Short answer: CrowdStrike’s 2025 European Threat Landscape Report found that Europe accounted for nearly 22% of the ransomware and extortion victims listed in the company’s monitored leak-site data. It counted approximately 2,100 Europe-based victims named on dedicated leak sites from January 1, 2024, and reported a 13% year-over-year increase in European entries. Those figures describe leak-site observations, not every ransomware attack, confirmed loss, or organization affected in Europe.
What does CrowdStrike’s report say about ransomware in Europe?
CrowdStrike released its 2025 European Threat Landscape Report on November 3, 2025. The report says European organizations represented nearly 22% of the global ransomware and extortion victims in the leak-site data it tracks, making Europe the second-largest regional grouping after North America.
In absolute terms, CrowdStrike says approximately 2,100 Europe-based victims had been named on dedicated leak sites since January 1, 2024. Its report landing page also records a 13% year-over-year rise in entries naming Europe-based entities.
These are vendor-reported observations from monitored criminal leak sites. A listing can represent an attacker’s claim and does not by itself establish that an intrusion was independently confirmed, that data was actually stolen, that encryption occurred, or that a ransom was paid.
Recommended Free Tools
#1 Best Overall
Is ransomware increasing in Europe?
CrowdStrike’s data indicates more Europe-based entries in its monitored leak-site dataset than in the previous year, which supports describing an increase in those observations. It does not prove that every form of ransomware activity across Europe rose by the same percentage.
The report covers findings published in 2025 and activity measured through that reporting period. It does not establish whether Europe’s ransomware rate continued rising in 2026. CrowdStrike’s newer global summary discusses 2025 activity, including a fastest reported eCrime breakout time of 27 seconds, but it is not a Europe-specific ransomware measure.
Which European countries and sectors are most affected?
For its big-game-hunting analysis, CrowdStrike identifies these countries as the most targeted:
Rank #2
- United Kingdom
- Germany
- Italy
- France
- Spain
The sectors it highlights are:
- Manufacturing
- Professional services
- Technology
- Industrials and engineering
- Retail
“Most targeted” here means most prominent in CrowdStrike’s tracked activity; it is not a population-adjusted risk ranking. Countries with fewer recorded leak-site listings may still experience serious attacks, including incidents that never become public.
Free tools Windows power users keep installed
One-click scans. No signup required.
What do the European cases involve?
CrowdStrike says 92% of the European cases described in its release involved both file encryption and data theft. That combination reflects the double-extortion model: criminals encrypt systems to disrupt operations while also threatening to publish or sell copied information.
The percentage applies to the cases described by CrowdStrike, not to all European ransomware incidents. It also does not mean that the remaining cases were harmless; some may have involved data theft without encryption, encryption without confirmed theft, or other forms of extortion.
How are ransomware groups getting into European organizations?
Voice phishing
CrowdStrike describes voice phishing as an access technique used against European organizations. Attackers use phone calls or voice communications to impersonate trusted staff, suppliers, help desks, or service providers and persuade employees to reveal credentials, approve access, or bypass a control.
Fake CAPTCHA pages
The company also reports more than 1,000 incidents involving fake CAPTCHA lures that affected Europe-based organizations in 2024 and 2025. These pages imitate a “verify you are human” prompt but direct the visitor through malicious instructions, downloads, or commands intended to compromise the device or account.
Because social engineering can defeat otherwise strong technical controls, organizations should treat unexpected support calls, urgent authentication requests, and unfamiliar CAPTCHA prompts as security events rather than routine web friction.
Rank #4
How does ransomware fit the wider European threat environment?
CrowdStrike places financially motivated ransomware and extortion alongside state-backed operations and hacktivism. Its actor assessments describe several overlapping pressures:
- Russian-nexus activity: targeting connected to the war in Ukraine and related regional interests.
- Chinese-nexus activity: intelligence collection affecting government, healthcare, and biotechnology.
- DPRK-linked activity: targeting defense, diplomatic, and financial entities.
- Iran-linked activity: espionage, hack-and-leak operations, and destructive campaigns.
- Hacktivism: politically motivated disruption and publicity-driven operations.
These categories should not be collapsed into one ransomware statistic. Criminal groups generally pursue money through extortion, while state-linked actors may seek intelligence, influence, disruption, or strategic access. The same organization can face several of these threats at once.
“The cyber battlefield in Europe is more crowded and complex than ever,” said Adam Meyers, head of Counter Adversary Operations at CrowdStrike. “We’re seeing a dangerous convergence of criminal innovation and geopolitical ambition, with ransomware crews using enterprise-grade tools and state-backed actors exploiting global crises to disrupt, persist, and conduct espionage.”
Quick wins for a faster PC:
Repair Windows errors before they cause bigger problemsFix Now →Scan for outdated or missing drivers - takes under a minuteDriver Scan →Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
CrowdStrike says its Counter Adversary Operations team tracks more than 265 named adversaries. That is the company’s own tracking figure, not an independently audited count of all threat groups operating in Europe.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.What the leak-site numbers can—and cannot—tell you
| Question | What CrowdStrike’s figures show | What they do not establish |
|---|---|---|
| How many victims? | Approximately 2,100 Europe-based names on dedicated leak sites since January 1, 2024 | A census of every ransomware victim or incident in Europe |
| Regional share | Nearly 22% of victims in CrowdStrike’s tracked global leak-site data were European organizations | Europe’s share of all attacks, losses, or ransom payments |
| Trend | A 13% year-over-year rise in Europe-based entries in that dataset | A definitive 2026 trend or a rise in every ransomware measurement |
| Technical impact | 92% of the described European cases involved file encryption and data theft | The same ratio across all European incidents |
| Access methods | Voice phishing and fake CAPTCHA lures are observed techniques; more than 1,000 fake CAPTCHA lure incidents affected Europe-based organizations in 2024 and 2025 | The total number of social-engineering intrusions in Europe |
Leak-site research is useful for identifying public extortion activity and victim patterns, but it is inherently selective. Incidents may be omitted when criminals do not operate a leak site, victims negotiate privately, a site is taken down, or the attacker’s claim cannot be verified.
How should you compare this report with other ransomware statistics?
Different reports often count different things. Before comparing a number with CrowdStrike’s, check:
- Unit of measurement: leak-site victim claims, incidents confirmed by responders, organizations reporting disruption, or victims that paid.
- Observation period: the exact start and end dates, and whether the figure is a one-year change or a cumulative total.
- Geographic scope: headquarters, affected operations, reported victim location, or the country of the investigated infrastructure.
- Extortion definition: whether data theft without encryption is included alongside conventional ransomware.
- Collection bias: whether the publisher’s own customers, telemetry, incident-response cases, or public disclosures shape the dataset.
Keep criminal ransomware and extortion separate from state-linked espionage and hacktivism when drawing conclusions. Similar labels can conceal very different objectives and evidence standards.
Quick Recap
What should European organizations do with these findings?
- Train staff to challenge unexpected voice requests, urgent credential prompts, and instructions that bypass normal support procedures.
- Block or investigate suspicious browser prompts, especially fake CAPTCHA pages that request downloads, command execution, or unusual clipboard actions.
- Use phishing-resistant multifactor authentication for privileged and remote access where possible.
- Maintain tested, offline or otherwise protected backups and rehearse restoration of critical services.
- Separate administrative privileges, segment high-value systems, and monitor identity activity as closely as endpoint activity.
- Prepare an incident plan covering legal duties, regulators, customers, insurers, law enforcement, and extortion communications.
- Measure internal incidents separately from public leak-site listings; a missing listing is not evidence that an attack did not occur.
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

