
TicTac Cyber Security logged 1,115 European ransomware attacks in H1 2026, up 29% year over year. Business services are on pace to overtake manufacturing as the top target.
Alpha Score of 68 reflects moderate overall profile with strong momentum, strong value, weak quality, moderate sentiment.
TicTac Cyber Security recorded 1,115 ransomware attacks across Europe in the first half of 2026, a 29% increase over the same period last year. April was the worst month ever logged on the continent, with 245 attacks, and the current pace puts the year on track to close near 2,250 incidents, which would mark a third consecutive record.
The Greek cybersecurity and data recovery firm, an Acronis Platinum Partner, published the update on Aug. 11. The figures test the accuracy of its original 2025 study, which forecast that European attacks would exceed 1,746 by year-end. The year closed with 1,723 recorded attacks, putting the forecast within 98.7% of the final total.
Business services are closing in on manufacturing as Europe's most targeted sector. Manufacturing led decisively in the first quarter, with 95 attacks against 46 for business services, a nearly two-to-one margin. In the second quarter that gap flipped: business services, which include law firms, accounting practices and consultancies, recorded 137 victims versus 95 for manufacturing. Based on that trend, the research projects business services will overtake manufacturing by the end of 2026, a first since tracking began in 2023.
The leading ransomware groups have also turned over quickly. In 2023, LockBit3 alone accounted for more than one in four attacks across Europe, at 26.74%. Within two years it had effectively disappeared from the leading actors, replaced by groups such as Qilin and TheGentlemen, both of which were either unknown or nonexistent at the time. Following that pattern, the research forecasts that at least two of today's top ten groups will disappear or rebrand by mid-2027.
The analysis covers ransomware activity from January 2023 through June 30, 2026. Data was collected through the official ransomware.live API and filtered to isolate incidents affecting European countries, then categorized by sector, ransomware group and country. Only publicly reported and confirmed incidents attributed to known groups are included, so the findings represent the visible portion of ransomware activity and the true number of incidents is likely considerably higher.
TicTac Cyber Security has handled data recovery and incident response cases since 1999, with services spanning penetration testing, security assessments, NIS2 compliance and incident response. The research was conducted by Social Active, a B2B marketing and research agency, on behalf of TicTac.
Drafted by a large language model from the source reporting linked above, then screened by automated publishing checks. It is not read by a journalist before publication. Some articles cite our Alpha Score. Verify prices and figures against the original source. Educational coverage, not personalized advice.