Observed Signal · Jul 22, 2026 · Security Advisory · Source: DEV Community · Impact: 2/5 · Sentiment: Negative

96% of Ransomware Victims Are Small Businesses

Executive Signal Summary

A July 2026 analysis highlights that ransomware overwhelmingly targets small and medium-sized businesses (SMBs): Verizon's 2026 DBIR reports that 96% of ransomware victims (where size was known) were SMBs, and ransomware appears in 48% of confirmed breaches. Third-party involvement in SMB breaches has risen (55%), and many very small businesses still allocate no cybersecurity budget. The article describes the modern ransomware kill chain, identifies vulnerability exploitation as the top initial access vector, and calls out an urgent WordPress pre-auth RCE chain (CVE-2026-60137 + CVE-2026-63030, aka “wp2shell”) with fixes available in patched WordPress releases. Practical mitigations recommended include verified immutable backups, a quick security baseline scan, rapid patching, enabling MFA, and locking down admin surfaces.

Polaris7 AgentPolaris7 Strategic Assessment
High Confidence

Widespread ransomware targeting SMBs raises operational and supply-chain risks for small publishers, web properties, and service providers; the article also flags an immediate, exploitable WordPress pre-auth RCE chain that requires urgent patching.

SIGNAL RADAR

Track Verizon Signals & Market Shifts in Real-Time

Polaris7 autonomous intelligence agents track regulatory filings, primary sources, executive changes, and deal flow 24/7. Create your free Explorer workspace to monitor these entities.

Start Free in Explorer
Free Explorer tierNo credit card requiredInstant watchlist setup

Key Takeaways & Evidence Grounding

  • Verizon DBIR 2026 found 96% of ransomware victims (where organization size was known) were small and medium-sized businesses.
  • Ransomware appears in 48% of all confirmed breaches (Verizon DBIR 2026).
  • Third-party involvement in SMB breaches is 55% (Verizon DBIR 2026); third-party involvement across all breaches is 48%.
  • Median ransom payments fell below $140,000 and 69% of victims now refuse to pay (Verizon DBIR 2026).
  • An active pre-auth WordPress RCE chain (CVE-2026-60137 + CVE-2026-63030, called “wp2shell”) was disclosed and patched in WordPress 6.8.6, 6.9.5, and 7.0.2.

Connected Companies & Entities

6 Entities mapped

“Verizon's newly-released 2026 DBIR found that 96% of ransomware victims (where organization size was known) were small and medium-sized busi...”

“Independent breach-tracking from Proton's Data Breach Observatory puts businesses under 250 employees at roughly 63–71% of all breaches reco...”

“Global average breach cost $4.44M (down 9% YoY) — IBM Cost of a Data Breach 2025....”

“If you're behind Cloudflare (or any WAF), you're ahead of most. But here's what a WAF actually covers vs. what ransomware exploits:...”

Primary Source Grounding & Direct Attribution
Direct Origin Attribution
Primary Reporting: DEV Community•Published: Jul 22, 2026
Original Coverage Title: “96% of Ransomware Victims Are Small Businesses — How to Actually Protect Your Stack”

Related Market Signals & Shifts

Recent verified developments and strategic activity across this market segment.

CybersecuritySep 24, 2026

Survey: Cyberattacks hit 90% of European SMBs

A Kaspersky survey reveals that 90% of European small and medium-sized businesses (SMBs) experienced at least one security incident in the past year. The most severe incidents included broad malware attacks and attacks using legitimate administrator tools, each at 10%. Phishing and exploitation of vulnerabilities related to AI followed at 8% each. Personal customer data was affected in 28% of severe incidents, business strategy information in 26%, and sensitive data like financial access or legal documents in 25%. Many companies reacted by installing new security solutions, updating systems, introducing password policies, or conducting vulnerability scans. Kaspersky recommends restrictive access rights, automated backups, clear software installation guidelines, and regular security training for employees.

Read assessment
CybersecurityAug 24, 2026

90% of SMEs Affected by Cyberattacks

A Kaspersky study cited by Retail-News reports that 90% of surveyed small and medium-sized enterprises (SMEs) in Europe experienced at least one security incident within a year. The research finds that human factors — insufficient IT security knowledge, weak security culture, and poor organizational structures — are more often blamed for successful attacks than missing security technologies. Phishing affected 23% of respondents, AI-based attacks 18%, while vulnerabilities, business email compromise, supply-chain attacks and deepfakes each affected about 15%. Around 74% of surveyed companies have increased cybersecurity spending, investing in personnel, hybrid/cloud protection and security training; 65% plan further security investments. Kaspersky recommends combining modern security software with regular employee training, automated backups, strict access controls and email protection.

Read assessment
Security / VulnerabilityJul 20, 2026

Hackers Exploit Recently Patched WordPress Flaws

Security researchers and multiple cybersecurity firms warn that attackers are actively exploiting two recently patched critical WordPress vulnerabilities (affecting versions 6.9.0–6.9.4 and 7.0.0–7.0.1). WordPress pushed immediate and, where possible, forced updates after the fixes were released. Firms including Patchstack, Hexastrike, and WatchTowr reported in-the-wild exploitation. Researcher Daniel Card sampled ~4,200 sites and estimates under 15% remain vulnerable, which could extrapolate to roughly 90 million at-risk WordPress sites. The exploit chain includes a vulnerability dubbed WP2Shell, reported by Adam Kues of Searchlight Cyber. Cloudflare and web application firewalls have helped block some attacks while many sites remain exposed.

Read assessment

Track Real-Time Market Signals & Shifts

Set up custom watchlists to receive automated, evidence-grounded executive digests whenever material signals or shifts occur across your tracked landscape.