Breaking the Shadows: Global Sector Threat Landscape H1 2026

Download the Report

Related Products

eye green

Threat Intelligence

Real-time insights into emerging threats and adversary tactics

AI green

AI Agents

Advanced AI-powered security operations and response

What's it About:

H1 2026 produced 666 recorded incidents and 4,471 ransomware victims worldwide, peaking at 99 separate victims in a single day. The period’s defining feature was concentration: a small set of groups running most operations, two techniques doing nearly all the work, and the United States absorbing close to half of all recorded activity.

Some headlines: 

  • 666 Incidents Tracked
  • 4,471 Ransomware Victims Worldwide
  • 99 Victims Claimed in a Single Day
  • 80,000 Fortinet Firewalls Compromised in One Government Breach

Download the full report now!

What you'll Learn:

Ransomware Volume Has Reached Industrial Scale

4,471 organizations were publicly named as ransomware victims in six months, peaking at 99 in a single day on April 27. Qilin alone claimed 662, followed by The Gentlemen at 416 and Akira at 279. Learn how to read volume at this scale without losing sight of which incidents actually carry systemic consequence.

The Software Supply Chain Became the Preferred Route In

PyPI was hit with trojanized development packages. Sapphire Sleet hijacked 141 npm packages at Mastra. The UK Foreign, Commonwealth and Development Office saw 80,000 Fortinet firewalls compromised. Upstream compromise became the clearest route to downstream scale. Understand what genuine attack surface control looks like when the intrusion arrives inside a trusted dependency.

Healthcare Absorbed Disproportionate Targeting

Aitkin County Health, Community Health Center of Buffalo, Sturdy Health, and United Healthcare Community & State were all breached. ShinyHunters took 8.8TB from a One Medical archive, and AdaptHealth lost patient records and EHRs to session hijacking. See why patient data concentration keeps pulling attackers toward the sector, and what that means for anyone holding comparable data.

Two Techniques Account for Almost Everything

Data breaches with exfiltration, paired with ransomware, are near-universal across The Gentlemen, ShinyHunters, Storm-1567, Krybit, DragonForce, SpaceBears, Kazu, and APT73. Credential attacks, web application attacks, and social engineering supply the entry. Learn why this convergence on a shared playbook works in your favor, because defending against one adversary's method now covers many.

Attackers Are Riding the AI Adoption Wave

Fake Claude Code installation pages deliver fileless .NET infostealers built for credential theft. AI-built ransomware toolkits automate Active Directory discovery and carry EDR evasion. Elsewhere, SharkLoader poses as Cisco AnyConnect and Google Update, Remcos RAT hides in steganographic loaders, and fake Indian tax notices drive six-stage chains delivering dual RATs. See what behavioral detection has to catch.

Geographic Concentration Is Extreme, With Telling Exceptions

The United States recorded 312 of 666 incidents, ahead of Germany at 25, France at 21, Canada at 18, and the United Kingdom at 17. Yet The Gentlemen focused on Argentina, Taiwan, Thailand, and France, and Krybit worked across Paraguay, Peru, Senegal, Morocco, and the UAE. Get the full regional picture and the actor-level exceptions that matter.

What's Inside

1

Executive Summary

The period in brief: 666 incidents, 4,471 ransomware victims, and the dominance of data breaches, exfiltration, and ransomware as primary vectors. Identifies The Gentlemen as the most prolific actor at 44 incidents, Qilin as the leading ransomware operator, and the malware families sustaining these campaigns, with forward guidance on where global risk is heading through the rest of 2026.

2

Incident Landscape

Analysis of 666 incidents spanning healthcare, government, financial services, consumer brands, and software infrastructure. Breaks down the dominant attack types and maps geographic exposure, with 312 incidents in the United States ahead of Germany, France, Canada, and the United Kingdom. Anchored to a timeline of the period's most consequential events, from the Nike breach to the Fortinet firewall compromise.

3

Threat Actor Behavior

Profiles of the groups that defined H1: The Gentlemen at 44 incidents across Argentina, Taiwan, Thailand, and France, ShinyHunters at 20 across North America and Europe, plus Storm-1567, Krybit, DragonForce, SpaceBears, and Kazu. Covers each group's geographic reach and technique mix, and what the presence of APT73 signals about state-aligned activity inside a financially motivated landscape.

4

Attack Techniques & Malware

Dominant families including Root Team, FortiBleed, LockBit, Xctdoor, Formbook, OnyxC2, SmartApeSG, Factory-v3, DonutLoader, and PoisonRAT, plus campaigns tied to APT32. Covers fake software installers, AI-themed lures, steganographic Remcos RAT delivery, tax season infection chains, and UAT-7810's expansion of its Operational Relay Box network with LONGLEASH, with defense implications mapped to each.

5

Ransomware

4,471 victims globally and a peak of 99 in a single day on April 27, 2026. Covers the full group leaderboard from Qilin at 662 victims through The Gentlemen, Akira, DragonForce, IncRansom, LockBit5, NightSpire, and Play, with per-country victim breakdowns for each. Includes a representative incident showing how operational reach extends well beyond any group's primary target geography.

6

Top 10 Trending CVEs

The vulnerabilities driving attacker focus in H1 2026, led by CVE-2026-56290 in Joomla Page Builder CK at CVSS 9.8. Also covers Microsoft Exchange Online, Jenkins, LiteSpeed cPanel, Langflow, libssh2, and three Apache Tomcat bypasses. Each entry carries CVSS score, severity, patch date, and exploitation evidence including public proof of concept availability and CISA catalog status.

Breaking the Shadows: Global Sector Threat Landscape H1 2026

Download your free report