European organizations are facing an unprecedented wave of ransomware attacks as cybercriminals increasingly artificial intelligence (AI) tools into their businesses.

Since January 2024, threat actors engaged in “big game hunting” have placed approximately 2,100 European-based victimson more than 100 data breach sites (a 13% year-on-year increase in attacks).
The region now accounts for nearly 22% of all global ransomware victims tracked, making it the second most targeted region after North America. Organizations in the UK, Germany, Italy, France and Spain have borne the brunt of these attacks, with the manufacturing, professional services and technology experiencing the greatest losses.
See also: Russian Curly COMrades abuses Windows Hyper-V
Why are ransomware attacks increasing in Europe?
The increase in ransomware activity across Europe stems from a number of factors that make the region particularly attractive to threat actors. Cybercriminals are exploiting the European Union’s General Data Protection Regulation (GDPR), threatening to report victims for non-compliance with the regulations during ransom negotiations.
The economic incentive remains significant, as Europe is home to five of the ten most valuable companies in the world, allowing threat actors to demand significant ransoms based on the organizations’ revenues.

Additionally, some cybercriminals have expressed political motivations, with some groups supporting geopolitical conflicts and collaborating with hybrid threat actors for mutual benefit.
CrowdStrike researchers noted that adversaries are increasingly using sophisticated tactics to maximize their impact. During the reporting period, from January 2024 to September 2025, threat actors heavily utilized credential dumping from backup and restore configuration databases , which often contain access to hypervisor infrastructure .
See also: Google warns of new AI-powered malware families
Attackers often executed ransomware from unmanaged systems that lacked endpoint detection and response software, allowing them to remotely encrypt files while evading traditional security measures.
A particularly worrying trend includes the development of Linux ransomware targeting VMware ESXi infrastructure, allowing adversaries to compromise entire virtualized environments at once.
The underground ecosystem supporting these operations has proven remarkably resilient despite law enforcement efforts. Russian-language forums like Exploit and XSS facilitate collaboration between threat actors, offering initial access brokers, malware-as-a-service providers, and even “violence-as-a-service operations.”
English-language platforms like BreachForums have created accessible marketplaces where adversaries exchange compromised credentials, tools, and information.
See also: DragonForce Cartel: New methods of attack
☁️ Keep safe copies with Proton Drive
Encrypted cloud storage from Proton — protect your files from ransomware, corruption, and data loss with end-to-end encryption.
- ✔ End-to-end encrypted files & backups
- ✔ Version history — recover files after ransomware
- ✔ Free space — sync across all devices
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

Integrating AI into ransomware attacks
The integration of AI capabilities has transformed the way threat actors conduct their operations across Europe. Adversaries are leveraging large language models to create more convincing phishing content and produce polymorphic code that evades signature-based detection systems. CrowdStrike researchers have identified campaigns where threat actors have used AI-powered tools to automate reconnaissance activities , allowing them to scan thousands of potential targets and identify vulnerable systems at unprecedented speed. The sophistication extends to operations social engineering , where adversaries are using AI-generated voice for vishing campaigns that convincingly mimic legitimate support staff. Voice phishing has emerged as a significant threat vector and initial step for ransomware attacks.
