A single cybercrime group was reportedly responsible for nearly a fifth of all ransomware attacks in June. It underlines how industrialised ransomware has become — run like a business, with affiliates, tooling and targets chosen for maximum payout.

Why it matters

These groups are prolific and opportunistic, and they favour organisations that are easy to breach and likely to pay. That puts small and mid-sized businesses — often with lighter defences — squarely in scope.

The defence hasn’t changed: close the common entry points (phishing, exposed remote access, unpatched systems), and make yourself recoverable with tested backups and monitoring. We help clients do both so they’re neither an easy target nor a paying one.

Source: ITPro, 13 July 2026.