San Antonio is not targeted because of its name. It is targeted because its business mix maps almost exactly onto what ransomware crews are actually hitting. The FBI’s 2025 data names legal, contracting, engineering, consulting and small manufacturing as the most reported non-critical-sector victims. Bexar County holds 6,250 of those firms, most with fewer than 20 people on staff.
San Antonio businesses are top ransomware targets because Bexar County is dense in the exact industries the FBI reports most often, and because most local firms run under 20 employees with no security staff. The region’s defense supply chain adds a third factor, turning small suppliers into a route toward contracts attackers cannot reach directly.
Why San Antonio businesses get picked
Attackers don’t pick cities. They pick conditions. That distinction is the entire reason cybersecurity services for San Antonio businesses keep getting bought after an incident instead of before one.
Ask most owners here why a criminal group in another country would care about a 30-person firm off Loop 1604, and you get some version of the same answer, usually delivered with a shrug. We’re too small. There’s nothing here worth stealing. That answer was reasonable in 2016. It has since inverted, and the numbers behind the inversion are all public.
Modern ransomware is a volume business run by affiliates who rent the malware and keep a cut. Affiliates are paid on conversion. Prestige pays nothing. A company that hands over $150,000 in 4 days without lawyers, a board or a public filing is worth more per hour of effort than a Fortune 500 target that will fight for 8 months and then sue. Size is not protection. Size is friction, and friction is the one thing an affiliate is actively trying to avoid. Friction costs money.
So the real question is not whether San Antonio sits on a list somewhere. Better question. Which conditions raise the odds of getting hit, and how many of them does this metro happen to stack? There are 4 that matter here. The local data on each one is public and none of it is flattering. All 4 line up unusually well in Bexar County.

The FBI’s own list of who is getting hit
Most ransomware coverage stops at the critical infrastructure numbers. Hospitals, utilities, manufacturers. Those sectors do carry the highest reported volume, and the FBI’s 2025 Internet Crime Report confirms it. That is where the headlines come from. Fair enough.
Buried further into the same report is a section almost nobody quotes. In 2025 the Internet Crime Complaint Center took more than 1,400 ransomware complaints from businesses and organizations with no connection to any critical sector at all, meaning ordinary private employers with no utility, hospital or defense tie of any kind. The FBI then breaks those complaints down by industry. The list is not what most people expect.
Legal services came first at 18%. Contracting services, meaning electricians and general contractors, came second at 17%. Engineering and architectural firms took 10%. Consulting firms took 7%, and small non-critical manufacturers 5%.
None of those are hospitals. All of them are ordinary local businesses. Most run under 20 staff.
Now set that list next to Bexar County. The Bureau of Labor Statistics publishes county-level establishment counts through its Quarterly Census of Employment and Wages, and the 2025 annual averages for private employers in Bexar County line up against the FBI’s list like this.
| Industry the FBI names | Share of non-critical ransomware complaints | Bexar County equivalent | Establishments | Employees | Average staff per site |
|---|---|---|---|---|---|
| Legal services | 18% | Offices of lawyers (NAICS 5411) | 1,127 | 7,555 | 7 |
| Contracting services | 17% | Specialty trade contractors (238) | 2,022 | 29,060 | 14 |
| Engineering and architectural | 10% | Architectural and engineering (5413) | 739 | 13,510 | 18 |
| Consulting services | 7% | Management and technical consulting (5416) | 1,240 | 9,085 | 7 |
| Non-critical manufacturing | 5% | Manufacturing (31-33) | 1,122 | 42,358 | 38 |
| Combined | 57% | Bexar County total | 6,250 | 101,568 | 16 |
That is the finding. Better than half of every non-critical-sector ransomware complaint the FBI received in 2025 came from 5 industries, and San Antonio holds 6,250 establishments sitting inside them, according to the 2025 annual averages published by the Bureau of Labor Statistics. Roughly 101,568 people go to work at those addresses every morning. Almost none are monitored.
Average headcount across the 5 is 16. Law offices average 7. Consulting firms average 7 as well. A 7-person firm does not have a security analyst, a patch schedule, or anyone whose job includes reading a vulnerability bulletin on a Tuesday. That is the profile the FBI’s complaint data keeps describing. Over and over.
San Antonio has been growing fastest in the industries attackers hit most
A snapshot only tells you where things stand. Direction matters more. Attacker tooling follows the pool of available targets, and the pool here keeps widening.
Compare the 2020 and 2025 QCEW annual averages for Bexar County private employers. Four of the FBI’s 5 industries grew faster than the county’s overall business base.
| Sector | Bexar establishments, 2020 | Bexar establishments, 2025 | Change |
|---|---|---|---|
| Management and technical consulting | 992 | 1,240 | +25.0% |
| Architectural and engineering | 649 | 739 | +13.9% |
| Specialty trade contractors | 1,890 | 2,022 | +7.0% |
| Manufacturing | 1,062 | 1,122 | +5.6% |
| Offices of lawyers | 1,119 | 1,127 | +0.7% |
| All private employers | 43,822 | 44,715 | +2.0% |
Consulting establishments grew 25% in 5 years against a countywide baseline of 2%. Specialty trade contractors added 132 firms and 4,257 workers while San Antonio kept building. Every one of those new firms started with a laptop, a cloud accounting login and a phone. Almost none of them started with a security program. Most still have not.
Construction deserves its own note. Contracting ranks second in the FBI’s non-critical data, and it is the industry San Antonio has been adding most visibly for a decade. Bexar County construction employment went from 41,221 in 2020 to 49,896 in 2025. That is 8,675 more people across 3,199 firms, moving project files, lien waivers, bank drafts and subcontractor payment data through email accounts that mostly still rely on a password and a text message. That is the whole perimeter.
Attackers noticed the money before the industry noticed the exposure. Progress billing means large, predictable, time-sensitive transfers. Freeze a contractor’s accounting system on the 25th of the month and you have not stolen anything. You have stopped a payroll and a draw request at the same time. That is a far more effective form of pressure than theft. Deadlines do the work.

The defense supply chain turns small San Antonio firms into a route
Here is where San Antonio genuinely differs from Houston or Dallas.
This is Military City. Joint Base San Antonio is the largest joint base in the country, the 16th Air Force runs cyber operations from Lackland, and Port San Antonio describes its 1,900-acre campus as home to nearly 2,000 cybersecurity professionals. Local coverage treats that concentration as a strength. For the region’s economy it plainly is.
For a small supplier it cuts the other way.
Around every large defense program sits a long tail of machine shops, engineering consultancies, logistics firms, staffing agencies and IT integrators. Those companies hold controlled unclassified information. Drawings. Schedules. Personnel rosters and delivery routes. They are also small, which means an attacker who cannot get into a prime contractor can often walk into a 15-person supplier holding the same documents.
That gap is precisely what the Department of Defense spent 6 years trying to close. The 48 CFR acquisition rule was published in the Federal Register on September 10, 2025 and took effect on November 10, 2025. It authorizes contracting officers to put DFARS clause 252.204-7021 into solicitations, which makes Cybersecurity Maturity Model Certification status a condition of award and of performance.
The clause flows down. A subcontractor handling controlled unclassified information carries the same obligation as the prime, and Level 2 means implementing all 110 controls in NIST SP 800-171. San Antonio suppliers who assumed CMMC was somebody else’s problem found out otherwise in November. The bill arrived first.
Two things follow, and they pull in opposite directions. Compliance pressure is finally forcing security budgets into firms that never had one. That part is good. It also published a map. A rule requiring a supplier to hold sensitive data under a specific certification also confirms, publicly, that the supplier holds sensitive data. If your firm is chasing defense work in Bexar County, our CMMC compliance work in San Antonio starts from the assumption that the certification and the threat arrived the same week.
How attackers actually get into a San Antonio company
Almost nobody gets ransomwared by a genius.
Sophos surveyed 2,158 IT and cybersecurity leaders for its State of Ransomware 2026 report. The root-cause picture has shifted in a direction that should worry small firms specifically.
| How the attack started | Share of incidents, 2026 | Movement |
|---|---|---|
| Malicious email | 26% | Now the top cause |
| Phishing | 24% | Rising |
| Compromised credentials | 23% | Held steady |
| Exploited vulnerability | 18% | Down 14 percentage points |
Email and phishing together now account for half of all incidents. Exploited vulnerabilities, which led this list for 3 straight years, fell 14 points. Attackers stopped hunting for unpatched software because they no longer need to. Logging in is cheaper than breaking in. Credentials are the product now.
Location tells the same story. When Sophos asked where the compromise actually happened, exposed applications and systems came first at 38%, user devices second at 30%, and firewalls third at 21%. Compromised credentials dominated that first category, showing up in 59% of cases involving an exposed application or system. Not exploits. Logins.
The multi-factor authentication finding is the one that stops people mid-sentence. Among organizations where compromised credentials were the confirmed root cause, 97% had MFA deployed in some form at the time of the attack, running an average of 2.5 methods. Read that twice. Having MFA turned on somewhere is not the same as having it turned on everywhere that matters, and attackers have gotten very good at finding the one login that was left out.
There is a live example running right now. Akira was the single most reported ransomware variant in the FBI’s 2025 data, and the joint #StopRansomware advisory from CISA, the FBI, DC3 and HHS was updated on November 13, 2025 to describe how the group operates. Akira gets in through VPN appliances, stealing credentials or exploiting CVE-2024-40766 in SonicWall devices, then brute-forces and password-sprays whatever is left exposed. The advisory states plainly that Akira threat actors primarily target small and medium-sized businesses. As of late September 2025 the group had claimed roughly $244.17 million in proceeds. From small companies, mostly.
Read the shape of that. An aging SonicWall firewall. A VPN account without hardware-backed MFA. A small business. That combination describes a very large number of offices in this city.

What an attacker thinks your company can pay
Ransom demands are not random. They are not one-size-fits-all either. Groups research the victim before they name a number. Revenue is the input.
The Sophos data makes the calibration visible.
| Company revenue | Median ransom demand |
|---|---|
| Under $50 million | $140,000 |
| $50.1 million to $250 million | $214,000 |
| $250.1 million to $500 million | $590,250 |
| $500.1 million to $1 billion | $1,368,000 |
| $1.1 billion to $5 billion | $2,280,000 |
| Over $5 billion | $5,700,000 |
A San Antonio firm under $50 million in revenue is looking at a median demand around $140,000. That number is not designed to be impossible. It is designed to be payable, which is the entire point, and Coveware’s Q2 2026 payment data puts the median actual payment at $150,000. The math is deliberate.
The ransom is never the real cost. Sophos puts the typical recovery bill at $1.7 million once downtime, remediation, legal work and lost business are counted. Recovery speed has improved, with 55% of victims back inside a week, though the average still runs 3 weeks. Three weeks without a job costing system is survivable for a general contractor. Three weeks during the summer building season, with retainage and subcontractor payments frozen, usually is not.
One honest correction to advice I have given myself. For years the standard line was that good backups turn ransomware into an inconvenience, and backup-based recovery did climb to 66% of encryption cases in the 2026 Sophos data, up sharply from 54% the year before. Backups are working better than they used to. What backups do not solve is extortion without encryption, where the attacker takes the data and never locks anything, and Coveware attributes much of the 2026 payment spike to exactly that pattern against law firms. A perfect restore does not un-publish a client file.
The attack 80 miles west that should have changed the conversation
San Antonio has not had a headline-grade corporate ransomware event. That quiet does real damage to local risk perception. People read national numbers as somebody else’s problem.
Something did happen close to home in September 2025. Uvalde Consolidated Independent School District was hit by ransomware that encrypted its data and forced the cancellation of most classes for a week, with the FBI investigating and internal systems restored slowly over the following days, according to KSAT’s coverage. Uvalde sits inside the FBI San Antonio field office’s territory.
Supervisory Special Agent Justin Akers of the FBI Cyber Squad put the motive in one line in that same report. “The main motivating factor for these groups behind the ransomware attacks is money.”
Not politics. Not spite. Money.
Bexar County has already been through a version of this. In March 2022 the Bexar Appraisal District confirmed a ransomware attack that damaged files and took its email system down. A tax district and a rural school system are not glamorous targets. That is the entire lesson worth taking from both. Nobody is too boring.
3 things that move a business up an attacker’s list
After 25 years of supporting Texas businesses, and a lot of conversations that started with a phone call nobody wanted to make, the same 3 conditions keep showing up in nearly every environment we are called into. None of them are exotic.
A remote access path that predates the company’s growth. A VPN appliance bought when the company had 12 people is often still the front door at 60 people. Local accounts nobody has audited. Firmware 2 years behind. This is the Akira pattern almost exactly, and it is the most common thing we find on a first assessment.
Money that moves on a schedule. Construction draws, legal trust accounts, month-end manufacturing invoices, quarterly professional services billing. Predictable cash timing hands an attacker a deadline to exploit. Firms with the tightest billing cycles feel the pressure fastest.
An IT relationship that is reactive by design. Break-fix support and hourly help are excellent at fixing a broken laptop. Neither model includes anyone watching authentication logs at 2 in the morning. In the fastest observed campaigns, ransomware now deploys in under an hour from first login. Nobody is awake for it.
Notice what is not on that list. Industry prestige. Company reputation. Whether anyone outside your county has heard of you. The affiliate scanning for exposed SonicWall devices has no idea what your firm does, and finds out only after the encryption starts. By then it is done.

What actually changes the odds
Being a good target is not a permanent condition. It is a set of specific, fixable properties. The fixes are not exotic either.
The controls that matter map directly onto the data above. Phishing-resistant MFA on every remote access path, not just email. Retirement or hardening of any internet-facing appliance running old firmware. Endpoint detection that contains automatically instead of alerting a mailbox nobody reads overnight. Immutable backups somebody has actually restored from in a test. Monitoring that runs while the office is closed, because that is when deployment happens.
Building that layer by layer is a separate exercise. We have written it out step by step in the 7-layer ransomware protection playbook, which applies to San Antonio without modification. If an incident is already underway the sequencing question is different and the clock is much shorter, which is covered in ransomware recovery in Texas.
Regulated firms carry an extra layer on top. Medical practices in Bexar County have obligations that start before an incident and continue long after, which we cover in HIPAA cybersecurity requirements for San Antonio practices. Budget is usually the next question. There is a full breakdown of what cybersecurity services cost in San Antonio with local labor figures behind the numbers.
One thing worth saying plainly. No program takes the risk to 0, and any provider promising that is selling something. What a real program does is move you out of the easy-conversion bucket affiliates depend on, and turn a 3-week recovery into a 3-day one. That gap decides survival.
Questions San Antonio owners ask about ransomware risk
Are San Antonio businesses actually attacked more than other Texas cities?
No public dataset breaks ransomware incidents down by Texas metro, so any provider claiming a San Antonio-specific attack rate is guessing. What is measurable is exposure. Bexar County holds 6,250 establishments in the 5 industries the FBI reports most often outside critical infrastructure, and 4 of those 5 grew faster than the county’s overall business base between 2020 and 2025.
We have 12 employees. Why would anyone bother with us?
Because 12 employees is the target profile, not an exemption from it. The CISA and FBI advisory on Akira, the most reported ransomware variant of 2025, states that the group primarily targets small and medium-sized businesses. Small firms convert faster, negotiate less, and rarely keep the logging needed to prove what happened, which lowers an affiliate’s cost per successful attack.
Does being a defense subcontractor make us a bigger target?
It raises attacker interest and it raises the consequences. Suppliers holding controlled unclassified information are a route into programs that are harder to attack directly, and the 48 CFR rule effective November 10, 2025 now makes CMMC status a condition of award, so a compromise can cost you contract eligibility on top of recovery. Small San Antonio suppliers around Joint Base San Antonio carry both risks at once.
Our data isn’t worth anything on a black market. Doesn’t that protect us?
Resale value stopped being the model years ago. Modern crews monetize your need for the data, not somebody else’s interest in it, so a contractor’s job costing file or a firm’s active matter list is valuable precisely because it is worthless to everyone except you. Extortion without encryption has made this worse, since the leverage is now publication rather than deletion.
How do attackers find a small company in San Antonio in the first place?
Mass scanning, almost always. Affiliates sweep the internet for specific appliance models and firmware versions, then work through whatever answers, which is why the Akira campaigns against SonicWall VPNs hit thousands of unrelated companies. Nobody researched your firm and chose it. Your firewall answered a scan, and geography never entered the decision.
We already have MFA and a VPN. Why is that still a weak point?
Coverage gaps are the issue, not the technology itself. In the Sophos 2026 data, 97% of organizations breached through compromised credentials had MFA deployed in some form and averaged 2.5 methods, which means the successful attacks went through whatever was left uncovered. Service accounts, legacy VPN logins and administrative consoles are the usual holdouts, and SMS codes are no longer sufficient on any of them.
Find out where your business actually sits
Most owners are surprised by 1 or 2 findings in a security assessment and completely unsurprised by the rest. They already suspected the VPN was old. What they usually cannot answer is which accounts lack real MFA, which appliance is running unsupported firmware, and how long an intruder could operate before anyone in the building noticed a single thing.
Uprite has supported Texas businesses for 25 years. We average 5 minutes to first response across all priority levels, day or night, and we back the relationship with a 120-day exit guarantee that no competitor in San Antonio publishes an equivalent to. An assessment gives you the specific list for your environment, in plain language, with nothing attached to it. No obligation, no pressure.
Get a free security assessment for your San Antonio business and find out which of these conditions apply to you.









