Security

Ransomware doubles in Spain in 2026: what SMEs can do

From Inditex to a seaport, attacks no longer discriminate by company size. Here's what the official figures show and how to reduce the real risk.

Published on August 8, 2026 · The mitza.es team

INCIBE handled 122,223 cybersecurity incidents in Spain during 2025, 26% more than the previous year. Within that figure, ransomware attacks rose from 176 to 392 in just twelve months — practically doubling. And it's not only a problem for large corporations: 60% of the incidents recorded directly affected SMEs and freelancers.

Cases that have defined the year

2026 has brought several incidents showing just how exposed every sector is. Inditex and Endesa suffered attacks originating from external technology suppliers, confirming that the supply chain is today one of the weakest links. The Ahorramás supermarket chain was targeted by the Qilin gang, and the Port of Vigo had to disconnect part of its IT system in late March to stop an ongoing attack. The Basic Fit gym chain exposed data belonging to more than 4.5 million users across Spain, France and Germany, and biopharmaceutical company Diater appeared on the DeadLock group's victims site.

Why SMEs are such a frequent target

  • They typically have fewer basic security measures than a large corporation, yet handle equally valuable data.
  • Many attacks arrive through a supplier or subcontractor with weaker controls, not directly.
  • A single ransomware attack can paralyze day-to-day operations for days if there are no tested backups.
  • Paying the ransom doesn't guarantee getting the data back, nor does it prevent it from being leaked anyway.

Minimum measures that reduce real risk

You don't need an in-house security department to eliminate a large share of the exposure. Automated backups that are tested regularly, systems kept up to date, access control with multi-factor authentication, and a minimum incident response plan cover most common scenarios. This connects directly with the obligations already required by the NIS2 directive for companies within its scope, and with good practices any SME should apply even when not legally required to.

From theory to reviewing your systems

The difference between suffering a crippling attack and absorbing it with barely any impact usually comes down to prior preparation, not luck. Our IT maintenance service includes a basic security review of devices and backups, and if you need a more complete diagnosis of your exposure, you can request a tailored audit.

When did you last check your backups?

We run a basic security review of your devices and systems before the problem shows up.

No spam. No sales calls. Just your personalised reply.