A new threat intelligence report from Cisco Talos shows that ransomware activity in Japan climbed 4.7% during the first half of 2026, with small and medium enterprises (SMEs) absorbing the brunt of the damage. The findings add to a growing body of evidence that ransomware attacks targeting SMEs are not a side effect of the broader threat landscape. They are the main event, driven by attackers who have figured out that smaller organizations often carry valuable data without the security budgets to defend it.

What the Cisco Talos Report Found About Japan's H1 2026 Ransomware Surge

According to Cisco Talos, ransomware incidents across Japan rose nearly 5% in the first six months of 2026 compared to the previous period. The report identifies an extortion syndicate calling itself "The Gentlemen" as a major driver of this increase, with the group directing roughly 80% of its targeting efforts at SMEs rather than large enterprises.

That concentration is notable. Ransomware operators have historically chased headline-grabbing targets such as hospitals, government agencies, and Fortune 500 companies. The Cisco Talos data suggests a strategic pivot toward businesses that are less likely to have dedicated security operations centers, incident response retainers, or 24/7 monitoring, but still generate revenue worth extorting.

Why 'The Gentlemen' Is Focusing on Small and Medium Enterprises

The logic behind targeting SMEs is straightforward from an attacker's perspective. Smaller companies frequently operate with lean IT teams, rely on a patchwork of legacy software, and lack the layered security architecture that larger enterprises can afford. That combination creates a lower barrier to entry for attackers while still offering meaningful payouts, especially when a business cannot survive prolonged downtime and feels pressured to pay quickly.

The Cisco Talos findings on "The Gentlemen" reinforce a pattern seen across ransomware ecosystems more broadly: attackers are diversifying, industrializing their operations, and using increasingly stealthy tools to maintain footholds inside compromised networks. That stealth-first approach mirrors other Talos research, including its analysis of Chaos ransomware's msaRAT hiding C2 traffic in your browser, which showed how modern ransomware groups increasingly blend malicious command-and-control traffic into legitimate-looking web activity to avoid detection.

Common Entry Points: Remote Access, Exposed VPNs, and Unpatched Network Gear

While the Cisco Talos report focuses on Japan's overall attack volume, the broader pattern across ransomware campaigns points to a consistent set of entry vectors: exposed remote access services, misconfigured VPN gateways, and unpatched network infrastructure. SMEs are disproportionately exposed on all three fronts because they often deploy remote access tools quickly to support hybrid work without revisiting configurations, patch schedules, or access controls afterward.

This is precisely why infrastructure-level vulnerabilities matter so much to smaller organizations. When critical network management software has a severe flaw, such as the one detailed in Cisco's own advisory covering the Cisco FMC flaw CVE-2026-20079 exploited by Sandworm and Qilin, attackers gain a ready-made path into networks that may otherwise look well defended on the surface. Ransomware groups routinely scan for these kinds of unpatched systems, and SMEs that delay updates or lack asset inventories are the easiest targets to find.

Practical Defenses SMEs Can Deploy Now

The good news is that SMEs don't need enterprise-level budgets to meaningfully reduce their ransomware risk. A few concrete steps can close many of the gaps attackers rely on:

  • Harden VPN and remote access configurations by enforcing multi-factor authentication, disabling unused accounts, and restricting access to only what employees need.
  • Segment networks so that a single compromised device or account cannot provide a direct path to critical systems or backups.
  • Maintain offline or immutable backups and test restoration regularly, since encrypted files are only a crisis if there's no clean copy to recover.
  • Patch network appliances and remote access software promptly, treating vendor advisories for critical infrastructure like Cisco FMC as urgent, not optional.
  • Build a basic incident response plan before an attack happens, including who to call, how to isolate affected systems, and how to communicate with employees and customers.

Understanding how attackers hide their activity is also part of the defense. Talos' research into Chaos ransomware's msaRAT hiding in Chrome and Edge illustrates why traditional antivirus alone is no longer sufficient; monitoring outbound network behavior and browser activity has become just as important as endpoint scanning.

What This Means For You

If you run or support an SME, this report is a reminder that size does not equal safety. Ransomware attacks targeting SMEs are increasing precisely because attackers know smaller organizations often skip the basics: consistent patching, layered network defenses, and rehearsed incident response. You don't need to match the security spend of a large enterprise, but you do need to treat VPN and remote access hygiene, backup discipline, and timely patching as non-negotiable business functions rather than IT afterthoughts.

Key Takeaways

The 4.7% rise in Japanese ransomware attacks documented by Cisco Talos, and the outsized focus on SMEs by groups like "The Gentlemen," reflects a global trend rather than an isolated regional issue. Small businesses everywhere should assume they are viable targets, not overlooked ones. Start by auditing remote access points and VPN configurations, verify that backups are tested and isolated from the main network, and stay current on vendor security advisories for any network infrastructure you rely on. Ransomware groups are counting on SMEs to remain under-defended. Closing even a few of these gaps can meaningfully shift the odds in your favor.