RansomwareThreatsSMEs

Ransomware in 2026: 5 groups targeting French SMEs

These groups no longer encrypt immediately. They copy data first, stay hidden, then strike. What Akira, RansomHub, Qilin, DragonForce and Medusa are doing this year.

Hakim Djelili7 min read

In late 2024, cybercriminals made a subtle shift: they no longer encrypt immediately. They copy data first, stay hidden for several weeks, then strike. For an SME, that changes everything. Backups alone can no longer protect you from having your data published.

Current landscape

What has changed since 2024

+38%

Increase in ransomware attacks

Against French SMEs compared with 2024

21 days

Average presence before encryption

The attacker maps the network in silence

72 hrs

NIS2 notification deadline

After detecting a significant incident

For a long time, ransomware followed a simple pattern: break in, encrypt, demand payment. SMEs that kept their backups up to date could recover without paying.

That model is obsolete.

Groups active in 2026 now use double extortion almost systematically:

  1. Phase 1 (D-30 to D-7)

    Silent exfiltration

    The attacker breaks in, maps the network, identifies sensitive data (HR, accounting, contracts) and quietly copies it to an external server.

  2. Phase 2 (D-0)

    Encryption begins

    Within hours, servers, workstations and backups connected to the network are encrypted. The ransom note appears.

  3. Phase 3 (D+1)

    Double pressure

    Pay for the decryption key AND pay to prevent the data from being published on a public leak site.

Who is attacking

5 groups targeting French SMEs

1. Akira

Target: Mid-sized companies with 50 to 500 employees, in manufacturing and B2B services.

Akira enters through unpatched Cisco VPNs, moves laterally for 2 to 3 weeks, exfiltrates accounting data and contracts, then encrypts the systems. The average ransom ranges from €150,000 to €300,000.

2. RansomHub

Target: Organisations of all sizes and in all sectors. RaaS model: affiliates keep 90% of the ransom.

In 18 months, RansomHub has become the platform most widely used by French-speaking affiliates. Its 90/10 model attracts opportunistic operators who target indiscriminately. Its distinguishing feature is a public “time until publication” countdown designed to maximise pressure.

3. Qilin

Target: Healthcare institutions, local authorities and digital service providers.

If you are a subcontractor to a hospital or local authority, you may be the entry point. Qilin gets in with credentials stolen from exposed services such as RDP and business portals.

4. DragonForce

Target: Manufacturers, distributors and transport companies.

DragonForce targets subcontractors to large companies to work its way towards the ultimate target. Your SME is not the main target; it is the necessary route in. This means you could lose a major contract after an attack, even if you pay.

5. Medusa

Target: Accountancy firms, law firms and SMEs holding sensitive customer data.

Medusa remains present for 30 to 60 days before attacking. It publishes the negotiation live on a public blog where your customers can see it. This forces companies to pay to preserve customer relationships, regardless of whether they can restore their systems.

Protect your business

The 5 priority preventive measures

  • Patch perimeter devices within 72 hours of a critical CVE being published (VPN, firewall, RDP). This is the attack vector used by Akira, DragonForce and most RansomHub affiliates.
  • Segment your backups from the main network. A connected backup can be encrypted. Follow the 3-2-1 rule: 3 copies, 2 types of media, 1 off-site.
  • Enable MFA on all remote access: VPN, email and management tools. Credentials stolen through phishing will no longer be enough to open the door.
  • Monitor unusual outbound data transfers. Exfiltration generates network noise. A properly configured EDR can detect it before encryption begins.
  • Test your recovery plan. How long would it take to restore production from scratch? Many SMEs have backups but have never tested a full restore.

If you want to assess your actual exposure, request a free assessment: 30 minutes to identify exposed entry points and your real recovery capability.

Need a second opinion?

Let's talk for 30 minutes — no commitment

A direct conversation with a senior consultant to frame your cybersecurity priorities and clarify your obligations.

Book a call