A single cybercrime group was reportedly responsible for nearly a fifth of all ransomware attacks in June. It underlines how industrialised ransomware has become — run like a business, with affiliates, tooling and targets chosen for maximum payout.

Why it matters

These groups are prolific and opportunistic, and they favour organisations that are easy to breach and likely to pay. That puts small and mid-sized businesses — often with lighter defences — squarely in scope.

The defence hasn’t changed: close the common entry points (phishing, exposed remote access, unpatched systems), and make yourself recoverable with tested backups and monitoring. We help clients do both so they’re neither an easy target nor a paying one.

Ransomware runs like a business

A single group accounting for so many attacks reflects how industrialised the model has become. Ransomware-as-a-service lets a core group build the tooling and rent it to affiliates, who carry out the break-ins; separate “initial access brokers” sell ready-made entry into victim networks. Most crews now use double extortion — encrypting your systems and stealing your data, then threatening to publish it — so that even a good backup does not remove the pressure to pay. Targets are chosen coldly: easy to breach, and likely to pay.

Breaking the chain

You do not have to beat every attacker, only be harder work than the next organisation. Close the common entry points — phishing, exposed remote desktop and VPN, unpatched systems — and put phishing-resistant multi-factor authentication in front of anything internet-facing. Deploy endpoint detection so intrusions are caught early, and keep immutable or offline backups that are tested regularly. Paying a ransom is no guarantee of recovery and carries legal and reputational risk, so the goal is to be neither an easy target nor a paying one. We help clients achieve both.

Recoverability, not luck, is what separates a bad day from a genuine catastrophe.

Source: ITPro, 13 July 2026.