// Blog / News

Ransomware is now a franchise business: what that means for small firms

Share

A ransomware trends report out this week put a striking number on something we have felt for a while: there are now around 146 active ransomware groups, with dozens of brand-new ones appearing in the past year alone. The takeaway is not another scary statistic. It is that ransomware has quietly turned into an industry, complete with software vendors, affiliates, and customer support, and that industrialisation is exactly why small businesses are getting hit more often.

What the numbers say

Researchers tracking the ecosystem counted roughly 61 new ransomware groups entering the market between spring 2025 and spring 2026, pushing the active total to about 146. Behind that growth is a model called ransomware-as-a-service (RaaS): a core group builds the malware and runs a slick platform, then rents it out to "affiliates" who carry out the actual break-ins and split the profits. Some of these operations run dedicated web portals where affiliates build payloads, manage victims, and track their cut, the trappings of a real software business.

Why a franchise model targets you

When attacking was a craft, it took skill and time, so criminals aimed at big, high-value targets to make the effort pay. RaaS removes that constraint. An affiliate with modest skills can rent professional-grade tools and go after whoever is easiest, and the easiest targets are small businesses with lighter defences. More attackers, lower skill barriers, and automation mean the net is cast far wider and far more often. This is the same shift that made AI-assisted attacks worth watching: the cost of attacking dropped, so smaller targets became worth it.

The other change: they steal before they lock

Modern ransomware is usually extortion-first. Before encrypting anything, attackers copy your data and threaten to publish it, which means a good backup alone no longer saves you from the worst outcome. We covered this shift when data theft became the headline act; the growth of the RaaS market just spreads that playbook to more attackers.

What actually protects a small business

The good news is that a bigger, busier criminal market does not need new defences, it makes the known ones matter more. The controls that stop the volume:

  • Phishing-resistant MFA on email, VPN, and cloud admin accounts. Stolen logins are how most affiliates get in.
  • Fast patching of anything internet-facing, since automated tools hunt for the unpatched.
  • Tested, offline backups so encryption is survivable, paired with the awareness that backups do not undo data theft.
  • A written incident response plan so a bad morning does not become a lost week.

Sources:Help Net SecurityBlackFog

Want the basics that stop most ransomware done properly, and watched?

Talk to us

Related