Black Kite 2026 European Cyber Risk Report: Ransomware Surges 55.1% as Third-Party Supply Chains Become Europe's Primary Attack Path (Qilin-Led)

Black Kite 2026 European Cyber Risk Report (TL-2026-0958), also tracked as 2026 European Cyber Risk Report, is a high-severity ransomware operation, first published 2026-06-27. It is attributed to Qilin RaaS with medium confidence, affects Multiple (European organizations) Enterprise IT, manufacturing OT, and, maps to 15 MITRE ATT&CK techniques (T1003, T1005, T1021.001), and is covered by 9 detection rules and 15 indicators of compromise.

Key facts for TL-2026-0958

Threat ID
TL-2026-0958
Also known as
2026 European Cyber Risk Report, Ransomware Is Escalating and Your Third Parties Are the Entry Point
Severity
HIGH
Status
ACTIVE
Category
RANSOMWARE
First published
2026-06-27
Last reviewed
2026-06-27
Attribution
Qilin RaaS
Attribution confidence
MEDIUM
Motivation
FINANCIAL
Target sectors
manufacturing, professional scientific and technical services, information technology services, healthcare, retail, transportation, government, financial
Target regions
Europe, Germany, United Kingdom, France, Italy, Spain, Sweden, Switzerland, Norway, Turkey
Detection rules
9
Indicators of compromise
15

Malware and tooling in Black Kite 2026 European Cyber Risk Report

Malware and tooling: AgendaCrypt, Akira, safepay, VMware ESXi / Linux encryptor deployment

Black Kite's first Europe-dedicated report finds ransomware against European organizations accelerating 55.1% year-over-year in early 2026 (monthly volume rising from ~108 to 171 incidents), with third-party suppliers emerging as a primary attack vector. Across 2,066 incidents in 31 countries (Jan 2025-Apr 2026), Qilin was the most active group, linked to 372 incidents across 26 of 31 countries.

How Black Kite 2026 European Cyber Risk Report works

The 2026 European Cyber Risk Report, published by cyber-risk management firm Black Kite on 25 June 2026 and titled 'Ransomware Is Escalating and Your Third Parties Are the Entry Point,' analyzes 2,066 publicly disclosed ransomware incidents across 31 European countries (the 27 EU member states plus the United Kingdom, Switzerland, Norway, and Turkey) over the 16-month window from January 2025 through April 2026. The headline finding is a 55.1% year-over-year increase in publicly disclosed ransomware incidents for the first four months of 2026 versus the same period in 2025, with the monthly average rising from roughly 108 incidents in the first half of 2025 to 171 incidents per month in early 2026.

Ransomware activity is heavily concentrated geographically: the top five countries account for nearly 70% of all European incidents. Germany leads with 370 incidents (17.9%), followed by the United Kingdom at 347 (16.8%), France at 255 (12.3%), Italy at 240 (11.6%), and Spain at 203 (9.8%). By sector, manufacturing is the single most-targeted industry at 27.9% of incidents, followed by professional, scientific, and technical services at 17.8%; IT service providers are called out as the single most-targeted subindustry, a finding that reinforces the supply-chain theme because a compromise of an IT/managed-service provider cascades to its downstream customers.

The Qilin ransomware-as-a-service operation (also tracked as Agenda) is identified as the most active group in the dataset, linked to 372 recorded incidents and active in 26 of the 31 countries analyzed, characterizing it as a 'ransomware generalist.' Akira ranks among the top groups with 159 incidents, and SafePay accounts for roughly 80 incidents heavily concentrated against German organizations.

The report's central strategic warning is that supply chains have become a primary attack path: 64 European organizations were compromised through third-party incidents during the study window, and 53% of those third-party compromises trace to a single event — the August 2025 ransomware attack on Swedish software supplier Miljödata. That breach (attributed in reporting to the 'datacarry' group, with a 1.5 BTC / ~$168,000 ransom demand) disrupted roughly 200 of Sweden's 290 municipalities, affected an estimated 250 downstream customers, and exposed the personal data of over one million individuals (estimates as high as 1.5 million). The 2025 Jaguar Land Rover attack — which forced 30,000+ staff to reset passwords and is cited as the UK's costliest cyber-attack at an estimated £19 billion — is referenced as emblematic of single-incident systemic impact. Dr. Ferhat Dikbiyik, Black Kite's Chief Research Officer, frames the environment as 'three forces converging on European organisations at once: ransomware is accelerating, supply chains are becoming a primary attack path, and regulations are placing greater emphasis on third-party risk,' citing the NIS2, DORA, CER, and Cyber Resilience Act regulatory frameworks. This record is a threat-landscape intelligence brief: it asserts no specific CVE or PoC, and indicators are entity-, sector-, and technique-level rather than network IOCs.

MITRE ATT&CK techniques used in TL-2026-0958

Credential Access

T1003 OS Credential Dumping

Collection

T1005 Data from Local System

Lateral Movement

T1021.001 Remote Desktop Protocol; T1021.002 SMB/Windows Admin Shares

Execution

T1059 Command and Scripting Interpreter; T1072 Software Deployment Tools

Initial Access

T1078 Valid Accounts; T1190 Exploit Public-Facing Application; T1199 Trusted Relationship; T1566.001 Spearphishing Attachment; T1566.002 Spearphishing Link

Impact

T1486 Data Encrypted for Impact; T1657 Financial Theft

impact

T1490 Inhibit System Recovery

Exfiltration

T1567 Exfiltration Over Web Service

Affected products and versions in Black Kite 2026 European Cyber Risk Report

  • Multiple (European organizations) — Enterprise IT, manufacturing OT, and third-party supplier ecosystems
    Vulnerable versions: Internet-facing VPN/RDP/Citrix; IT/managed-service provider supply chains
  • Miljödata — Municipal HR / sick-leave / incident-reporting platform
    Vulnerable versions: Production environment as of August 2025

Remediation for Black Kite 2026 European Cyber Risk Report

Patches

  • Prioritize patching of internet-facing applications (VPN, RDP gateways, Citrix) commonly exploited for initial access

Immediate actions

  • Inventory and risk-rank all third-party suppliers with access to data or systems (payroll, CRM, HR, logistics, IT/managed-service providers)
  • Enforce phishing-resistant MFA on all external access (VPN, RDP, Citrix, webmail) to blunt valid-account and infostealer-credential abuse
  • Block and monitor for Qilin/Agenda, Akira, and SafePay TTPs and known leak-site activity

Workarounds

  • Restrict and log RDP/SMB/WMI/PsExec lateral-movement paths; disable unused remote services
  • Maintain tested, offline, immutable backups to recover without paying ransom

Longer-term hardening

  • Operationalize continuous third-party/supplier cyber-risk monitoring aligned to NIS2 and DORA obligations
  • Deploy EDR/XDR with behavioral detection for ESXi/Linux/Windows ransomware encryptors and shadow-copy deletion
  • Segment networks to contain supplier-originated intrusions and limit blast radius of a single compromised vendor

Timeline of Black Kite 2026 European Cyber Risk Report

  • Qilin (Agenda) ransomware-as-a-service first observed, operating Go/Rust encryptors against Windows, Linux, and VMware ESXi and using a double-extortion data-leak site.
  • Start of Black Kite's 16-month measurement window for the 2026 European Cyber Risk Report (2,066 incidents across 31 countries).
  • Attackers gain unauthorized access to Swedish software supplier Miljödata's servers (intrusion later dated to ~22 August).
  • Miljödata confirms the breach; the attack disrupts ~200 of Sweden's 290 municipalities and downstream HR/sick-leave systems.
  • Reporting details a 1.5 BTC (~$168,000) ransom demand; over one million individuals' personal data is ultimately exposed, with the 'datacarry' group named.
  • Through end of 2025, Qilin emerges as the most active group (372 incidents across 26 of 31 countries); Germany leads national incident counts.
  • Jan-Apr 2026 disclosed ransomware incidents up 55.1% year-over-year; monthly average rises from ~108 to 171; third-party compromises reach 64 organizations.
  • Black Kite publishes the 2026 European Cyber Risk Report 'Ransomware Is Escalating and Your Third Parties Are the Entry Point.'

Sources cited for Black Kite 2026 European Cyber Risk Report

Threats related to Black Kite 2026 European Cyber Risk Report

Detection coverage for TL-2026-0958

As of 2026-06-27, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-0958 across Splunk SPL, Microsoft KQL and Sigma, covering 15 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

Further reading

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Latest Threats