950 Ransomware Attacks, 80% on SMEs: Lessons for Mid-Sized Companies

The BSI-Lagebericht 2025 and Bitkom figures show: ransomware hits SMEs above all. Three controls decide the outcome – soberly assessed.

The BSI-Lagebericht 2025 (reporting period July 2024 to June 2025) names 950 reported ransomware incidents in Germany. 80 percent of the attacks were directed against small and mid-sized companies. Anyone who reads from this that ransomware is a problem of large corporations and critical infrastructure is reading the figures the wrong way around.

Two clarifications up front: first, 950 is the reported number of cases – the dark figure is substantial, and the actual number is higher. Second, the 80 percent rate is no coincidence. Attackers select not by prominence but by reachability. A company with 120 employees, an exposed VPN gateway, and backups on the same storage is a better target than a corporation with its own security operations center.

The situation in figures

From the BSI-Lagebericht and the Bitkom study Wirtschaftsschutz 2025 (presented on September 18, 2025), a consistent picture emerges:

  • 950 reported ransomware incidents, 80% of them against SMEs (BSI). In most cases, according to the BSI, the attacks were accompanied by data exfiltration – ransomware has long also been a data-protection and extortion problem, not just an availability problem.
  • On average 119 new vulnerabilities per day, up 24% year over year (BSI).
  • EUR 289.2 billion in total damage from theft, espionage, and sabotage over twelve months (about +8%), of which roughly EUR 202.4 billion – about 70% – from cyberattacks (Bitkom).
  • 87% of companies were affected by theft, espionage, or sabotage; 34% recorded damage from ransomware within twelve months (Bitkom).
  • 46% of affected companies each attributed attacks to Russia and China respectively (Bitkom).

The most uncomfortable figure: 56 percent

The most important statement of the situation report for mid-sized companies is not an attack figure but a self-diagnosis: according to the BSI, SMEs on average meet only about 56 percent of the baseline requirements of the BSI CyberRisikoCheck – and often assess their own situation too optimistically.

This is no occasion for alarmism, but for an honest stocktaking. The difference between perceived and actual security posture is exactly the space in which attackers work. The right question is not “Are we secure?” but: “Which of our baseline measures would hold up to scrutiny – and which would not?”

Case study Fortinet: when the security device itself becomes the entry point

How little “we have a firewall” means today is shown by a case from the start of the year: CVE-2026-24858, a second FortiCloud SSO bypass independent of the December case – an authentication-bypass vulnerability in the FortiCloud SSO mechanism that affected FortiOS, FortiAnalyzer, FortiManager, and FortiProxy in version levels between 7.0 and 7.6 depending on the product. It was actively exploited – even against fully patched devices. Attackers created local admin accounts and exfiltrated device configurations. Fortinet published advisory FG-IR-26-060 on January 27, 2026, and temporarily suspended FortiCloud SSO globally on January 26; it was reactivated initially only for patched devices. Secondary sources cite a CVSS score of 9.4 and inclusion in the CISA KEV catalog.

Three lessons from this, independent of the vendor:

  • Management interfaces of firewalls and security appliances never belong on the internet. Administration only over separate management networks or VPN.
  • Patching alone is not enough. Here even patched devices were affected – the attack was detected via conspicuous accounts and configuration accesses, that is, via monitoring.
  • Cloud convenience functions such as central SSO enlarge the attack surface and belong deliberately enabled or disabled, not left at the default.

Three controls that decide the outcome

From the incidents that end well and badly, a pattern can be derived. Three controls make the difference:

1. A hardened and monitored perimeter

Firewalls, VPN gateways, and load balancers are the most-attacked systems in the company – and often the worst monitored. They need consistent hardening, timely patching, and monitoring that reports new admin accounts or configuration changes. Network and security engineering is not a project here but an ongoing task.

2. Round-the-clock detection

Ransomware attacks frequently escalate at night and on weekends, when no one responds to alerts. Between initial access and encryption lies a window – whoever uses it limits the damage; whoever sleeps through it loses the environment. Without 24/7 monitoring, this window goes unused.

3. Tested, immutable backups

Attackers seek out and destroy backups deliberately before they encrypt. Decisive are therefore immutable backup copies, separate access paths – and regularly practiced restores. A backup whose restore has never been tested is a hope, not a plan.

Conclusion

The figures from BSI and Bitkom describe not an abstract threat landscape but the everyday reality of mid-sized IT. The good news: the decisive controls are known, established, and attainable for companies between 50 and 500 employees. The 56-percent gap does not close through new products, but through consistent implementation of the basics.

How sector7 supports you

As an owner-led firm with engineering practice on Juniper, Cisco, HPE, F5, Fortinet and Palo Alto Networks, we harden and operate exactly the perimeter systems at issue in cases like CVE-2026-24858. Our NOC monitors customer environments around the clock, our Veeam practice takes care of immutable backups including tested restores – on request as a managed service at flat monthly rates.

Sources

Let's talk about your situation.