European Ransomware Incidents Rise Amidst Targeted Sector Attacks
A new report from security vendor CrowdStrike indicates a measurable escalation in ransomware activity across European organizations over the past year. The analysis, compiled by Infosecurity Magazine and based on data gathered between September 2024 and August 2025, documents a double-digit annual increase in victims listed on data leak sites.
The specific figure cited for this period is 1380 European entities that appeared as targets. This represents an increase of 13 percent compared to the previous year leading up to November 2025. The report attributes these figures to CrowdStrike’s threat intelligence and threat hunting data.
Geographically, the United Kingdom was identified as the most targeted nation within Europe during this reporting window. Following the UK in terms of victimization frequency were Germany, Italy, France, and Spain. These five countries accounted for a significant portion of the incidents observed on extortion leak sites.
The attack vectors focused heavily on specific industrial verticals where critical infrastructure or high-value data resides. The most targeted sectors included manufacturing, professional services, technology firms, industrials and engineering companies, as well as retail operations. These industries were deemed particularly vulnerable during the September 2024 to August 2025 timeframe.
Looking at the broader global context provided by CrowdStrike in its 2025 European Threat Landscape Report, Europe accounts for approximately 22 percent of all global ransomware victims. This statistic positions the region as the second-most targeted globally after North America, which holds roughly three-quarters of the remaining total.
The nature of these attacks has shifted toward more aggressive methods involving both file encryption and data exfiltration. Since January 2024, over 2100 European victims have been named on extortion leak sites. According to the analysis, 92 percent of these incidents involved a combination of file encryption and data theft tactics.
CrowdStrike identified specific threat actors responsible for the majority of successful campaigns during this period. The Akira ransomware group was noted with 167 recorded instances, followed closely by LockBit with 162 cases. RansomHub accounted for 141 incidents, while INC, Lynx, and Sinobi were each linked to 133 separate attacks.
The report highlights a persistent threat model known as “big-game hunting” or BGH. This strategy involves deliberately targeting larger companies rather than smaller entities with fewer security resources. CrowdStrike explained that this approach remains a significant menace in Europe, partly due to the presence of many valuable enterprises within the region.
Geopolitical Friction Amplifies Cyber Exposure
The cybersecurity environment is increasingly intertwined with physical conflicts and geopolitical realignments. Yuval Wollman, President of CyberProof and author of a related opinion piece published on January 2, 2026, stated that these dynamics will continue to evolve into new zones of pressure in the coming year.
Wollman noted that major tectonic movements have occurred over recent years. These include the ongoing war in Ukraine and heightened tensions in the Middle East between nations such as Israel and Iran. Increased strategic rivalry is also documented in East Asia, where state-backed cyber campaigns are escalating rapidly.
The report suggests these physical conflicts bleed directly into the digital domain. Physical hostilities amplify exposures for corporations and governments alike, creating a complex landscape of risk that extends beyond traditional technical defenses.
Supply Chain Vulnerabilities and Rare-Earth Dependencies
Beyond immediate conflict zones, supply chain vulnerabilities are becoming strategic issues in specific regions. Wollman pointed out that the Americas are increasingly drawn into friction as supply-chain chokepoints become critical weaknesses. These dependencies often revolve around rare-earth materials essential for modern technology.
The semiconductor industry sits at the center of this dynamic. The report notes that Taiwan is a focal point within these global tensions, influencing how organizations manage exposure across international borders. Supply chain weaponization has redefined what it means to manage cyber risk effectively in 2026 and beyond.
Generative AI Diffusion and Future Risk Management
The rapid diffusion of generative artificial intelligence is another factor expected to challenge existing resilience frameworks. Wollman argued that the coming year will demand a shift from reactive security postures to proactive, intelligence-driven approaches.
This transition requires organizations to integrate cyber strategy with operational continuity and geopolitical awareness deeply. The convergence of these three elements—cyber strategy, operations, and geopolitics—is expected to define the cybersecurity environment in 2026 according to industry experts analyzing current trends.
As organizations move forward, the expectation is that they will need to adapt their risk management strategies to account for these multifaceted threats. The combination of geopolitical friction, supply chain weaponization, and AI diffusion presents a compounded challenge for corporate security teams worldwide.

