Black Kite 2026 European Cyber Risk Report: Ransomware Surges 55.1% as Third-Party Supply Chains Become Europe's Primary Attack Path (Qilin-Led) — Threadlinqs Intelligence
As of 2026-06-27, Black Kite 2026 European Cyber Risk Report: Ransomware Surges 55.1% as Third-Party Supply Chains Become Europe's Primary Attack Path (Qilin-Led) is a high-severity ransomware threat attributed to Qilin RaaS, tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 15 indicators of compromise.
Threat ID: TL-2026-0958 · Severity: HIGH · Status: ACTIVE · Category: RANSOMWARE
Attribution: Qilin RaaS · FINANCIAL
Black Kite's first Europe-dedicated report finds ransomware against European organizations accelerating 55.1% year-over-year in early 2026 (monthly volume rising from ~108 to 171 incidents), with
The 2026 European Cyber Risk Report, published by cyber-risk management firm Black Kite on 25 June 2026 and titled 'Ransomware Is Escalating and Your Third Parties Are the Entry Point,' analyzes 2,066 publicly disclosed ransomware incidents across 31 European countries (the 27 EU member states plus the United Kingdom, Switzerland, Norway, and Turkey) over the 16-month window from January 2025 through April 2026. The headline finding is a 55.1% year-over-year increase in publicly disclosed ransomware incidents for the first four months of 2026 versus the same period in 2025, with the monthly average rising from roughly 108 incidents in the first half of 2025 to 171 incidents per month in early 2026.
Ransomware activity is heavily concentrated geographically: the top five countries account for nearly 70% of all European incidents. Germany leads with 370 incidents (17.9%), followed by the United Kingdom at 347 (16.8%), France at 255 (12.3%), Italy at 240 (11.6%), and Spain at 203 (9.8%). By sector, manufacturing is the single most-targeted industry at 27.9% of incidents, followed by professional, scientific, and technical services at 17.8%; IT service providers are called out as the single most-targeted subindustry, a finding that reinforces the supply-chain theme because a compromise of an IT/managed-service provider cascades to its downstream customers.
The Qilin ransomware-as-a-service operation (also tracked as Agenda) is identified as the most active group in the dataset, linked to 372 recorded incidents and active in 26 of the 31 countries analyzed, characterizing it as a 'ransomware generalist.' Akira ranks among the top groups with 159 incidents, and SafePay accounts for roughly 80 incidents heavily concentrated against German organizations.
The report's central strategic warning is that supply chains have become a primary attack path: 64 European organizations were compromised through third-party incidents during the study window, and 53% of those third-party compromises trace to a single event — the August 2025 ransomware attack on Swedish software supplier Miljödata. That breach (attributed in reporting to the 'datacarry' group, with a 1.5 BTC / ~$168,000 ransom demand) disrupted roughly 200 of Sweden's 290 municipalities, affected an estimated 250 downstream customers, and exposed the personal data of over one million individuals (estimates as high as 1.5 million). The 2025 Jaguar Land Rover attack — which forced 30,000+ staff to reset passwords and is cited as the UK's costliest cyber-attack at an estimated £19 billion — is referenced as emblematic of single-incident systemic impact. Dr. Ferhat Dikbiyik, Black Kite's Chief Research Officer, frames the environment as 'three forces converging on European organisations at once: ransomware is accelerating, supply chains are becoming a primary attack path, and regulations are placing greater emphasis on third-party risk,' citing the NIS2, DORA, CER, and Cyber Resilience Act regulatory frameworks. This record is a threat-landscape intelligence brief: it asserts no specific CVE or PoC, and indicators are entity-, sector-, and technique-level rather than network IOCs.
Target sectors: manufacturing, professional scientific and technical services, information technology services, healthcare, retail, transportation, government, financial
Target regions: Europe, Germany, United Kingdom, France, Italy, Spain, Sweden, Switzerland, Norway, Turkey
Detections & IOCs
As of 2026-07-28, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 15 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
RANSOMWARE, HIGH, threat intelligence, cybersecurity, T1190, T1566.001, T1566.002, T1199, T1078, T1059, T1072, T1003, T1021.001, T1021.002