started · updated
Germany ranks second globally in ransomware attacks
A Q2 2026 Threat Landscape Report from Rapid7 Labs indicates a significant escalation in cyber risks, particularly for the financial sector. The report highlights that state-sponsored groups from Iran, North Korea, and Russia are conducting targeted campaigns against financial institutions.
Germany has emerged as a major target, ranking second globally in ransomware attacks behind the United States. Data from ransomware.live shows that Germany recorded 107 victims in June and July 2026 alone, a threefold increase compared to the previous year. The SafePay ransomware group has become the most active threat in Germany, often completing the encryption process within hours of an initial infection.
Technological trends show that attackers are exploiting vulnerabilities with increasing speed. The number of vulnerabilities classified as high or critical has doubled to 8,539 year-over-year. Furthermore, 62 percent of newly exploited vulnerabilities are zero-click exploits, which allow network-based access without requiring user interaction or authentication. Rapid7 warns that traditional patch cycles and static risk assessments are no longer sufficient to keep pace with the rapid deployment of exploit code.
Entities
Germany · Qilin · Rapid7 Labs · SafePay · United States
Claims
What the coverage asserts, and how many sources carry each claim.
- [● 3 SOURCES] Germany ranks second globally in ransomware attacks, following the United States. www.it-finanzmagazin.de · www.security-insider.de · www.linux-magazin.de
- [● 2 SOURCES] 62 percent of newly exploited vulnerabilities were zero-click vulnerabilities. www.it-finanzmagazin.de · www.linux-magazin.de
- [● 2 SOURCES] The Q2 2026 Threat Landscape Report shows an increase in cyber risks for financial institutions. www.it-finanzmagazin.de · www.linux-magazin.de
- [● 2 SOURCES] The number of vulnerabilities classified as high or critical doubled year-over-year to 8,539. www.it-finanzmagazin.de · www.linux-magazin.de
- [○ 1 SOURCE] Publicly available exploit code increased by 76 percent within one year. www.linux-magazin.de
- [● 2 SOURCES] Newly exploited vulnerabilities increased by up to 40 percent. www.it-finanzmagazin.de · www.linux-magazin.de
- [● 2 SOURCES] State-sponsored attackers from Iran, North Korea, and Russia are targeting the financial sector. www.it-finanzmagazin.de · www.linux-magazin.de
- [○ 1 SOURCE] SafePay became the most active ransomware group in Germany during June and July 2026. www.security-insider.de