajos) — https://www.nomoreransom.org/
- [9] Europol, LockBit power cut: four new arrests and financial sanctions against affiliates — https://europol.europa.eu/media-press/newsroom/news/lockbit-power-cut-four-new-arrests-and-financial-sanctions-against-affiliates
- [10] Comisión Europea, Commission refers Ireland, Spain, France and the Netherlands to the Court of Justice for failing to transpose the rules on cybersecurity (8 julio 2026) — https://ec.europa.eu/commission/presscorner/detail/en/ip_26_1499
- [11] Real Decreto 311/2022, de 3 de mayo, por el que se regula el Esquema Nacional de Seguridad (BOE) — https://www.boe.es/eli/es/rd/2022/05/03/311
- [12] Reglamento (UE) 2022/2554 del Parlamento Europeo y del Consejo (DORA) — EUR-Lex — https://eur-lex.europa.eu/legal-content/ES/TXT/?uri=CELEX:32022R2554
- [13] Veeam Community, The 3-2-1-1-0 Rule in Practice: How to Actually Implement It with Veeam — https://community.veeam.com/blogs-and-podcasts-57/the-3-2-1-1-0-rule-in-practice-how-to-actually-implement-it-with-veeam-12799
- [14] Verizon, Data Breach Investigations Report 2026 (síntesis vía Help Net Security) — https://www.helpnetsecurity.com/2026/05/20/verizon-2026-dbir-findings/
Does NIS2 apply to you?
Self-check your NIS2 scope (essential/important/out) and which directive domains you already cover, in 2 minutes.
Was this article useful?
Gorka Gonzalo
Founder & CEO
Founded Hodeitek in 2023 and runs the company. A cybersecurity and AI expert, he sets the technical and product direction of HodeiShield and personally leads the most critical engagements.
Need help with this?
Schedule a free consultation with our team and see how to apply it to your organization.
Schedule free consultation