Security
Ransomware is still rising in 2026 — and service businesses are targets
111 publicly disclosed ransomware attacks in July 2026, 6.7% more than the year before. Service businesses are already the second most-hit sector — not just hospitals and banks.
August 14, 2026|5 min read
The number that flew under the radar
BlackFog's The State of Ransomware 2026 report counted 111 publicly disclosed ransomware attacks in July 2026 alone — 6.7% more than the same month the year before, hitting victims across 27 countries. This isn't a declining trend. It's a problem that keeps growing, month after month.
The part that often goes unnoticed: hospitals and banks aren't the only favorite targets anymore. In July, healthcare led with 35% of attacks, but services came right behind at 14% — ahead of manufacturing at 11%. "Services" here includes consulting firms, accounting practices, agencies, law offices, small clinics — the kind of business that often assumes it's "too small to matter" to a criminal.
Why small service businesses became targets
Ransomware criminals don't pick victims by size — they pick them by how easy they are to get into and how likely they are to pay quickly to get back running. A small service business usually has fewer technical protection layers than a bank, but depends just as much on working systems (schedule, records, contracts, financial spreadsheets) to operate day to day. That combines exactly what an attacker looks for: an easier door in, a strong reason to pay fast.
Another figure from the same report underscores the scale of the problem: 47% of attacks still remain unattributed, showing how hard it is to trace who's behind them — and why prevention matters more than reacting after the fact.
What you can do without an IT team
Automated, tested backups — not just having a backup, but having actually tried restoring it at least once. Keeping operating systems and software up to date, since most attacks exploit a flaw that's had a fix available for months. A different password for every important system, with two-factor authentication turned on wherever possible. And a simple, written plan for "what do we do if systems go down tomorrow" — who to call, where the backup lives, which IT provider to bring in.
None of these require buying an expensive tool. They require a routine.
Where Diglion comes in
Diglion helps small and mid-sized businesses close the most common gaps — backup, updates, access — before an attack forces that conversation to happen under pressure.
Sources consulted
- BlackFog, The State of Ransomware 2026, retrieved 2026-08-14.
Corporate deepfakes: the scam your company has not seen yet
Generative AI security: risks that do not have names yet
Pentest: when to hire and what to expect from the report
Practical LGPD for teams without a dedicated DPO
Security for IoT devices in operations
Web3 and blockchain: separating hype from real application
Next step
Want to turn this topic into a real project?
Diglion helps diagnose the context, design the path, and build technology with product, architecture, and execution moving together.
Talk to a specialist