The first six months of 2026 show that organizations must prepare for continuous pressure from increasingly well-organized cybercriminal groups.
The Cyble Research and Intelligence Labs (CRIL) – H1 2026 Global Threat Landscape Report analyzes ransomware activity, data leaks, sales of access to compromised environments, and hacktivist group operations worldwide.
Ransomware Operates on an Industrial Scale
According to the report, there were 3,836 ransomware attacks in the first half of 2026, averaging over 630 incidents per month.
A relatively small group of Ransomware-as-a-Service (RaaS) operators is responsible for a significant portion of the attacks, with Qilin, Akira, DragonForce, INC Ransom, and The Gentlemen leading. These groups mainly shape the current threat landscape.
One of the most critical findings of the report is the widespread adoption of the double extortion model. Cybercriminals first steal data from organizations and only then encrypt the environment. The threat of publishing confidential information is now the main tool for extorting ransoms.
This means effective protection for organizations must include not only preventing data encryption but also detecting attempts to exfiltrate data at the earliest possible stage.
The largest number of ransomware attacks were recorded in North America and Europe (including the UK). In contrast, in the Middle East and Africa (MEA) and parts of the Asia Pacific (APAC) region, the activity was dominated by individual groups – The Gentlemen in the MEA region and Qilin/The Gentlemen in the remaining parts of APAC. This shows that regional threat models should not be assessed solely based on global statistics.
The Market for Selling Access to Organizations Continues to Grow
The report highlights the dynamic growth of the market for brokered access to already compromised environments. There were 129 offers to sell access to organizational environments globally, which serve as entry points for ransomware attacks and espionage operations.
Access to technology companies and retail sector organizations is most commonly offered. These types of information are later used by ransomware groups and entities conducting espionage activities. This demonstrates that cyberattacks are increasingly the result of collaboration between many specialized groups operating within a single criminal ecosystem.
Financial Data Remain the Most Valuable Target
Data security breaches and leaks (367 incidents) most affected the BFSI sector (banking, financial services, and insurance), followed by public administration, law enforcement, and the technology sector. This is primarily due to the high financial value of the data and personal information (PII).
Vulnerability Management Remains Crucial
The report’s authors indicate that almost 90% of the analyzed vulnerabilities were rated critical or high.
Vulnerabilities in solutions from manufacturers such as Ivanti, Fortinet, Cisco, and SolarWinds were most frequently exploited. Edge devices, VPN systems, and IT infrastructure management platforms are of particular interest to criminals.
Hacktivism Changes its Face
Hacktivism and geopolitically motivated cyber actions increasingly blur the line with profit-driven cybercrime. The report recorded over 32,400 domains affected by hacktivist group activity and around 9,825 entries on data leaks published in channels associated with hacktivist groups worldwide.
Groups operating under the banner of hacktivism increasingly conduct DDoS campaigns, publish stolen data, and participate in selling access to organizations. According to Cyble, this activity increasingly has a commercial nature and is part of a developed underground cybercrime services market.