Black Kite 2026 European Cyber Risk Report: Ransomware Surges 55.1% as Third-Party Supply Chains Become Europe's Primary Attack Path (Qilin-Led)
Black Kite 2026 European Cyber Risk Report (TL-2026-0958), also tracked as 2026 European Cyber Risk Report, is a high-severity ransomware operation, first published 2026-06-27. It is attributed to Qilin RaaS with medium confidence, affects Multiple (European organizations) Enterprise IT, manufacturing OT, and, maps to 15 MITRE ATT&CK techniques (T1003, T1005, T1021.001), and is covered by 9 detection rules and 15 indicators of compromise.
Key facts for TL-2026-0958
- Threat ID
- TL-2026-0958
- Also known as
- 2026 European Cyber Risk Report, Ransomware Is Escalating and Your Third Parties Are the Entry Point
- Severity
- HIGH
- Status
- ACTIVE
- Category
- RANSOMWARE
- First published
- 2026-06-27
- Last reviewed
- 2026-06-27
- Attribution
- Qilin RaaS
- Attribution confidence
- MEDIUM
- Motivation
- FINANCIAL
- Target sectors
- manufacturing, professional scientific and technical services, information technology services, healthcare, retail, transportation, government, financial
- Target regions
- Europe, Germany, United Kingdom, France, Italy, Spain, Sweden, Switzerland, Norway, Turkey
- Detection rules
- 9
- Indicators of compromise
- 15
Malware and tooling in Black Kite 2026 European Cyber Risk Report
Malware and tooling: AgendaCrypt, Akira, safepay, VMware ESXi / Linux encryptor deployment
Black Kite's first Europe-dedicated report finds ransomware against European organizations accelerating 55.1% year-over-year in early 2026 (monthly volume rising from ~108 to 171 incidents), with third-party suppliers emerging as a primary attack vector. Across 2,066 incidents in 31 countries (Jan 2025-Apr 2026), Qilin was the most active group, linked to 372 incidents across 26 of 31 countries.
How Black Kite 2026 European Cyber Risk Report works
The 2026 European Cyber Risk Report, published by cyber-risk management firm Black Kite on 25 June 2026 and titled 'Ransomware Is Escalating and Your Third Parties Are the Entry Point,' analyzes 2,066 publicly disclosed ransomware incidents across 31 European countries (the 27 EU member states plus the United Kingdom, Switzerland, Norway, and Turkey) over the 16-month window from January 2025 through April 2026. The headline finding is a 55.1% year-over-year increase in publicly disclosed ransomware incidents for the first four months of 2026 versus the same period in 2025, with the monthly average rising from roughly 108 incidents in the first half of 2025 to 171 incidents per month in early 2026.
Ransomware activity is heavily concentrated geographically: the top five countries account for nearly 70% of all European incidents. Germany leads with 370 incidents (17.9%), followed by the United Kingdom at 347 (16.8%), France at 255 (12.3%), Italy at 240 (11.6%), and Spain at 203 (9.8%). By sector, manufacturing is the single most-targeted industry at 27.9% of incidents, followed by professional, scientific, and technical services at 17.8%; IT service providers are called out as the single most-targeted subindustry, a finding that reinforces the supply-chain theme because a compromise of an IT/managed-service provider cascades to its downstream customers.
The Qilin ransomware-as-a-service operation (also tracked as Agenda) is identified as the most active group in the dataset, linked to 372 recorded incidents and active in 26 of the 31 countries analyzed, characterizing it as a 'ransomware generalist.' Akira ranks among the top groups with 159 incidents, and SafePay accounts for roughly 80 incidents heavily concentrated against German organizations.
The report's central strategic warning is that supply chains have become a primary attack path: 64 European organizations were compromised through third-party incidents during the study window, and 53% of those third-party compromises trace to a single event — the August 2025 ransomware attack on Swedish software supplier Miljödata. That breach (attributed in reporting to the 'datacarry' group, with a 1.5 BTC / ~$168,000 ransom demand) disrupted roughly 200 of Sweden's 290 municipalities, affected an estimated 250 downstream customers, and exposed the personal data of over one million individuals (estimates as high as 1.5 million). The 2025 Jaguar Land Rover attack — which forced 30,000+ staff to reset passwords and is cited as the UK's costliest cyber-attack at an estimated £19 billion — is referenced as emblematic of single-incident systemic impact. Dr. Ferhat Dikbiyik, Black Kite's Chief Research Officer, frames the environment as 'three forces converging on European organisations at once: ransomware is accelerating, supply chains are becoming a primary attack path, and regulations are placing greater emphasis on third-party risk,' citing the NIS2, DORA, CER, and Cyber Resilience Act regulatory frameworks. This record is a threat-landscape intelligence brief: it asserts no specific CVE or PoC, and indicators are entity-, sector-, and technique-level rather than network IOCs.
MITRE ATT&CK techniques used in TL-2026-0958
Credential Access
Collection
Lateral Movement
T1021.001 Remote Desktop Protocol; T1021.002 SMB/Windows Admin Shares
Execution
T1059 Command and Scripting Interpreter; T1072 Software Deployment Tools
Initial Access
T1078 Valid Accounts; T1190 Exploit Public-Facing Application; T1199 Trusted Relationship; T1566.001 Spearphishing Attachment; T1566.002 Spearphishing Link
Impact
T1486 Data Encrypted for Impact; T1657 Financial Theft
impact
Exfiltration
Affected products and versions in Black Kite 2026 European Cyber Risk Report
- Multiple (European organizations) — Enterprise IT, manufacturing OT, and third-party supplier ecosystems
Vulnerable versions: Internet-facing VPN/RDP/Citrix; IT/managed-service provider supply chains - Miljödata — Municipal HR / sick-leave / incident-reporting platform
Vulnerable versions: Production environment as of August 2025
Remediation for Black Kite 2026 European Cyber Risk Report
Patches
- Prioritize patching of internet-facing applications (VPN, RDP gateways, Citrix) commonly exploited for initial access
Immediate actions
- Inventory and risk-rank all third-party suppliers with access to data or systems (payroll, CRM, HR, logistics, IT/managed-service providers)
- Enforce phishing-resistant MFA on all external access (VPN, RDP, Citrix, webmail) to blunt valid-account and infostealer-credential abuse
- Block and monitor for Qilin/Agenda, Akira, and SafePay TTPs and known leak-site activity
Workarounds
- Restrict and log RDP/SMB/WMI/PsExec lateral-movement paths; disable unused remote services
- Maintain tested, offline, immutable backups to recover without paying ransom
Longer-term hardening
- Operationalize continuous third-party/supplier cyber-risk monitoring aligned to NIS2 and DORA obligations
- Deploy EDR/XDR with behavioral detection for ESXi/Linux/Windows ransomware encryptors and shadow-copy deletion
- Segment networks to contain supplier-originated intrusions and limit blast radius of a single compromised vendor
Timeline of Black Kite 2026 European Cyber Risk Report
- Qilin (Agenda) ransomware-as-a-service first observed, operating Go/Rust encryptors against Windows, Linux, and VMware ESXi and using a double-extortion data-leak site.
- Start of Black Kite's 16-month measurement window for the 2026 European Cyber Risk Report (2,066 incidents across 31 countries).
- Attackers gain unauthorized access to Swedish software supplier Miljödata's servers (intrusion later dated to ~22 August).
- Miljödata confirms the breach; the attack disrupts ~200 of Sweden's 290 municipalities and downstream HR/sick-leave systems.
- Reporting details a 1.5 BTC (~$168,000) ransom demand; over one million individuals' personal data is ultimately exposed, with the 'datacarry' group named.
- Through end of 2025, Qilin emerges as the most active group (372 incidents across 26 of 31 countries); Germany leads national incident counts.
- Jan-Apr 2026 disclosed ransomware incidents up 55.1% year-over-year; monthly average rises from ~108 to 171; third-party compromises reach 64 organizations.
- Black Kite publishes the 2026 European Cyber Risk Report 'Ransomware Is Escalating and Your Third Parties Are the Entry Point.'
Sources cited for Black Kite 2026 European Cyber Risk Report
- Ransomware gangs find Europe's weakest link in third-party suppliers
- Black Kite's First Report Dedicated to Europe: Ransomware Incidents Rose 55% Year-Over-Year
- Major Increase in Ransomware Attacks Targeting Europe, Warns Report
- Qilin, Software S1242 — MITRE ATT&CK
- Ransomware crooks knock Swedish councils offline over $168K — The Register
- IT system supplier cyberattack impacts 200 municipalities in Sweden — BleepingComputer
- Ransomware attack on IT supplier disrupts hundreds of Swedish municipalities — IT Pro
- Threat Actor Profile: Qilin Ransomware Group — Cyble
Threats related to Black Kite 2026 European Cyber Risk Report
Detection coverage for TL-2026-0958
As of 2026-06-27, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-0958 across Splunk SPL, Microsoft KQL and Sigma, covering 15 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.