In late 2024, cybercriminals made a subtle shift: they no longer encrypt immediately. They copy data first, stay hidden for several weeks, then strike. For an SME, that changes everything. Backups alone can no longer protect you from having your data published.
Current landscape
What has changed since 2024
+38%
Increase in ransomware attacks
Against French SMEs compared with 2024
21 days
Average presence before encryption
The attacker maps the network in silence
72 hrs
NIS2 notification deadline
After detecting a significant incident
For a long time, ransomware followed a simple pattern: break in, encrypt, demand payment. SMEs that kept their backups up to date could recover without paying.
That model is obsolete.
Groups active in 2026 now use double extortion almost systematically:
Phase 1 (D-30 to D-7)
Silent exfiltration
The attacker breaks in, maps the network, identifies sensitive data (HR, accounting, contracts) and quietly copies it to an external server.
Phase 2 (D-0)
Encryption begins
Within hours, servers, workstations and backups connected to the network are encrypted. The ransom note appears.
Phase 3 (D+1)
Double pressure
Pay for the decryption key AND pay to prevent the data from being published on a public leak site.
Who is attacking
5 groups targeting French SMEs
1. Akira
Target: Mid-sized companies with 50 to 500 employees, in manufacturing and B2B services.
Akira enters through unpatched Cisco VPNs, moves laterally for 2 to 3 weeks, exfiltrates accounting data and contracts, then encrypts the systems. The average ransom ranges from €150,000 to €300,000.
2. RansomHub
Target: Organisations of all sizes and in all sectors. RaaS model: affiliates keep 90% of the ransom.
In 18 months, RansomHub has become the platform most widely used by French-speaking affiliates. Its 90/10 model attracts opportunistic operators who target indiscriminately. Its distinguishing feature is a public “time until publication” countdown designed to maximise pressure.
3. Qilin
Target: Healthcare institutions, local authorities and digital service providers.
If you are a subcontractor to a hospital or local authority, you may be the entry point. Qilin gets in with credentials stolen from exposed services such as RDP and business portals.
4. DragonForce
Target: Manufacturers, distributors and transport companies.
DragonForce targets subcontractors to large companies to work its way towards the ultimate target. Your SME is not the main target; it is the necessary route in. This means you could lose a major contract after an attack, even if you pay.
5. Medusa
Target: Accountancy firms, law firms and SMEs holding sensitive customer data.
Medusa remains present for 30 to 60 days before attacking. It publishes the negotiation live on a public blog where your customers can see it. This forces companies to pay to preserve customer relationships, regardless of whether they can restore their systems.
Protect your business
The 5 priority preventive measures
- Patch perimeter devices within 72 hours of a critical CVE being published (VPN, firewall, RDP). This is the attack vector used by Akira, DragonForce and most RansomHub affiliates.
- Segment your backups from the main network. A connected backup can be encrypted. Follow the 3-2-1 rule: 3 copies, 2 types of media, 1 off-site.
- Enable MFA on all remote access: VPN, email and management tools. Credentials stolen through phishing will no longer be enough to open the door.
- Monitor unusual outbound data transfers. Exfiltration generates network noise. A properly configured EDR can detect it before encryption begins.
- Test your recovery plan. How long would it take to restore production from scratch? Many SMEs have backups but have never tested a full restore.
If you want to assess your actual exposure, request a free assessment: 30 minutes to identify exposed entry points and your real recovery capability.
Let's talk for 30 minutes — no commitment
A direct conversation with a senior consultant to frame your cybersecurity priorities and clarify your obligations.
Book a call