U.S. small and mid-size businesses experienced a notable surge in ransomware attacks in Q2 2026 as cybercriminal groups escalated their campaigns. With federal agencies reducing SMB outreach and attackers leveraging AI, leaders face new challenges in protecting revenue and operations. The evolving landscape calls for board-level attention, proactive investment, and strategic partnerships.


Ransomware Surge Signals Escalating Stakes for SMBs
In the second quarter of 2026, reported ransomware attacks against U.S. small and mid-size businesses (SMBs) jumped to 769 incidents—an increase that threatens both business continuity and reputation. Most victims had fewer than 200 employees and under $25 million in annual revenue, underscoring that size is no defense. These attacks aren’t happening in isolation: competition among major ransomware gangs, particularly Qilin and The Gentlemen, is accelerating both the frequency and sophistication of campaigns targeting SMBs.
Ransom demands are rising, but operational disruption is often the greatest cost. In a recent analysis, business downtime and lost contracts collectively exceeded ransom payments by as much as 4:1. Missed orders, delays in payroll, and shaken partnerships have immediate revenue implications. For owner-led businesses, reputational fallout can have a lasting effect, especially when communication lapses or breaches spill into the public sphere.
With perpetrators leveraging automated tools and double-extortion tactics—encrypting files and threatening data leaks—the window for detection and response is shrinking. Even organizations with backup protocols have reported public leak threats, making after-the-fact mitigation far less effective in maintaining customer trust.


Targeted Manufacturing Attacks and Waning Federal Support
The manufacturing sector continues to face highly targeted digital intrusions. SonicWall’s 2026 report showed intrusion prevention activity dropped more than 56%, but attackers are using increasingly tailored techniques, including 43 million camera-based attacks and the highest observed rate of industrial control system targeting. This signals a shift from broad, high-volume attacks to surgical strikes aimed at the weakest digital links—be it a factory floor device or a remote office connection. Operational downtime in these scenarios can severely disrupt production schedules and supply chain commitments.
Meanwhile, the Cybersecurity and Infrastructure Security Agency (CISA) is reducing direct outreach and support to SMBs and local utilities. For many owner-operators who previously relied on CISA for cyber risk guidance, this creates a resource gap at a time when the threat landscape is intensifying. Decisions about software, staffing, and partnerships now rest more heavily on business owners and their advisors.
SMBs in the UK offer a preview of strategic responses to these shifts. Sixty-seven percent report lacking actionable cybersecurity plans, but a growing segment is moving beyond reactive defense—building formal partnerships and investing in external expertise for long-term resilience. In both the U.S. and abroad, small firms are quietly acknowledging that ad hoc spending is no longer sufficient.
AI-Driven Threats and Evolving Attack Patterns
Cybercriminals have begun using AI to identify and exploit weaknesses—namely, inconsistent user identity management and cloud misconfigurations—at scale. This increases both the speed and effectiveness of attacks, outpacing traditional defense tactics. The net effect is a faster-moving threat environment where vulnerabilities can be weaponized within days, not months.
At the same time, the shifting tactics from ransomware crews and targeted industry breaches highlight a pattern: the value of data and uninterrupted operations is climbing, and attackers know it. With revenue and customer trust at risk, SMBs can no longer relegate cybersecurity to the IT department or treat it as a compliance box-check. Instead, it must be part of core business planning and risk management discussions at the executive level.
What Business Leaders Should Consider
- Review and update business continuity and cyber response plans quarterly, factoring in ransomware-specific scenarios.
- Assess whether current security partnerships and insurance are adequate for today’s risks; consider formalizing relationships with specialized cybersecurity providers.
- Invest in basic AI-driven threat detection tools or managed services, particularly for identity and access management.
- Prioritize layered backups and tested recovery protocols, but also plan for public communications should a breach occur.
- Educate leadership and managers on evolving threats; cybersecurity should be a regular board agenda item, not a delegated IT task.
