Pandorex
Security

Ransomware in the DACH Region Q1 2026: New Actors, Old Vulnerabilities, and What Companies Must Do Now

Published Pandorex Redaktion·8 min read
—

The first quarter of 2026 reveals a changed threat landscape for companies in Germany, Austria, and Switzerland. While the well-known ransomware groups LockBit and ALPHV/BlackCat have been weakened by law enforcement actions, new actors have stepped into the gap. Attacks are becoming faster, more targeted, and technically more sophisticated.

New Groups, New Tactics

Three groups currently dominate the DACH threat landscape:

  • RansomHub: The most active group in Europe since late 2025. Uses Initial Access Brokers (IABs) for initial entry and encrypts within an average of 4 hours after compromise. Target sector: manufacturing and logistics.
  • Medusa: Focuses on educational institutions and healthcare in the German-speaking region. Distinguishing feature: double extortion with a public countdown timer on the leak site.
  • Qilin: Technically sophisticated group that specifically targets VMware ESXi environments, encrypting entire virtualization landscapes in one strike.

The Most Common Entry Points

The analysis of 87 documented ransomware incidents in the DACH region (Q1 2026, sources: BSI, NCSC, CERT.at) paints a clear picture:

  • VPN vulnerabilities (34%): Unpatched Fortinet, Cisco, and Ivanti appliances remain the number one entry point. Despite available patches, systems are often updated only weeks after release.
  • Compromised credentials (28%): Infostealer malware on employee devices delivers valid credentials that are traded on darknet marketplaces. MFA bypass through token theft is increasing.
  • Email / Phishing (22%): Targeted spear-phishing campaigns with QR codes (quishing) and fake Microsoft 365 login pages.
  • Exposed RDP services (11%): Remote Desktop Protocol directly accessible from the internet, often with weak passwords.
  • Supply Chain (5%): Compromise via IT service providers or MSPs with privileged access to customer systems.

Average Downtime Is Rising

The average downtime after a ransomware incident in the DACH region rose to 18 days in Q1 2026 (Q4 2025: 14 days). The reason: attackers deliberately destroy backup infrastructure before encrypting. Those without immutable backups or air-gapped copies face total loss.

What Companies Should Do Now

The good news: defense works when the basics are in place.

  1. Patch management with SLAs: Patch VPN appliances and internet-exposed systems within 48 hours of a critical CVE. No exceptions.
  2. MFA everywhere: Not just for VPN and email, but also for RDP, admin portals, and cloud consoles. Hardware tokens (FIDO2) instead of SMS.
  3. Immutable backups: At least one backup copy that can neither be encrypted nor deleted. Regular recovery tests.
  4. Network segmentation: Strictly separate production networks, office IT, and management interfaces.
  5. EDR/XDR on all endpoints: Signature-based antivirus is no longer enough. Behavior-based detection is mandatory.
  6. Incident response plan: Documented, tested, with clear escalation paths. Do not improvise during an actual incident.

The ransomware threat will not disappear. But companies that do their homework drastically reduce the risk of a successful attack.

Sources: BSI Situation Report Q1/2026, NCSC Semi-Annual Report, CERT.at Statistics, Sophos Threat Report 2026.

Comments

Sign in to write a comment.

Swipe up
Next Article

The Zero-Day Market 2026: Prices Rise, States Buy, Companies Pay

Security