Bottom line: According to the report, ransomware accounts for 76.1 percent of the analyzed incidents, with data ranging from several hundred gigabytes to terabytes additionally stolen in 63.6 percent of cases.
A report by Riedel Networks covering more than 180 IT security incidents from the first half of 2026 shows that ransomware attacks are increasingly being combined with targeted data theft. Pure system encryption is taking a back seat in favor of multi-stage extortion.
“
The current report by Riedel Networks analyzes more than 180 IT security incidents from the first half of 2026. Ransomware remains the defining attack pattern, accounting for 76.1 percent of all investigated incidents – compared to 32.5 percent in the second half of 2025. What has changed is the attackers’ modus operandi: in 63.6 percent of ransomware cases, targeted data theft additionally occurred. The perpetrators copy confidential information ranging from several hundred gigabytes to several terabytes before encrypting systems. They then threaten to publish the data, backed up by screenshots as proof of access, short payment deadlines, and entries on leak sites.
For CISOs, this development means that pure backup and recovery strategies are no longer sufficient to neutralize extortion pressure – even with functioning backups, the threat of data publication remains. The distribution across industries remains uneven: manufacturing companies continue to represent the largest share of recorded cases at around 32 percent (second half of 2025: 34.6 percent), followed by healthcare and social services at around eleven percent, and logistics and transport at around nine percent. This particularly affects industries with complex supply chains, critical operational processes, or highly sensitive data.
Another finding concerns the role of third-party providers. IT service providers, software vendors, logistics companies, billing agencies, or facility service providers are increasingly acting as an entry point through which compromises can spread along the entire supply and value chain. Securing partners and service providers is thus becoming a fixed component of an organization’s own cyber resilience strategy, not merely a supplement to its own perimeter protection.
According to Riedel Networks, the use of artificial intelligence is also changing attack preparation: phishing and social engineering can be tailored more quickly and individually, and more complex attacks can be planned more efficiently. At the same time, digital dependency on cloud services, software platforms, and specialized service providers is growing, meaning that a successful attack on a central provider can have far-reaching consequences for supply chains, business processes, and customer trust.
In terms of attribution, financially motivated cybercriminals dominate with around 91 percent of recorded incidents (second half of 2025: 86.95 percent). State-backed actors are less prominent according to the report, but are gaining visibility and increasingly using everyday communication platforms for espionage activities.
”
Source: www.it-daily.net · Published August 17, 2026
Lumi AI News — AI-assisted curation pursuant to Art. 50 EU AI Act. Paraphrasing and classification by Lumi News Pipeline v1.8.3.