The state of the cyber threat
- 00A semester of reckoningEditorial: what our data says3
- 01The age of consolidationRansomware: fewer groups, more victims5
- 02One supplier, dozens of victimsThird parties & OAuth: the ShinyHunters saga8
- 03Cyber as a weaponGeopolitics: reprisals and infrastructure11
- 04The inventory of the semesterData breaches: from France to resale15
- 05What is actually exploitedVulnerabilities: KEV over CVSS19
- 06The AI that industrialises theftCross-cutting: the multiplier of trends22
- 07Priorities and outlookWhat it means for security teams24
A semester of reckoning
00 · EDITORIALA semester of reckoningWhat our data says
The first half of 2026 will not be remembered for a single attack, but for three underlying shifts that reinforce one another: a ransomware market that concentrates around a handful of actors, the return of cyber as an extension of geopolitical conflict, and the industrialisation, through artificial intelligence, of the theft and resale of data.
Our watch has consolidated nearly 64,000 major cyber signals since 1 January 2026: incidents, vulnerability disclosures, data breaches, group claims. From that flow, we continuously reconstruct incidents linking an identified attacker to a named victim: more than 14,500 to date, covering 10,200 distinct organisations. This raw material, and not a selection of spectacular events, is what informs the pages that follow.
The overall picture is clear. Ransomware and data theft saturate the landscape; edge devices (VPNs, firewalls) remain the favoured entry point; and a single weak link, a supplier or a forgotten OAuth token, is now enough to compromise dozens of organisations in cascade. This report breaks these dynamics into six chapters, each grounded in our figures and set against the major sector reports.
| Indicator | Value |
|---|---|
| Qualified cyber signals | nearly 64,000 |
| Reconstructed incidents (attacker to victim) | 14 500 |
| Distinct named victims | 10 200 |
| Ransomware claims (leak sites) | 1,592 / 79 groups |
| Actively exploited CVEs tracked (KEV) | 1 629 |
| of which weaponised in ransomware | 327 |
The age of consolidation
01 · RANSOMWAREThe age of consolidationFewer groups, more victims
For two years the ransomware market had fragmented: the takedowns of LockBit and ALPHV/BlackCat had scattered affiliates into a myriad of small franchises. The first half of 2026 reverses the trend. The market reconcentrates around a handful of industrial actors. Globally, the first quarter of 2026 saw more than 2,100 victims listed on leak sites, and the top 10 groups now account for roughly 71% of victims, up from 57% (ScienceDirect).
Our sample confirms it in its own measure. Across 1,592 claims observed on leak sites since late January, spread over 79 groups, the ten most active account for 54% of victims. The gap with the global 71% reflects our collection coverage; the direction is the same: value shifts towards the top of the ranking.
At the top, Qilin stands out as the most prolific group, a third consecutive quarter of dominance. Its aggressive affiliate model and its permanence make it the centre of gravity of the market. Behind it, the ranking mixes established names (INC Ransom, DragonForce, Akira, Play) with a new generation of franchises (Nova, SafePay, NightSpire), a sign of an ecosystem reshaping rather than calming down.
The Gentlemen: the revelation of the semester
No trajectory illustrates this reshaping better than The Gentlemen. Emerging in August 2025, the group went from around thirty victims in the last quarter of 2025 to 182 in the first quarter of 2026, climbing to second most active actor. In our own leak-site tracking it also ranks second, with 165 claims. Its signature: a professional, almost corporate approach, and heavy exploitation of edge devices (FortiOS, SonicWall VPN, Cisco ASA). It is the typical 2026 newcomer: not a band of amateurs, but a seasoned organisation industrialising initial access through infrastructure flaws.
This landscape lines up precisely with our study « Anatomy of attacker groups », which already mapped the dominance of financial actors and the rise of newcomers. The consolidation observed here is its logical sequel: ransomware-as-a-service matures, and in a criminal economy, maturity means concentration.
One supplier, dozens of victims
02 · THIRD PARTIES & OAuthOne supplier, dozens of victimsThe ShinyHunters saga
If one actor sums up the through-line of 2026, it is ShinyHunters. In our data, across all reconstructed incidents, it is the most present group in the corpus, ahead of LockBit and Qilin. Its hallmark is not encryption, but large-scale data theft, often via a trusted third party.
The modus operandi that defined the semester comes down to one word: OAuth. After the 2025 Salesloft Drift wave, a third-party app connected to Salesforce whose stolen tokens exposed more than 700 organisations, the mechanism repeated in 2026. In June, a group operating as Icarus exploited an OAuth integration via the Klue tool to siphon Salesforce data from several security firms themselves: HackerOne, Gong, OneTrust, Tanium, Huntress, LastPass. ShinyHunters also hit 7-Eleven, and Medtronic confirmed a claimed theft of more than 9 million records.
These names are not theoretical for us: they are among the victims our watch attributed to ShinyHunters this semester, Instructure, 7-Eleven, ADT, DentaQuest, the Council of Europe, Medtronic, the European Commission. The common denominator is never the victim's fortress, but the excessive permission once granted to a third-party application.
The weak link is not in the fortress
This is exactly the thesis of our article on third-party security: nearly one in three breaches now involves a third party (30%, up from 15% a year earlier per Verizon's 2025 DBIR), and these intrusions are the slowest to detect, 267 days on average (IBM). Data is no longer stolen by breaching a wall, but by borrowing a trust tunnel you opened yourself. A forgotten OAuth token, a never-revoked service account: the aggravating factor is organisational before it is technical.
Cyber as a weapon
03 · GEOPOLITICSCyber as a weaponReprisals, hacktivism, infrastructure
The overwhelming majority of attacks remain motivated by financial gain: 63% of the groups we attribute act for money. But the first half of 2026 saw a motivation long thought secondary resurface, geopolitics. State espionage (25%) and hacktivism (11%) now make up more than a third of attributed incidents.
The trigger is known: after the February 2026 US-Israeli strikes on Iranian targets, researchers observed a wave of cyber reprisals and hacktivist campaigns against Israel, the United States and their allies. In March, medical technology firm Stryker suffered an attack linked to a pro-Iranian hacktivist group, with employees watching their machines wiped in real time. Our base reflects this activity: Anonymous remains the leading hacktivist label in our corpus, followed by pro-Russian collectives such as NoName057(16) and Killnet.
In parallel, Russia remains the most imminent threat to European critical infrastructure, with confirmed attacks capable of hitting the EU's energy and water systems. On origin attribution, our mapping of state groups brings out a dozen groups linked to China (espionage), a Russian core spanning espionage, financial operations and sabotage, and Iranian and North Korean clusters.
The target shifts towards vital functions
This tension shows in the targeted sectors. Beyond technology, which dominates mechanically, defense and energy weigh heavily in our flow, two sectors where an intrusion carries not just market value but strategic value. The blurring between common crime and state operation, where a « financial » group sometimes serves as cover for a state, is one of the most worrying developments of the semester.
- Russia: mostly financial (the ransomware ecosystem: LockBit, Qilin, Clop...), with a pro-Russian hacktivist fringe (NoName057, Killnet) and a touch of state sabotage (Sandworm).
- North Korea: almost exclusively financial (Lazarus), complemented by espionage (Kimsuky).
- China: an assumed espionage profile (Mustang Panda).
The inventory of the semester
04 · DATA BREACHESThe inventory of the semesterFrom France to the resale market
The data breach is, by far, the leading incident type we reconstruct: it represents 61% of the qualified incidents of the semester, ahead of ransomware (26%). 2026 is the year stealing data takes precedence over encrypting it.
The scale of the standout cases is staggering. France Titres (ANTS) disclosed on 20 April 2026 a breach of 11.7 million accounts on the ants.gouv.fr portal, with the arrest of a 15-year-old suspect. Internationally: Telus (700 TB claimed by ShinyHunters), Under Armour (72 million accounts), Match Group, and the French national bank-account registry. One case will stand as a major warning: a healthcare breach exposed the fingerprints and palm-print biometrics of 1.8 million people, data that, unlike a password, cannot be reset.
France is no blind spot in this picture: it is the fourth most present country in our geolocated flow, as our study on France's place already documented. Far from being spared, it is a prime target.
The price of stolen data: a market that splits
What becomes of this data? It is resold, and its price tells a story. Dark-web price indexes (Privacy Affairs) show a steady erosion of bulk-data prices: a stolen payment card backed by a $5,000 balance was worth $240 in 2021, only $110 in 2023. The cause is massive oversupply: more than 2.8 billion compromised credentials circulated on the markets in 2025, fed by infostealers.
But the market does not collapse: it splits in two. On one side, raw data (PII, context-less cards) becomes a commodity sold for a few dollars. On the other, what is rare and directly monetisable gains value: a verified crypto account trades for $200 to $400, privileged admin access tops $1,000, and a full medical record is worth about ten times a payment card. Biometric data, for its part, still escapes any public pricing grid, its market is opaque, which is not reassuring.
| Resold data | Indicative price | Trend |
|---|---|---|
| Raw identity / PII (name + email) | under $15 | down (oversupply) |
| Payment card with CVV | $10 to $40 | down |
| Full identity (fullz) | $20 to $100 | down |
| Medical / health record | $250 to $310 | stable (10x a card) |
| Verified crypto account | $200 to $400 | up (scarcity) |
| Admin / privileged access | over $1,000 | up (premium) |
What is actually exploited
05 · VULNERABILITIESWhat is actually exploitedKEV over CVSS
In March 2026, attackers actively exploited FortiGate firewalls as an initial access vector, via recent flaws including CVE-2026-24858. A campaign dubbed ClickFix compromised more than 700 sites by exploiting a critical SQL injection (CVE-2026-26980) in the Ghost CMS. Two reminders that a vulnerability is not an abstraction: it is the raw material of initial access.
Our mirror of CISA's KEV catalog tracks 1,629 vulnerabilities confirmed as actively exploited, of which 327 are already weaponised in ransomware campaigns. The breakdown by vendor maps the entry points of the moment.
Microsoft dominates by historical volume, but it is edge devices that make the news: Cisco, Ivanti and Fortinet concentrate the recent additions. In the first half of 2026 alone, we watched a cascade of Cisco Catalyst SD-WAN, FortiClient EMS and FortiOS flaws enter the KEV, exactly the products The Gentlemen and others exploit to get in. 145 CVEs have been added to the catalog since January.
The CVSS score does not measure risk
The most important point of this chapter is not a volume, it is a method. Our base counts more than 440 CVEs published in 2026, all rated « high » or « critical », yet across all the flaws we track, nearly 28% are rated « medium » or « low ». CVSS severity, computed in isolation, says nothing about real-world exploitation.
This was already the thesis of our analysis on minor vulnerabilities, published in early June: fewer than one in five « critical » vulnerabilities is actually exploited, while « medium » flaws become the decisive link in an attack chain. A few weeks later, CISA confirmed this analysis in the clearest way. Its new directive BOD 26-04, « Prioritizing Security Updates Based on Risk », revoked the historic BOD 22-01 to base prioritisation no longer on the CVSS score, but on real risk: asset exposure, presence in the KEV catalog, exploit automation capability and technical impact. That the agency explicitly keeps exploit automation as a criterion echoes our finding about the effect of AI word for word. The right question is no longer « is this flaw critical? », but « is it exploited, exposed, and reachable? ».
Because AI has rewritten the equation. The average time to exploit fell from 745 days in 2020 to 44 days in 2025 (Flashpoint), and an autonomous agent can now exploit a known flaw for a few dollars. The stock of « minor » vulnerabilities an organisation leaves lying around is no longer a dormant risk: it is compound-interest debt.
The AI that industrialises theft
06 · CROSS-CUTTINGThe AI that industrialises theftThe multiplier of every trend
One force runs through the previous five chapters: artificial intelligence. It does not create a new threat; it accelerates and automates all the others. In the first quarter of 2026, the successful exfiltration rate reportedly reached 96%, with an average of 743 GB stolen per undisclosed incident, and criminal platforms like LotAI or ClawdBot show how AI now automates the sorting and prioritisation of stolen data.
On the attacker side, AI lowers the cost of exploitation (chapter 5), sorts infostealer logs in seconds to extract high-value access (chapter 4), and multiplies OAuth reconnaissance (chapter 2). On the defense side, it finds flaws faster than they can be fixed: Anthropic's Glasswing program identified more than 10,000 critical or high vulnerabilities in two months, of which more than 99% were unpatched at announcement. Discovery is no longer the bottleneck, remediation is.
This frontier model has a name: Mythos, Anthropic's system at the heart of Glasswing, and this is where the loop closes with the rest of the half-year. That same capability, discovering and chaining flaws at machine speed, has become an asset that states seek to lock down: on 12 June, Washington forced Anthropic to disable Mythos 5 and Fable 5 worldwide under export controls, while the vendor separately accused a Chinese lab of trying to clone it through distillation. The underlying risk is one of uncontrolled drift: because a model's guardrails are diffuse across its weights, a distilled clone (or, more simply, an open-weight model such as GLM 5.2, released by Z.ai in early July and presented as rivaling Claude Opus 4.8) can be stripped of its refusals and turned into an offensive tool. The power Mythos puts at the service of defense can, without its guardrails, be turned entirely against it.
This new surface has its own risk framework, detailed in our OWASP LLM overview: prompt injection, data leakage to LLMs, over-autonomous agents, poisoned RAG. Securing the internal use of AI has become a discipline in its own right, on a par with securing a classic information system.
Priorities and outlook
07 · FOR THE TEAMSPriorities and outlookWhat it means for security teams (CISOs)
What to make of this overview? The priorities that emerge for security leaders are not a checklist: they follow directly from what the semester showed, and obey a single principle, focus effort where attack chains actually break, rather than stacking tools downstream.
The first door to close remains the edge. VPNs, firewalls and gateways concentrate the initial access of dominant groups; a thorough inventory, a patch applied within days whenever a flaw enters the KEV, and Internet exposure cut to the strict minimum are worth more than any defense added later. In the same move, it becomes vital to regain control of third-party integrations: map OAuth connectors, impose least privilege, rotate and revoke secrets, demand verifiable guarantees (ISO 27001, SOC 2) from critical suppliers. One in three breaches now runs through a third party; granted trust is not a security control.
On vulnerabilities, the reflex to install is to prioritise by exploitability rather than by CVSS, crossing KEV status, public exploit and EPSS score: a « medium » flaw actually exploited must come before a « critical » one isolated behind several layers of segmentation. The geopolitical escalation calls in parallel for preparing for the destructive: for sensitive operators, the wiper scenario is no longer theoretical, which brings immutable backups, genuinely tested restoration and OT/IT separation back to the fore.
Facing AI-driven industrialisation, finally, two stances stand out. First, treat any stolen data as already resold: rather than hoping a leak stays confidential, bet on detecting the use of compromised credentials and on phishing-resistant authentication. Second, govern internal AI use, that is, frame what staff and agents can do with LLMs before that surface becomes a blind spot. Beyond these priorities, a more structural avenue is worth raising: for the most critical data, the best protection against a third party's failure is still not to depend on it, by reinternalising what can be.
No organisation is invulnerable. But, as we wrote about third-party security, you cannot claim victimhood if you have not put the means in place to protect yourself. The first half of 2026 does not say the threat is unstoppable: it says where to put the effort.
Sources cited
- LuksMentis watch (primary data, June 2026 queries).
- Verizon, 2025 Data Breach Investigations Report (third-party share).
- IBM, Cost of a Data Breach Report 2025 (cost, supply-chain dwell time).
- Flashpoint, N-Day Vulnerability Trends (time to exploit).
- Rapid7, 2026 Global Threat Landscape Report.
- Privacy Affairs, Dark Web Price Index (2021 to 2023 editions).
- Biometric Update; deepstrike, Constella (resale prices and infostealers, 2025-2026).
- CISA, BOD 26-04 « Prioritizing Security Updates Based on Risk » (revokes BOD 22-01); KEV catalog: cisa.gov.
- ScienceDirect (ransomware consolidation, top-10 concentration).
- Infosecurity Magazine (exfiltration rate, stolen volumes).
- Trade press: PurpleSec, La Nouvelle Tribune, Factoria, Quiver Quantitative, Techtime, Franceinfo.
- LuksMentis articles: Anatomy of attacker groups; Third-party security; Minor vulnerabilities; OWASP LLM overview (luksmentis.com/blog).
About this report
Report produced by LuksMentis from its proprietary cyber threat watch (nearly 64,000 qualified signals from January to June 2026) and the external sources listed above. Figures marked « LuksMentis watch » rely on our internal data. Attribution often relies on open sources and has no value as judicial proof. © LuksMentis 2026, luksmentis.com, reproduction and reuse subject to authorisation.