TL;DR: Q2 2026 ransomware data from NordStellar and adjacent threat-intelligence sources shows the SMB tier absorbed a disproportionate share of the quarter's damage. Total Q2 2026 ransomware incidents: 2,581, with Qilin (299 incidents) and The Gentlemen (284 incidents) as the two most active RaaS operations. US SMBs (organizations with up to 200 employees and under $25M in revenue) took 769 of those incidents, more than eight times the second-place country (Canada, 97). 88% of all ransomware incidents involved small and midsize businesses, and small-business-specific ransom costs ranged between $120,000 and $1.24 million. The underlying dynamic is a rivalry between Qilin and The Gentlemen for market position, and rivalry translates into volume: both operations are running more affiliates, releasing more novel tooling, and moving down-market to smaller targets to feed the affiliate pipeline. For NC SMBs, this is not a "cybersecurity trend" data point. It is an operating environment where the base-rate probability of a ransomware incident is measurably higher than it was in Q1 2026.
Key takeaway: The 2026 ransomware market is not becoming safer for SMBs; it is becoming more crowded and more aggressive at the SMB tier specifically. Owners who last reassessed defenses in 2024 or 2025 are working from a threat model that no longer matches the environment.
Do you want an outside read on your NC small business ransomware readiness against Qilin, The Gentlemen, and the current RaaS market? Contact Preferred Data Corporation for a same-month ransomware-readiness assessment and remediation program. BBB A+ rated. On-site within 200 miles of High Point. Call (336) 886-3282.
What Do the Q2 2026 Ransomware Numbers Actually Tell NC SMBs?
The consolidated Q2 2026 ransomware picture is a portrait of a market where SMBs are the primary revenue engine for the RaaS operators, and where two operators (Qilin and The Gentlemen) are driving a growth spiral through affiliate expansion.
Three concrete facts every NC SMB owner should treat as confirmed:
- US SMBs absorbed 769 ransomware incidents in Q2 2026. That is a rate of roughly 260 US SMB incidents per month, or 8-9 per business day. The next-highest country (Canada) took 97 incidents in the same quarter. The US SMB tier is a specifically attractive target.
- 88% of all ransomware incidents involve SMBs. SMBs are not "collateral damage" of ransomware operations aimed at Fortune 500s. They are the primary customer base. Over two-thirds of ransomware attacks between 2024 and 2025 targeted businesses with fewer than 500 employees, and Q2 2026 continued the pattern.
- Small-business ransom costs range from $120,000 to $1.24 million. The lower end is a small ransom or a strong recovery from backups; the upper end includes ransom payment, negotiator fees, recovery costs, business interruption, legal, and notification. Median for a Piedmont Triad SMB in the 40-150 employee range is $280,000-$450,000.
The Qilin vs. Gentlemen rivalry is the specific market dynamic driving volume. Qilin ran 299 incidents in Q2; The Gentlemen ran 284, up 39% from Q1. Both operations use the ransomware-as-a-service model, in which the core operator provides the malware and infrastructure and independent affiliates execute the intrusions. Rivalry means more affiliates recruited, more novel tooling released to attract affiliates, and more pressure on affiliates to close deals. All of that translates directly into more attempts against SMBs.
Key takeaway: The 769 US SMB Q2 2026 incidents figure is not "US SMBs are unusually vulnerable." It is "US SMBs are the most valuable target market in the RaaS economy right now." Volume follows profitability.
Why Are SMBs the Preferred Target in the 2026 RaaS Economy?
Ransomware actors target SMBs because the economic math works better at the SMB tier than at the enterprise tier for a specific set of reasons.
Three concrete reasons the RaaS market moved down-market in 2024-2026:
- SMBs pay faster and negotiate less. The typical Fortune 500 victim engages a full breach-response team, legal counsel, cyber-insurance carrier, and law enforcement, and negotiation windows extend to 30-60 days. The typical SMB victim negotiates in 3-14 days with less sophisticated defense support, and the pay-vs-recover math often tilts toward pay because the business cannot survive the downtime.
- SMBs have weaker defenses per dollar of revenue. IT spending as a percentage of revenue averages 6.9% for SMBs versus 4.3% for enterprises. The gross-dollar IT budget is smaller, and modern EDR, MDR, immutable backup, and 24/7 SOC coverage are enterprise-priced. Many SMBs still run traditional AV, writable NAS backups, and no after-hours monitoring.
- SMBs have less mature incident-response readiness. Fortune 500 organizations run quarterly tabletop exercises, retain outside IR firms on standby, and have documented decision trees for pay-vs-recover. Most SMBs discover their playbook does not exist the day the ransom note appears.
The Q2 2026 data is a market signal: RaaS operators went where the margin is. NC SMBs that treat "we are too small to be a target" as a defense strategy are running the exact strategy the RaaS market prices into its targeting decisions.
What Is the NC SMB Ransomware Defense Playbook for the Rest of 2026?
The response is a coordinated five-track program aligned to the current threat model. All five tracks run in parallel over 60-120 days.
Track 1: Identity plane hardening.
- Enforce MFA everywhere. Every user, every admin, every service where a service account cannot be constrained. Microsoft Entra Conditional Access, Duo, or Okta enforcement.
- Eliminate legacy authentication protocols. Basic Auth, POP3, IMAP, SMTP AUTH without OAuth. Every one is an MFA bypass.
- Rotate credentials after any suspicious event. Do not wait for confirmation.
Track 2: Endpoint plane hardening.
- Deploy EDR on 100% of workstations and 100% of servers. SentinelOne, CrowdStrike Falcon, Microsoft Defender for Endpoint Plan 2, Sophos Intercept X, Huntress. Traditional AV is not sufficient in 2026.
- Establish 24/7 alert response. Either an internal team with rotation coverage or an MDR partnership. Q2 2026 attacks routinely detonated between 10pm and 4am US Eastern local time, when unattended SMB EDR alerts sit in a mailbox unread.
- Block macro-enabled Office documents from the internet. Microsoft's default is to block; verify the setting has not been changed to allow.
Track 3: Backup and recovery hardening.
- Deploy immutable backup as the third copy. Wasabi, Backblaze B2, Azure immutable blob, AWS S3 Object Lock, Veeam Hardened Repository, Datto Immutable Cloud Series. A NAS with a mapped drive is not immutable.
- Perform a documented restore test every 90 days. Full-system restore of at least one production server to a test environment. Written record of restore time and success.
- Document the recovery time objective (RTO) per system class. File servers, email, ERP, CRM, line-of-business.
Track 4: Network and segmentation.
- Segment domain controllers, backup infrastructure, and EDR management from user workstation VLANs. East-west traffic paths are the ransomware highway.
- Restrict SMB, WinRM, and RDP to specific admin jump-hosts. Everywhere-to-everywhere flat networks are the pre-2020 default; they should be gone by 2026.
- Log firewall east-west denies to the SIEM. Denied traffic that pattern-matches a lateral-movement attempt is a leading indicator.
Track 5: Incident-response readiness.
- Run a ransomware tabletop exercise every six months. Owner, IT lead, insurance broker, outside counsel, MSP. 90-minute session, no laptops.
- Retain an outside IR firm on standby. Not "we will call one if it happens." A signed retainer with response-time SLA.
- Confirm cyber insurance coverage terms in writing. Ransomware sublimit, KEV-exclusion language, business-interruption trigger. Ask the broker to walk you through the specific denial scenarios.
For a typical NC SMB in the 40-150 employee range, the five-track program is a 90-180 day rollout at $30,000-$80,000 in year-one cost, then $18,000-$45,000 annual maintenance. The alternative, the mid-case Q2 2026 SMB ransomware cost of $280,000-$450,000, is 6-15x the year-one defense investment.
How Does 2026 SMB Ransomware Look Compared to 2020 SMB Ransomware?
The 2026 ransomware environment for NC SMBs is qualitatively different from the 2020 environment across several dimensions.
Comparison: 2020 vs. 2026 SMB ransomware market.
| Element | 2020 State | 2026 State |
|---|---|---|
| Primary attack vector | Phishing to macro-enabled Office | MFA fatigue, VPN/appliance zero-days, OAuth abuse, phishing |
| Time from initial access to encryption | 3-7 days | 4-72 hours (LLM-assisted attackers accelerate) |
| SMB ransom demand median | $50,000-$150,000 | $200,000-$600,000 |
| Double-extortion prevalence | Emerging | Standard (98%+ of incidents) |
| Data-exfiltration volume typical | 50-200 GB | 500 GB - 5 TB |
| RaaS operator count | ~15 major | ~50 major, 100+ minor |
| MDR / 24/7 SOC as SMB standard | Rare | Table stakes for cyber insurance |
| Cyber insurance ransomware coverage | Full policy limit typical | 25-50% sublimit common |
| Q2 US SMB incident volume | ~120 | 769 |
The volume growth (120 → 769 across roughly six years) is a 6x expansion, and the operator count growth is a similar 3-6x expansion. NC SMBs that maintained a 2020-era defense posture into 2026 are working against a market that scaled up around them.
Explore Preferred Data's cybersecurity services
How Does Preferred Data Handle NC SMB Ransomware Readiness?
Preferred Data has integrated ransomware readiness into every managed cybersecurity retainer since 2022 and refreshed the program specifically against the Q2 2026 threat data.
PDC's five-layer ransomware readiness program for NC SMBs:
- Baseline assessment against the current threat model. Q2 2026 Qilin, Gentlemen, and adjacent RaaS TTPs mapped to your specific environment. Gap report on the five-track program above.
- Remediation execution. MFA rollout, EDR deployment (workstations and servers), immutable-backup provisioning, restore-test execution, network segmentation. Progress reported weekly.
- 24/7 SOC coverage via MDR partnership. After-hours alert response, ransomware detonation containment, credential rotation triggers.
- Semi-annual tabletop exercise. Owner, IT lead, insurance broker, outside counsel, PDC. Written after-action report with named remediation items.
- Cyber-insurance evidence packet. Continuous refresh of the identity, endpoint, backup, and IR-readiness evidence for renewal-cycle assembly.
Cost for a typical NC SMB in the 40-150 employee range: $30,000-$80,000 for the year-one program build, $18,000-$45,000 annual maintenance thereafter. Ransomware readiness is not an insurance-adjacent nice-to-have; it is the primary defense against a market that measurably grew in Q2 2026.
Frequently Asked Questions
Is my NC small business really a target for Qilin or The Gentlemen?
The Q2 2026 data says yes. 769 US SMB incidents in a single quarter is not "a few unlucky organizations." At current attack rates, a US SMB in the 40-500 employee range has a materially higher probability of experiencing a ransomware incident in 2026 than in any prior year. Qilin and The Gentlemen affiliates specifically target SMBs because the ransom-per-attempt math works better than at the enterprise tier.
How much does ransomware actually cost a Piedmont Triad SMB?
Small-business ransom costs range from $120,000 (low end, strong backup recovery) to $1.24 million (high end, ransom paid plus recovery plus business interruption). Median for a Piedmont Triad SMB in the 40-150 employee range is $280,000-$450,000, including ransom payment (if paid), negotiator fees, recovery labor, legal, notification, and 5-15 days of business interruption.
What is the difference between EDR and traditional antivirus?
Traditional antivirus is signature-based: it recognizes known malware by matching file hashes or byte patterns. Endpoint Detection and Response (EDR) is behavior-based: it watches process activity, network connections, registry changes, and file operations, and flags patterns that indicate malicious activity even when the underlying malware is novel. Modern ransomware routinely uses novel malware or living-off-the-land binaries that traditional AV cannot detect. EDR is table stakes for 2026 SMB defense.
Do we need 24/7 SOC coverage if we are a 60-person company?
Q2 2026 attacks routinely detonated between 10pm and 4am US Eastern local time. If your EDR fires an alert at 2am and no one responds until 8am, you have already lost. 24/7 SOC coverage is a materially harder ask for an SMB than for an enterprise, which is why MDR (managed detection and response) partnerships exist. MDR outsources the after-hours coverage to a partner with a 24/7 SOC and defined response-time SLAs.
Can our backups actually recover us from a ransomware attack?
Only if the backups are (a) immutable (cannot be deleted or encrypted by an attacker with domain-admin credentials), (b) tested (a documented restore in the last 90 days), and (c) segmented from the production network (an attacker with domain-admin cannot reach them). Many SMBs have "backups" that fail all three tests. A NAS with a mapped drive letter reachable from the file server, no restore test in 18 months, and administrator credentials shared between backup and production is not a backup posture that survives 2026 ransomware.
What is a ransomware tabletop exercise and do we need one?
A tabletop is a facilitated conversation, not a technical drill. The facilitator (typically your MSP or an outside IR firm) walks the owner, IT lead, insurance broker, and outside counsel through a specific ransomware scenario over 60-90 minutes. Decisions are surfaced: Who calls the insurer? Who talks to the attacker? Who authorizes payment? What is the RTO for email? What if backups are also encrypted? The value is the surfacing of assumptions and gaps before the real incident.
Does cyber insurance cover the whole cost of a ransomware event?
Not usually in 2026. Ransomware sublimits (25-50% of the policy limit) and business-interruption trigger conditions have tightened significantly. The typical NC SMB cyber policy covers meaningful but partial cost recovery. Uncovered categories often include: reputational-repair costs, lost future revenue from customers who leave, retained-counsel fees above the policy's panel-counsel rate, and any ransom payment if the policy has an "extortion sublimit" of $50K-$250K.
Sources
- TechRadar — Ransomware attacks hit SMBs harder than ever as cybercrime gang rivalry heats up
- ReliaQuest — Ransomware and Cyber Extortion in Q2 2026
- BlackFog — The State of Ransomware 2026
- The Cyber Express — Qilin And INC Ransom Drive 2026 Ransomware Surge
- OSIbeyond — Qilin Ransomware Remains a Major Threat to SMBs
- Manufacturing Business Technology — Attacks Surge as Two RaaS Groups Battle for Dominance
- Entre — Ransomware in 2026: Why Small Businesses Remain the #1 Target
- Dark Reading — Cyberattacks & Data Breaches
Related Resources
- Cybersecurity Services for NC Small Businesses
- Managed IT Services
- Backup Services
- Contact PDC — request a same-month ransomware-readiness assessment and remediation program