Ransomware 2026: The Target Is Not the Systems. It Is the Data.
2025 threat report: Organisations faced an average of 1,968 cyberattacks per week, 18% more than the previous year and nearly 70% more than in 2023. The new normal: high frequency, low barriers to entry, rising financial damage.
Ransomware: less encryption, more extortion economy
Ransomware hit record levels worldwide in 2025, with a 53% rise in victims listed on leak sites. Switzerland shows a more nuanced picture. Recorded case numbers actually fell slightly, according to recent analyses, from 77 cases in 2024 to 58 in 2025. That is no reason for false confidence. The attacks that do get through are more targeted and more costly. The market is shifting away from pure encryption toward a pure extortion economy built on data exfiltration. For Swiss boards, this means fewer hits, perhaps, but the ones that land go straight for the company’s existence and reputation.
For executive teams and boards, the risk equation is shifting. What used to be a classic infrastructure availability problem is increasingly becoming a data, liability and reputation problem, including follow-on costs for recovery, legal advice, communications and regulatory proceedings.
Attack vector 2026: trust in workflows
A clear trend stands out: attacks increasingly start not through exotic zero-days, but through what happens in companies every day anyway. Support, collaboration, browsers, identity processes. ClickFix is considered one of the most important social engineering techniques of 2025.
ClickFix activity rose by roughly 500%, and the method appeared in nearly half of all documented malware campaigns.
The principle is simple and dangerous. Users are led, through seemingly legitimate instructions, to carry out the harmful step themselves. Variants such as FileFix and ConsentFix have emerged from this, abusing legitimate system and cloud workflows, right up to OAuth flows.
The finding is uncomfortable. Classic technical defences work less well when the attack rides on ‘correct’ user behaviour inside a compromised process.
Voice and helpdesk attacks: the human ‘admin access’
Social engineering is moving away from email in parallel. Cross-platform, cross-channel campaigns combine phone calls, messaging and real-time impersonation. ‘Voice-driven’ social engineering is particularly relevant as an entry vector into highly critical enterprise incidents.
One example:
The incident involving Marks & Spencer is described as attackers gaining third-party access through convincing impersonation and helpdesk manipulation, which led to a ransomware deployment. Reported figures include roughly £300 million in lost profit and roughly £136 million net impact after insurance.
What matters is less the individual case than the method. Whoever controls identities and support processes bypasses many classic protective measures.
AI becomes infrastructure, and therefore an attack surface
By 2025, AI has become invisible in cyber reality. It sits inside development, reconnaissance, social engineering and malware optimisation. At the same time, attackers increasingly target the AI ecosystem itself, including agentic frameworks and integration layers.
Direct and indirect prompt injection are named as a growing pattern. Indirect prompt injection is particularly insidious, because malicious instructions can hide inside seemingly harmless artefacts: emails, documents, web pages, tickets, and so in the very data streams that assistants and agents routinely process.
Then there is the tool and agent layer. Where AI systems are given permissions, manipulation can translate into real actions, up to unintended tool invocations or data leakage. On top of that come risks around MCP ecosystems (integration servers, IDE plugins, configurations) and documented vulnerability patterns, from API key exposure to injection classes.
The central governance problem is now clear. AI is no longer just a productivity tool. It is becoming a system that consumes data, proposes decisions, and in part acts. As autonomy grows, so does the need to treat integrity, access and traceability the way critical production systems are treated.
Cybersecurity is steering, not a status report
The attack reality of 2026 concentrates along three axes:
- Scale: more attacks, more victims, more extortion pressure.
- Process exploitation: social engineering uses trust in workflows, identity and support as a shortcut.
- New attack surfaces: AI integrations and agent ecosystems create additional paths for manipulation and data leakage.
Treating this as a pure security initiative falls short. It is a question of operational stability, data accountability and governance. What matters is not how many tools are deployed, but whether a company applies the risk lever where attackers actually strike: at identities, processes and data flows.
Reporting duties and oversight obligations in Switzerland
In Switzerland, governance pressure is intensifying through clear duties and expectations:
- Operators of critical infrastructure have faced a statutory reporting duty since 1 April 2025. Cyberattacks must be reported to the Federal Office for Cybersecurity (BACS) within 24 hours of discovery; missing details may follow within 14 days. Sanctions for non-reporting have been in force since 1 October 2025.
- Under data protection law, Article 24 of the Swiss Data Protection Act (nDSG) requires notification to the FDPIC where a data security breach is likely to result in high risk to personality rights or fundamental rights, and this must happen ‘as quickly as possible’. The FDPIC sets this out in more detail in its guidance, including how to assess ‘high risk’ and how to proceed. With ransomware involving exfiltration in particular, cyber incidents automatically become legal, communications and liability matters too.
- For banks, operational resilience is formally anchored. FINMA Circular 2023/1 “Operational Risks and Resilience – Banks” has been in force since 1 January 2024. FINMA has also carried out cyber-specific on-site reviews and emphasises, among other things, the use of scenario-based cyber exercises.
What boards should demand now: 10 concrete questions a board must ask
- Crown jewels: Which 10 data or system assets are existential, and how is access segmented?
- Identity: Where do privileged accounts exist without strong controls (MFA, device trust, PAM)?
- Dwell time: How fast do we detect ‘quiet’ admin abuse? (Weeks is too slow.)
- Backups: Are backups immutable or offline, and protected against privileged destruction?
- Data exfiltration: What telemetry proves data actually left, not just alerts?
- Third parties: Which external identities have standing access? How is this monitored continuously?
- Cloud/SaaS drift: How do we measure configuration drift and risky integrations in real time?
- AI controls: Where are prompt injection and tool-call risks technically mitigated?
- IR readiness: When was the incident playbook last tested under real stress?
- Outcome metrics: Which five metrics do we report to the board quarterly, with trend and target?
If strategic cybersecurity is not yet an explicit board-level topic for you, it is worth a closer look. I help leadership bodies strengthen their decision-making capacity on cybersecurity.
Sources
- Ransomware-Fälle in der Schweiz 2025 erstmals rückläufig
- Erpressung und Ransomware sind für mehr als die Hälfte aller Cyberangriffe verantwortlich - Source EMEA
- Swisscom Cybersecurity Threat Radar 2025: neue Gefahren im Visier | Computerworld
- M&S says cyber hackers broke in through third-party contractor | Reuters
- Report | Cyber Security Report, 2026 | Check Point Software