Thousands fall victim to ransomware as European attacks reach record highs – here’s why they’re so at risk
- European companies are being targeted more and more by ransomware attacks
- High income and strict regulations make them lucrative targets, Crowdstrike finds
- Geopolitics also plays a role in the increased number of breaches
European companies are increasingly the targets of ransomware and extortion, new research from CrowdStrike has claimed, with the region now accounting for almost 22% of global ransomware victims, second only behind North America.
Since 2024, over 2,100 victims have been posted on extortion leak sites across the continent – making European firms twice as likely to be targeted than those in the Asia Pacific, and the view that richer companies can pay higher ransoms makes them attractive targets.
The strict GDPR regulations and heavy penalties that come with violations have created the perception that European companies are more likely to pay ransom demands, with lucrative industries like manufacturing, professional service, and technology most commonly targeted.
Evolving threats
No matter where in the world you are, the ransom attack tactics and techniques usually stay pretty similar. Credentials are dumped from backups, files are remotely encrypted, access is leveraged to unmanaged systems in order to steal data and deploy the ransomware, and Linux ransomware on VMware EsXI infrastructure is deployed.
Although it’s a common playbook, it’s quicker than ever for criminals to execute this, with adversaries averaging just 35.5 hours between initial access and ransomware deployment – meaning security teams are scrambling to protect themselves after they detect an incident, even if they know what’s coming.
Geopolitics plays an important role in European attacks, with the war in Ukraine driving politically motivated hacktivist groups to target supporters on each side, collecting information and disabling services.
“The cyber battlefield in Europe is more crowded and complex than ever,” said Adam Meyers, head of Counter Adversary Operations at CrowdStrike.
Sign up to the TechRadar Pro newsletter to get all the top news, opinion, features and guidance your business needs to succeed!
“We’re seeing a dangerous convergence of criminal innovation and geopolitical ambition, with ransomware crews using enterprise-grade tools and state-backed actors exploiting global crises to disrupt, persist, and conduct espionage. In this high-stakes environment, intelligence-led defense powered by AI and guided by human expertise is the only combination designed to stop cyber threats.”

The best ID theft protection for all budgets
European companies are being targeted more and more by ransomware attacks High income and strict regulations make them lucrative targets, Crowdstrike finds Geopolitics also plays a role in the increased number of breaches European companies are increasingly the targets of ransomware and extortion, new research from CrowdStrike has claimed, with…
Recent Posts
- Amazon’s new plan for games: James Bond and AI Snoop Dogg
- How to watch France vs Ivory Coast: FREE streams, TV channels for World Cup 2026 warm-up
- Marshall Milton ANC review: Making the rare case for premium on-ear headphones
- Belkin’s new Joy-Con grips also boost the Switch 2’s battery life
- How to watch Spain vs Iraq: Free Streams & TV Channels for World Cup 2026 warm-up match
Archives
- June 2026
- May 2026
- April 2026
- March 2026
- February 2026
- January 2026
- December 2025
- November 2025
- October 2025
- September 2025
- August 2025
- July 2025
- June 2025
- May 2025
- April 2025
- March 2025
- February 2025
- January 2025
- December 2024
- November 2024
- October 2024
- September 2024
- August 2024
- July 2024
- June 2024
- May 2024
- April 2024
- March 2024
- February 2024
- January 2024
- December 2023
- November 2023
- October 2023
- September 2023
- August 2023
- July 2023
- June 2023