Product
MSSPs
Enterprises
Resources
Company
Mythos
Real-time insights into emerging threats and adversary tactics
Advanced AI-powered security operations and response
H1 2026 produced 666 recorded incidents and 4,471 ransomware victims worldwide, peaking at 99 separate victims in a single day. The period’s defining feature was concentration: a small set of groups running most operations, two techniques doing nearly all the work, and the United States absorbing close to half of all recorded activity.
Download the full report now!
4,471 organizations were publicly named as ransomware victims in six months, peaking at 99 in a single day on April 27. Qilin alone claimed 662, followed by The Gentlemen at 416 and Akira at 279. Learn how to read volume at this scale without losing sight of which incidents actually carry systemic consequence.
PyPI was hit with trojanized development packages. Sapphire Sleet hijacked 141 npm packages at Mastra. The UK Foreign, Commonwealth and Development Office saw 80,000 Fortinet firewalls compromised. Upstream compromise became the clearest route to downstream scale. Understand what genuine attack surface control looks like when the intrusion arrives inside a trusted dependency.
Aitkin County Health, Community Health Center of Buffalo, Sturdy Health, and United Healthcare Community & State were all breached. ShinyHunters took 8.8TB from a One Medical archive, and AdaptHealth lost patient records and EHRs to session hijacking. See why patient data concentration keeps pulling attackers toward the sector, and what that means for anyone holding comparable data.
Data breaches with exfiltration, paired with ransomware, are near-universal across The Gentlemen, ShinyHunters, Storm-1567, Krybit, DragonForce, SpaceBears, Kazu, and APT73. Credential attacks, web application attacks, and social engineering supply the entry. Learn why this convergence on a shared playbook works in your favor, because defending against one adversary's method now covers many.
Fake Claude Code installation pages deliver fileless .NET infostealers built for credential theft. AI-built ransomware toolkits automate Active Directory discovery and carry EDR evasion. Elsewhere, SharkLoader poses as Cisco AnyConnect and Google Update, Remcos RAT hides in steganographic loaders, and fake Indian tax notices drive six-stage chains delivering dual RATs. See what behavioral detection has to catch.
The United States recorded 312 of 666 incidents, ahead of Germany at 25, France at 21, Canada at 18, and the United Kingdom at 17. Yet The Gentlemen focused on Argentina, Taiwan, Thailand, and France, and Krybit worked across Paraguay, Peru, Senegal, Morocco, and the UAE. Get the full regional picture and the actor-level exceptions that matter.
The period in brief: 666 incidents, 4,471 ransomware victims, and the dominance of data breaches, exfiltration, and ransomware as primary vectors. Identifies The Gentlemen as the most prolific actor at 44 incidents, Qilin as the leading ransomware operator, and the malware families sustaining these campaigns, with forward guidance on where global risk is heading through the rest of 2026.
Analysis of 666 incidents spanning healthcare, government, financial services, consumer brands, and software infrastructure. Breaks down the dominant attack types and maps geographic exposure, with 312 incidents in the United States ahead of Germany, France, Canada, and the United Kingdom. Anchored to a timeline of the period's most consequential events, from the Nike breach to the Fortinet firewall compromise.
Profiles of the groups that defined H1: The Gentlemen at 44 incidents across Argentina, Taiwan, Thailand, and France, ShinyHunters at 20 across North America and Europe, plus Storm-1567, Krybit, DragonForce, SpaceBears, and Kazu. Covers each group's geographic reach and technique mix, and what the presence of APT73 signals about state-aligned activity inside a financially motivated landscape.
Dominant families including Root Team, FortiBleed, LockBit, Xctdoor, Formbook, OnyxC2, SmartApeSG, Factory-v3, DonutLoader, and PoisonRAT, plus campaigns tied to APT32. Covers fake software installers, AI-themed lures, steganographic Remcos RAT delivery, tax season infection chains, and UAT-7810's expansion of its Operational Relay Box network with LONGLEASH, with defense implications mapped to each.
4,471 victims globally and a peak of 99 in a single day on April 27, 2026. Covers the full group leaderboard from Qilin at 662 victims through The Gentlemen, Akira, DragonForce, IncRansom, LockBit5, NightSpire, and Play, with per-country victim breakdowns for each. Includes a representative incident showing how operational reach extends well beyond any group's primary target geography.
The vulnerabilities driving attacker focus in H1 2026, led by CVE-2026-56290 in Joomla Page Builder CK at CVSS 9.8. Also covers Microsoft Exchange Online, Jenkins, LiteSpeed cPanel, Langflow, libssh2, and three Apache Tomcat bypasses. Each entry carries CVSS score, severity, patch date, and exploitation evidence including public proof of concept availability and CISA catalog status.