Diglion
Back to blog

Security

Ransomware is still rising in 2026 — and service businesses are targets

111 publicly disclosed ransomware attacks in July 2026, 6.7% more than the year before. Service businesses are already the second most-hit sector — not just hospitals and banks.

August 14, 2026|5 min read

Ransomware is still rising in 2026

The number that flew under the radar

BlackFog's The State of Ransomware 2026 report counted 111 publicly disclosed ransomware attacks in July 2026 alone — 6.7% more than the same month the year before, hitting victims across 27 countries. This isn't a declining trend. It's a problem that keeps growing, month after month.

The part that often goes unnoticed: hospitals and banks aren't the only favorite targets anymore. In July, healthcare led with 35% of attacks, but services came right behind at 14% — ahead of manufacturing at 11%. "Services" here includes consulting firms, accounting practices, agencies, law offices, small clinics — the kind of business that often assumes it's "too small to matter" to a criminal.

Why small service businesses became targets

Ransomware criminals don't pick victims by size — they pick them by how easy they are to get into and how likely they are to pay quickly to get back running. A small service business usually has fewer technical protection layers than a bank, but depends just as much on working systems (schedule, records, contracts, financial spreadsheets) to operate day to day. That combines exactly what an attacker looks for: an easier door in, a strong reason to pay fast.

Another figure from the same report underscores the scale of the problem: 47% of attacks still remain unattributed, showing how hard it is to trace who's behind them — and why prevention matters more than reacting after the fact.

What you can do without an IT team

Automated, tested backups — not just having a backup, but having actually tried restoring it at least once. Keeping operating systems and software up to date, since most attacks exploit a flaw that's had a fix available for months. A different password for every important system, with two-factor authentication turned on wherever possible. And a simple, written plan for "what do we do if systems go down tomorrow" — who to call, where the backup lives, which IT provider to bring in.

None of these require buying an expensive tool. They require a routine.

Where Diglion comes in

Diglion helps small and mid-sized businesses close the most common gaps — backup, updates, access — before an attack forces that conversation to happen under pressure.

Sources consulted

Next step

Want to turn this topic into a real project?

Diglion helps diagnose the context, design the path, and build technology with product, architecture, and execution moving together.

Talk to a specialist