Picture the operations lead at a 60-person distribution company. Tuesday morning, the shared drive won’t open. Then the accounting software throws an error. Then a text file lands on three desktops explaining that the files are encrypted and the clock is running. By the time anyone calls IT, the business is already down. This isn’t a Fortune 500 problem anymore. It’s a Tuesday problem for companies that used to think they were too small to bother with.
That feeling of “we’re too small to be a target” is exactly the assumption the numbers just broke.
What the July 2026 data actually shows
According to SWK Technologies’ July 2026 cybersecurity recap, two rival ransomware collectives, Qilin and a group calling itself The Gentlemen, each claimed close to 300 victims in Q2 2026 alone. SWK Technologies reports that total global ransomware volume was up roughly 20% year over year through the first half of 2026. And the detail that matters most for a company reading this: SWK Technologies reports that U.S.-based small and mid-sized businesses continue to absorb the largest share of incidents from both groups.
Read that last part again. Not collateral damage. The largest share. SMBs are no longer the accidental victims caught in a wide net aimed at bigger fish. They are the fish.
Why the shift? It comes down to attacker economics, and specifically to the affiliate model that both of these groups run.
Why SMBs became the preferred target
Groups like Qilin don’t do all the breaking-in themselves. They build the ransomware, run the payment infrastructure, and manage the leak sites, then rent the whole operation to affiliates who do the actual attacks. The affiliate keeps most of the ransom; the core group takes a cut off the top. This is ransomware-as-a-service, and it changes the math in a way that works against smaller companies.
Here’s the logic. A large enterprise has a dedicated security team, monitored endpoints, tested backups, and a lawyer on retainer for exactly this scenario. Breaking in takes weeks and might fail. A 40-to-150-person business often has one overworked IT person or a break-fix vendor, backups nobody has tested, and no plan for the first hour of an incident. Breaking in takes days and usually works.
When an affiliate is choosing where to spend effort, the smaller target is the better business decision. Lower defenses, faster payout, and enough companies to hit that the affiliate never runs out of options. Volume over size. That’s the model, and it’s why the incident share keeps sliding toward companies that never thought they’d make the list.
The ransom demands scale down too. A group that used to want seven figures from a hospital system will happily take $80,000 from a distributor, because the distributor is easier to hit and there are ten thousand more just like it. The affiliate model turns ransomware into a numbers game, and small businesses are where the numbers live.
Why this matters for your business
If you run operations at a company between 10 and 150 people, the old risk calculation no longer holds. “We’re not a target” was never a security strategy, but for a while the odds were quietly on your side. They aren’t anymore. The people attacking you have industrialized the process specifically because companies your size are the softest, most profitable place to spend their time.
The cost of an incident isn’t just the ransom. It’s the days of downtime while systems get rebuilt. It’s the customers who don’t get their orders. It’s the payroll you still owe while nothing is running. It’s the data on the leak site if you don’t pay, and the uncertainty about whether the attacker actually deleted anything if you do. For a small business, one bad week can be the difference between a rough quarter and closing the doors.
The good news is that the same thing that makes SMBs attractive targets, thin defenses, is fixable. Affiliates chase easy. You don’t have to be easy.
What to verify this month
You don’t need a bigger budget to close the gaps affiliates count on. You need to confirm a handful of controls are actually working, not just theoretically in place. Walk through these with whoever owns your IT.
- Test a backup restore, don’t just confirm backups exist. Most companies have backups. Far fewer have restored from one recently. Pick a system and actually recover it. If it takes days, or fails, you found the gap before the attacker did.
- Confirm backups are offline or immutable. Modern ransomware hunts for connected backups and encrypts those first. A backup the attacker can reach is not a backup. Verify at least one copy is isolated or write-protected.
- Turn on multi-factor authentication everywhere it isn’t already. Email, VPN, remote access, admin accounts. Stolen or guessed passwords are how most affiliates get in. MFA closes that door on most of them.
- Check that endpoint detection is actually deployed and monitored. Antivirus that nobody watches is not detection. Confirm you have a tool that flags suspicious behavior and a human or service watching the alerts.
- Patch the systems facing the internet. Affiliates buy access through known, unpatched vulnerabilities. Confirm your firewall, VPN, and any public-facing servers are current on updates.
- Write down the first hour. Who gets called, who can disconnect the network, who talks to staff. A one-page plan you’ve never needed beats a scramble when the drive won’t open. This is the cheapest control on the list and the one most companies skip.
None of this requires a new platform or a security team you can’t afford. It requires someone confirming, this month, that the basics work. Affiliates are running a volume business. The whole point is to make your company the one that isn’t worth the effort.
Common Questions
Are small businesses really being targeted more than large enterprises? According to SWK Technologies’ July 2026 recap, U.S.-based small and mid-sized businesses are absorbing the largest share of incidents from both Qilin and The Gentlemen. Smaller companies typically have thinner defenses and faster payouts, which makes them the better business decision for attackers working on volume.
What is the affiliate model and why does it matter? Groups like Qilin build the ransomware and rent it to affiliates who carry out the attacks and split the ransom. This lowers the skill needed to run an attack, multiplies the number of people attacking, and pushes them toward easier targets. It’s why smaller businesses have moved from accidental victims to preferred targets.
If we get hit, should we pay the ransom? That’s a decision to make with legal counsel, your insurer, and law enforcement, not in the first panicked hour. Paying doesn’t guarantee your data is returned or deleted, and it marks you as a company that pays. Tested, isolated backups are what give you the option to say no.
What’s the single most valuable thing to do first? Test a backup restore. Most companies have backups they’ve never actually recovered from. If your restore is slow or broken, that’s the gap the attacker is counting on, and you want to find it on your own schedule.
centrexIT has protected businesses across California, Nevada, Arizona, Washington, and Oregon since 2002. If you’re not certain your backups, MFA, and first-hour plan would hold up against a group running this playbook, that’s worth knowing before someone else finds out for you. Take the 2-Minute Cybersecurity Assessment: https://centrexit.com/cyber-security-readiness-assessment/
Sources
- Qilin and The Gentlemen ransomware groups each claimed nearly 300 victims in Q2 2026, with global ransomware volume up roughly 20% year-over-year through H1 2026 and U.S. SMBs absorbing the largest share of incidents: SWK Technologies, “Qilin & ‘The Gentlemen’ Ransomware Groups Hit Record Pace in July 2026” (2026), https://www.swktech.com/swk-cybersecurity-news-recap-july-2026/
The centrexIT team brings decades of combined IT expertise, helping San Diego businesses thrive with secure, reliable technology solutions.
Meet Our Team