Ransomware Attacks Surge 55% in Europe as Supply Chains Become Prime Targets

  • Black Kite's first Europe-focused report reveals a 55.1% year-over-year increase in ransomware incidents in early 2026, with supply chains emerging as key attack vectors.
  • Germany was the most targeted country (370 incidents), followed by the UK (347) and France (255).
  • The Qilin ransomware group operated across 26 of 31 analyzed countries, while SafePay concentrated over half its attacks on Germany.
  • The August 2025 breach of Swedish HR software supplier Miljödata affected 250 customers and exposed data of over one million individuals.

Black Kite's report highlights a dangerous convergence of accelerating ransomware attacks, supply chain vulnerabilities, and tightening European regulations. The Miljödata incident demonstrates how single supplier breaches can cascade through entire ecosystems, creating systemic risks that traditional perimeter defenses cannot address. As regulatory frameworks like NIS2 and DORA increase accountability for third-party risk, organizations face growing pressure to transform their cybersecurity strategies from reactive to proactive.

Regulatory Pressure
How NIS2 and DORA frameworks will enforce third-party cyber risk assessments across European supply chains.
Attack Patterns
Whether ransomware groups like Qilin will maintain broad geographic reach or shift to more concentrated strategies like SafePay's focus on Germany.
Supply Chain Vulnerabilities
The pace at which organizations adopt continuous monitoring of third-party cyber risks following high-profile incidents like the Miljödata breach.