Cybersecurity & Protection

Cyber Risk Report: Ransomware on the Rise, Germany Among Top 3 Victim Countries

Aug 18, 2026 5 min read
All articles

Trend Micro subsidiary TrendAI has published its Cyber Risk Report 2026, and it paints a mixed picture. Companies are measurably improving their cybersecurity posture, yet the number of successful ransomware attacks worldwide is rising significantly. Based on cybercriminal leak sites, TrendAI identified a total of 433 confirmed ransomware attacks in Germany for 2025, putting the country among the three most affected worldwide. Only the US with 4,893 and Canada with 520 incidents recorded more.

A slightly lower but more volatile risk

To gauge global cyber risk, TrendAI calculates the Cyber Risk Index (CRI). It averaged 35.8 points in 2025, down from 38.5 the year before, a positive development overall. However, the index fluctuated far more in 2025 than in 2024: it stood at 34.6 in January, briefly jumped to 37.4 in April, which TrendAI attributes to many new IT projects at the start of the year, and dropped back to 34.1 in July. Regardless of industry or size, the companies studied overall sit in the medium risk range.

With a CRI of 42.5, mining led the industry risk ranking in 2025, followed by healthcare and agriculture at 40.3 each, telecommunications at 39.9, education at 39.8, and government and public institutions at 39.7. Companies with up to 100 employees remain the lowest-risk group, but they're also the only size segment whose CRI rose in 2025, a sign that attackers are increasingly using small businesses as an entry point into larger supply chains.

Cloud access and stale accounts remain the main entry points

As in the previous year, risky access to cloud applications and stale Microsoft Entra ID accounts top the list of most frequently detected risk events. Accounts without multi-factor authentication enabled remain among the biggest vulnerabilities. New to the top 5 are violations of zero-trust access rules, which TrendAI views as a sign of growing, though not yet consistently enforced, zero-trust adoption.

In vulnerability management, CVSS scores alone aren't enough: among the ten most frequently detected unpatched vulnerabilities, three were rated only medium severity, yet combined with highly critical remote code execution and privilege escalation flaws, they enabled particularly dangerous attack chains. Unpatched vulnerabilities most often led to complete attack paths, with TrendAI finding more than 2.3 million detected paths that started this way. In second place were attacks on poorly protected accounts, such as password spraying and password guessing, combining for more than two million paths. A user account is usually the target at the end of the chain, with an average of around 33,000 accounts attacked per day, nearly twice as often as endpoints in second place.

A more fragmented, more active ransomware scene

According to TrendAI, the ransomware landscape keeps fragmenting while also becoming more active. The number of confirmed victims of the ten most active ransomware groups rose 236 percent in 2025 to 5,096 companies. Qilin catapulted from tenth place in 2024 to first with 1,262 confirmed attacks, a jump of 1,270 percent, followed by Akira with 857 cases, up 708 percent. Five groups newly entered the top ten in 2025, including INC Ransom, SafePay, Lynx, DragonForce, and Sinobi, while previously dominant groups like LockBit lost significant ground. A defense strategy that relies only on the known tactics of established groups falls behind in such a rapidly shifting landscape. It's more effective to reduce the underlying vulnerabilities, regardless of who ends up exploiting them.

Recommendations for companies

To sustainably reduce cyber risk, TrendAI recommends a consistently risk-based security approach: actively optimize security configurations instead of just setting them up once, consistently enforce identity and access management by deleting stale accounts, requiring strong passwords, and rolling out MFA broadly, prioritize vulnerabilities based on risk rather than CVSS score alone, look at attack paths instead of individual risks, and actually operationalize existing security platforms in daily operations through automated playbooks and AI-assisted prioritization.