Skip to content
← All posts
· 5 min read· By

Ransomware Wave 2026: Qilin Targets Manufacturing and Construction in German SMBs

176 German victims in H1 2026, ranked 4th globally — Qilin is zeroing in on manufacturing and construction. Threat landscape and 7 immediate actions.

IT SecurityRansomwareSMBManufacturingMittelstandRuhr Area

In the first half of 2026, a Bitdefender analysis recorded 176 German companies publicly claimed as ransomware victims — placing Germany 4th globally, just behind the USA, Canada, and the UK. Monthly incident counts nearly doubled over that period: from 22 in January to 42 in June 2026. The most active group in Germany goes by the name Qilin — and it is specifically targeting manufacturing and construction businesses.

For companies in the Ruhr Area, one of Germany's most densely industrialised regions, this is not an abstract warning. It is an active, ongoing threat with named victims — from the very industries that shape the Recklinghausen district and the wider Ruhr economy.

Disclaimer: This article is for general informational purposes only and does not constitute legal or security advice. Security incidents require professional support. Status: August 2026.

How serious is the situation? Germany's ransomware landscape in H1 2026

The Bitdefender analysis, published on 11 August 2026 at netzpalaver.de, captures only attacks that ransomware groups have publicised on their own leak sites. The actual number of incidents is substantially higher: when ransoms are paid, public disclosure is usually avoided.

Even so, the figures are stark. In the first half of 2026, 4,641 ransomware attacks were publicly claimed worldwide — up from 4,381 in the same period last year. Germany accounts for 176 of those, placing it 4th globally. The trend is not flattening; it is accelerating.

Who is Qilin — and why are manufacturing and construction so exposed?

Qilin operates a ransomware-as-a-service (RaaS) model: the group develops the malware, brokers initial access, and shares ransom payments with affiliate groups. In Germany, Qilin has been the most active ransomware group in 2026 so far, with 30 claimed victims — well ahead of Akira (21) and Safepay (14). Globally, Qilin recorded 1,358 claimed victims, an increase of 443 percent year-over-year, across more than 50 countries.

Manufacturing is the hardest-hit sector in Germany: 46 manufacturing companies were listed as victims in the first five months of 2026 — 25.3 percent of all German ransomware incidents. Across the DACH region, construction, technology, finance, and healthcare round out the top targeted sectors.

Recent confirmed victims published by Qilin on its leak site include Clausing Tiefbau (civil engineering, 08 August 2026) and Roth Industries (manufacturing, June 2026). These names represent the industries that form the economic backbone of the Ruhr Area and Recklinghausen district: metalworking, mechanical engineering, civil construction, and logistics.

Why are these sectors particularly vulnerable?

  • Operational pressure: Every hour of downtime costs thousands of euros. Attackers factor this in to maximise leverage when demanding ransoms.
  • Legacy IT infrastructure: Older, rarely updated systems expose a wide attack surface with known, unpatched vulnerabilities.
  • Mixed OT/IT networks: When office IT and production control systems are not properly segmented, ransomware can spread from a compromised office machine to PLCs, SCADA systems, and production machinery — causing damage far beyond data loss.

How does ransomware get into a business?

The leading attack vectors in 2026:

  • Infostealers and stolen credentials: Inconspicuous malware silently steals browser passwords, VPN credentials, and stored tokens. The harvested data is sold on underground markets — then used months later to launch targeted ransomware attacks. Roughly one in five Qilin victims had a corporate domain that had previously appeared in infostealer logs.
  • Unpatched VPN and remote access systems: Known but unaddressed vulnerabilities in VPN gateways and remote desktop services are a preferred entry point for Qilin and similar groups.
  • Phishing: Convincingly crafted emails trick employees into surrendering credentials or opening malicious attachments. Social engineering remains a widespread and inexpensive first-access vector for attackers.

7 immediate actions that make a difference right now

The following priorities are based on BSI recommendations and the CISA Ransomware Guide:

  1. Enforce MFA on all remote access. VPN, RDP, email, and admin interfaces must be protected with multi-factor authentication immediately. Phishing-resistant methods (FIDO2/passkeys) are far superior to SMS-OTP — SMS codes can be intercepted or redirected via SIM-swapping.

  2. Create offline backups and test restoration regularly. At least one backup copy must be stored offline, disconnected from the network. Critically: run regular restore tests. A backup that fails at recovery time offers no protection at all.

  3. Prioritise patching — VPN gateways and internet-facing systems first. Unpatched VPN endpoints are Qilin's preferred point of entry. The public CISA KEV catalogue (Known Exploited Vulnerabilities) provides a prioritised list of the most urgent vulnerabilities to address.

  4. Segment the network — separate OT and IT. Production and office networks must operate in distinct segments with no unfiltered connections between them. Segmentation stops ransomware from jumping from a compromised office device to industrial control systems.

  5. Harden privileged accounts (least privilege, PAM). Domain admin accounts must not be used for everyday tasks. Privileged access should be managed, logged, and time-limited through a dedicated Privileged Access Management system.

  6. Train employees — schedule phishing simulations. Regular security awareness training and realistic phishing simulations help office and administrative staff recognise suspicious messages and respond correctly.

  7. Create and rehearse an incident response plan. Without practised processes, businesses lose critical hours when an attack occurs. The plan must include offline communication channels, escalation paths, BSI reporting obligations, and contact details for specialised incident response providers.

For a foundational overview of preventive measures, see our earlier article Ransomware protection for small businesses.

What to do if you are hit

Immediately isolate affected systems from the network — but do not restart or wipe them, as forensic evidence would be lost. Paying the ransom is not a reliable solution: in a significant share of cases, the promised decryption does not work fully, and every payment funds the next wave of attacks. BSI CERT-Bund is available for reports and initial guidance. Companies subject to NIS2 also have a statutory reporting obligation.

Act now — before it is too late

If you are unsure whether your IT infrastructure is adequately protected against current attack methods, get in touch with us. We analyse your attack surface, prioritise the right measures, and help you stay operational when it matters most — for businesses in the Ruhr Area, the Recklinghausen district, and beyond.

Note: The articles on this blog are produced with the help of AI and are editorially reviewed before publication. Editorial responsibility lies with Emre Yurtbay (see the Impressum).

Discuss your project