Research date: September 14–15, 2026. Threat-landscape coverage only: prevention, detection, response, victim impact, and law enforcement. Attack patterns are described at a high level. This document contains no procedures, tooling instructions, or evasion techniques.
Evidence labels used throughout: [Confirmed] — official government or law-enforcement statements, court records, victim disclosures. [Vendor] — statistics from commercial telemetry or surveys. [Assessment] — analytic judgments including attribution and motive. [Estimate] — modeled, survey-based, or extrapolated figures.
1. The numbers that frame everything else
| Metric | Figure | Source & date | Label |
|---|---|---|---|
| Reported US cybercrime losses, 2025 | $20.9B, +26% YoY, >1M complaints for the first time | FBI IC3 2025 Annual Report (Apr 2026) | [Confirmed — reported only] |
| Five-year cumulative IC3 losses (2020–25) | $71.3B | IC3 2025 | [Confirmed] |
| Global ransomware payments, 2025 | ~$820M on-chain, −8% YoY, while claimed attacks rose ~50% | Chainalysis Crypto Crime Report (Feb 26, 2026) | [Estimate — tracing floor] |
| Ransomware payment rate | ~28% overall (all-time low); 15% for exfiltration-only | Chainalysis; Coveware by Veeam Q2 2026 (Jul 30, 2026) | [Vendor] |
| Median dwell time | 14 days (up from 11); 122 days for espionage and DPRK IT-worker cases | Mandiant M-Trends 2026 (Mar 23, 2026) | [Vendor] |
| Top initial infection vectors | Exploits 32% (sixth year at #1); voice phishing 11%; prior compromise 10%; email phishing 6% | M-Trends 2026 | [Vendor] |
| Top breach vectors | Vulnerability exploitation 31%; credentials appear in 39% of breaches; human element in 62% | Verizon DBIR 2026 (May 2026) | [Vendor] |
| Third-party involvement | 48% of breaches, +60% YoY | DBIR 2026 | [Vendor] |
| eCrime breakout time | ~29 minutes average, −65% YoY; fastest observed 27 seconds | CrowdStrike 2026 Global Threat Report (Feb 24, 2026) | [Vendor] |
| Average breach cost | $4.99M global (2026 edition, record, +12%) | IBM Cost of a Data Breach 2026 | [Estimate — modeled] |
| Record DDoS | 31.4 Tbps (Nov 2025, Aisuru/Kimwolf); 47.1M attacks mitigated in 2025, +121% | Cloudflare via The Hacker News (Feb 5, 2026) | [Vendor] |
| North Korean crypto theft, 2025 | $2.02B, +51%, including the $1.5B Bybit heist; ≥$6.75B cumulative | Chainalysis (Dec 2025) | [Assessment + on-chain] |
A caveat that belongs on every page using these numbers. IC3 figures cover only reported US losses. Chainalysis figures are a floor based on traceable on-chain payments. Survey figures from Sophos, Ponemon, and IBM are estimates built on self-report. Underreporting is severe across all of them — Coveware cautions that "adverse cyber extortion outcomes happen more often than victims are told."
2. Ransomware and data extortion
The 2025–26 paradox: more attacks, less money
Claimed attacks rose roughly 50% to record levels while on-chain payments fell 8% to about $820M and the payment rate hit an all-time low near 28%. Chainalysis attributes the decline to better backups and incident response, regulatory pressure, and eroding trust that payment actually helps.
Fragmentation followed the takedowns. Law-enforcement action "scattered the ecosystem into a decentralized web of smaller, independent operations." Check Point observed major ransomware-as-a-service brands going dark and affiliates going independent: RansomHub, running roughly 75 victims a month, vanished in April 2025; Qilin nearly doubled to about 70 victims a month in Q2 2025; DragonForce, SafePay, and Akira absorbed orphaned affiliates. By Q2 2026 Coveware's top variants were Lone Wolf (17%), ShinyHunters (12%), Akira (9%), The Gentlemen (8%), and DragonForce (4%).
Ransom economics have bifurcated into a barbell. Chainalysis's median payment jumped to roughly $59,556 from $12,738 in 2024 as actors targeted smaller, faster-paying firms. Coveware's Q2 2026 average was $1.88M, up 176% quarter over quarter, while its median was $150K, down 50% — a few enormous payments alongside many small ones. Sophos's 2025 survey found 57% of demands exceeded $1M and victims paid about 85% of the initial demand on average (a mean ratio; Sophos's median payment of $1M against a median demand of $1.32M is a different comparison — see 10-cybersecurity-economics.md). This is a useful statistics lesson for readers: averages and medians tell opposite stories here.
"Recovery denial" is the tactical shift. M-Trends 2026 flags a move from mere encryption to actively destroying recovery capability — targeting backup infrastructure, identity services, virtualization management planes, and cloud backup objects. Prior compromise, meaning access purchased from brokers, became the number-one ransomware entry vector at 30%, doubling from 15% in 2024.
Profile
Targeted industries. Coveware Q2 2026: software services 17.2%, healthcare 14.1%, professional services 13.1%. Mid-market dominance is stark — 75.8% of cases, median victim around 750 employees. ENISA's EU view puts public administration first at 38.2% of incidents, then transport and digital infrastructure.
Attack pattern (high level). Purchased or brokered access, often from infostealer logs or initial-access brokers, or socially engineered credentials, or exploited edge devices → privilege escalation and lateral movement → data theft → destruction of backups → encryption with pay-or-leak extortion.
Warning signs. Unexpected disabling of security tooling or backups; new privileged accounts; off-hours mass file access; anomalous transfers to unfamiliar destinations; and — critically — alerts from apparently low-severity intrusions. M-Trends urges treating "low-impact" alerts as critical because the hand-off from access broker to ransomware crew now averages 22 seconds, down from more than eight hours in 2022.
Business impact. Sophos 2025 found average recovery cost excluding ransom at $1.53M, down 44% year over year, with 53% recovering within a week, up from 35%. The extremes are what readers remember: Jaguar Land Rover's August–October 2025 shutdown produced an estimated £1.9B (roughly $2.5B) in economic damage per the Cyber Monitoring Centre, assessed as the UK's costliest cyber event, with a £196M direct charge booked by the company and a £1.5B government loan guarantee to stabilize its supply chain.
Controls. Phishing-resistant MFA; immutable and offline backups tested by restore; network segmentation; hardened, monitored edge devices; treating hypervisor, backup, and identity planes as Tier 0; least privilege; KEV-prioritized patching.
Detection. EDR plus behavioral analytics for identity anomalies; monitoring of backup-system access; canary files; egress monitoring for staging and exfiltration; log retention beyond 90 days including network devices and hypervisors.
Response priorities. Isolate but preserve evidence; activate the IR retainer and legal and insurance contacts early; verify backup integrity before restoring; assume data theft even absent a leak; report to the FBI or national CERT; check No More Ransom — Chainalysis notes many newer strains are poorly designed and vulnerable to decryptors.
Recovery challenges. Rebuilding identity infrastructure; leaks continuing after "recovery"; re-extortion; regulatory notification waves; insurer disputes; team exhaustion.
Reference incidents
- Change Healthcare (Feb 2024, ALPHV/BlackCat) — roughly $22M ransom paid, after which ALPHV exit-scammed its own affiliate; approximately 193 million people affected, the largest US healthcare breach; nationwide claims and pharmacy disruption; total UnitedHealth costs reported around $2.9B. Entry was a Citrix remote-access portal without MFA. [Confirmed]
- CDK Global (Jun 2024) — roughly 15,000 car dealerships disrupted; a ~$25M payment was reported by media but not officially confirmed; dealer losses estimated near $1B. [Reported]
- Synnovis / NHS London (Jun 2024, Qilin) — thousands of postponed procedures and national blood-supply impact; UK officials later linked at least one patient death to the disruption, the clearest documented cyber-attack-to-patient-harm chain in the UK. [Confirmed]
- UK retail wave (Apr–May 2025) — help-desk social engineering leading to DragonForce ransomware at M&S (company-estimated ~£300M profit impact), with Co-op pulling its own systems offline mid-intrusion in a successful containment, and Harrods restricting access. The Cyber Monitoring Centre put combined losses at £270–440M. [Confirmed]
- Jaguar Land Rover (Aug–Oct 2025) — a five-plus-week global production shutdown. Attribution claims pointed to Scattered Spider/ShinyHunters-linked actors but were not officially confirmed. [Confirmed impact; attribution = claims]
Extortion without encryption
Data-theft-only extortion is now a mature model. The 2025 Salesforce and Salesloft Drift campaigns by ShinyHunters and Scattered Spider-linked actors were purely steal-and-extort; the 2024 Snowflake customer campaign (UNC5537, roughly 165 organizations including Ticketmaster and AT&T, using infostealer-stolen credentials on accounts without MFA) was the template. Coveware's finding that only 15% of exfiltration-only victims paid in Q2 2026 suggests leverage is declining without encryption. IC3 logged 89,129 extortion complaints and $122.5M in extortion losses in 2025, plus more than 75,000 sextortion reports.
3. Phishing, vishing, and social engineering
Phishing was the number-one IC3 complaint type in 2025 with 191,561 complaints. ENISA implicated phishing in roughly 60% of EU intrusions and described it as industrialized by phishing-as-a-service platforms, reporting that by early 2025 AI-supported phishing represented more than 80% of observed social engineering worldwide — a figure worth treating as a soft estimate.
The big shift is voice. Email phishing fell to 6% of Mandiant intrusions as technical controls improved, while voice phishing surged to 11% and second place overall — mostly calls to IT help desks to trigger MFA resets and harvest long-lived OAuth tokens and session cookies. DBIR 2026 highlights pretexting embedded in legitimate workflows over crude lures.
The help-desk pattern — impersonating an employee to IT support, or IT support to an employee, to obtain password and MFA resets — sits behind the 2023 MGM and Caesars attacks and the 2025 UK retail, insurance, and airline intrusions. The defenses are procedural as much as technical: strict identity verification for all help-desk resets with callbacks to known numbers and identity proofing, never resets based on caller-supplied information alone; FIDO2/WebAuthn phishing-resistant MFA; limiting who holds MFA-reset privileges; out-of-band verification for privileged changes.
Warning signs: unusual MFA-reset requests, fatigue prompts, urgent calls claiming to be IT or an executive, new OAuth app authorizations, logins from unfamiliar geographies immediately after a help-desk contact.
Detection and response: alert on MFA method changes and new device enrollments; monitor OAuth grants; treat any confirmed vishing contact as an active-incident precursor; rapid session and token revocation is the key containment step — a password reset alone does not log an attacker out.
4. Business email compromise
Losses: $3.05B reported to IC3 in 2025 across 24,768 complaints, up from $2.77B in 2024 — the second-costliest crime type after investment fraud, and nearly $8.5B over three years. The FBI's long-run figure is $55.5B in exposed losses from 305,033 incidents between October 2013 and December 2023. [Confirmed — reported]
Pattern (high level). Compromise or spoofing of a trusted mailbox — an executive, a vendor, payroll — followed by a studied, well-timed payment-redirection request. Vendor-email compromise dominates, at roughly 61% of BEC in Abnormal's dataset. The average fraudulent wire request is around $42K. Microsoft's framing is useful: BEC is about 2% of threats but roughly 21% of attack outcomes.
The recovery lever that matters. The FBI's Financial Fraud Kill Chain froze $679M of $1.164B in attempted transfers in 2025 — 58%. Speed of reporting is the single biggest recovery factor. The practical instruction for readers is to contact the bank and IC3 within hours, not days.
Controls. Out-of-band verification of any payment-detail change; dual approval for wires; DMARC, DKIM, and SPF at enforcement; mailbox-rule and OAuth-grant monitoring; finance-team-specific training.
5. Credential theft, infostealers, and account takeover
Europol calls stolen data "a core currency of the underground economy," and reported initial-access prices rising roughly 50% in 2024. Aggregators estimate billions of credentials exposed through stealer logs in 2025.
The Lumma takedown (May 19–21, 2025) is the reference case: the FBI, Microsoft's Digital Crimes Unit, Europol, and Japan's JC3 seized more than 2,300 domains against a malware-as-a-service operation renting for $250–$1,000 a month, with roughly 394,000 Windows infections in two months and about 10 million total infections attributed by the FBI. Lumma partially resurged afterward — takedowns disrupt but rarely kill. [Confirmed]
Why this matters more than it looks. Stealer logs feed initial-access brokers, whose access is now the number-one ransomware entry vector at 30%. The Snowflake campaign showed years-old stealer credentials unlocking massive cloud datasets wherever MFA was absent. Credentials appear in 39% of breaches.
Warning signs. Organizationally: impossible-travel logins, logins from residential-proxy IP space, dormant-account revivals, session-token reuse. Individually: password-reset emails you did not request, unfamiliar devices in account settings.
Controls. Phishing-resistant MFA everywhere, especially SaaS and cloud administration; short session lifetimes for sensitive applications; dark-web and stealer-log monitoring of your domains; blocking unmanaged-device access; password managers with unique passwords; disabling legacy authentication protocols. Response: mass credential and token and OAuth revocation, not just password resets.
6. Malware, botnets, and DDoS
Malware-free intrusion dominates. Most eCrime intrusions are now hands-on-keyboard using legitimate tools; where malware appears it is increasingly commodity or AI-assisted. Mandiant documented experimental AI-querying malware families (PROMPTFLUX, PROMPTSTEAL) and a credential stealer hunting local AI tool configurations (QUIETVAULT), while assessing that most 2025 breaches still stem from human and systemic failures rather than AI.
Botnets and DDoS. 2025 was the worst DDoS year on record: Cloudflare mitigated 47.1 million attacks, up 121%, averaging 5,376 an hour, with network-layer attacks up 58%. The Aisuru/Kimwolf botnet — more than 2 million compromised devices, largely off-brand Android TV boxes, plus 600 trojanized Android apps and 3,000 trojanized Windows binaries routed through residential proxies — set successive records, peaking at 31.4 Tbps for 35 seconds in November 2025. Telecoms and carriers were hit hardest.
Hacktivist DDoS. In the EU, DDoS was 77% of reported incidents with roughly 80% traced to hacktivists, dominated by pro-Russia NoName057(16) — but only about 2% caused actual service disruption. High noise, low individual impact, real aggregate cost.
Controls. Contract DDoS mitigation before you need it; test runbooks and provider contacts. For consumers and small businesses: patch or replace end-of-life routers and IoT devices and avoid gray-market streaming boxes, which are botnet fodder.
7. Supply-chain and third-party attacks
This is the defining growth vector of 2025–26: third parties involved in 48% of breaches, up 60% year over year.
- Salesloft Drift (Aug 2025) — stolen OAuth tokens for a chat integration cascaded into more than 700 downstream organizations' Salesforce data, described as roughly a tenfold greater blast radius than direct attacks. Victims included security vendors (Cloudflare, Zscaler, Palo Alto Networks all disclosed exposure); attackers mined the exports for embedded AWS keys and Snowflake tokens. [Confirmed]
- Shai-Hulud npm worm (Sep 2025) — a self-replicating worm compromised more than 500 npm packages, harvesting GitHub tokens and cloud API keys, publishing stolen secrets, and re-injecting itself into further packages. CISA issued an alert on September 23, 2025 with mitigation guidance: rotate credentials, pin versions, require phishing-resistant MFA for developers. A second wave followed in November 2025. [Confirmed]
- Precedents: the xz-utils backdoor near-miss (March 2024), 3CX (2023), and MOVEit's mass exploitation (2023, Cl0p) affecting 2,700-plus organizations and roughly 95 million individuals.
- 2026: open-source build-chain compromises at Trivy, Bitwarden, and Checkmarx with downstream impact at companies including OpenAI and Vercel; the Klue breach (June 2026) exposing roughly 200 downstream companies' cloud service keys.
Controls. Vendor risk tiering with contractual security and notification terms; SBOMs and dependency pinning; secret scanning; audit and minimize OAuth app grants — the single recurring theme across Salesforce, Salesloft, and npm; segment vendor access; monitor for anomalous API exports. Response: map blast radius fast (which tokens and keys could this vendor's compromise expose), rotate credentials, and do not wait for the vendor's full forensics.
8. Cloud compromise
Cloud intrusions rose 37% overall in 2025, with state-nexus cloud targeting up 266%. SaaS is now the crown-jewel store, and attackers pivot via long-lived OAuth tokens and session cookies harvested through help-desk vishing.
Pattern (high level). Valid credentials or tokens — stolen, phished, or vished — leading to API-level bulk data access, often with no malware at all, so endpoint detection sees nothing.
Emblematic cases. Snowflake customer tenants (2024, UNC5537, ~165 organizations, credentials from old infostealer logs, no MFA); Salesforce and Drift (2025, OAuth abuse); Microsoft's Midnight Blizzard corporate-email compromise through a legacy test tenant (January 2024, Russian SVR).
Controls. Phishing-resistant MFA mandatory for all SaaS; route SaaS through a central IdP with conditional access; shorten token lifetimes; audit third-party app connections quarterly; enable and retain cloud audit logs; alert on bulk API export and anomalous query volumes; treat identity as the perimeter. Response: token and session revocation first, password reset second.
9. Insider threats, including hired ones
Cost. Ponemon's 2025 study put average annual insider-risk cost at $17.4M per organization, up from $16.2M, with $211K containment cost per incident and 81-day average containment. Incidents contained in under 31 days cost $10.6M annualized versus $18.7M for those taking 91 days or more. [Estimate — survey]
The new insider is hired, not turned. North Korea's IT-worker infiltration scheme places operatives under false identities inside Western technology and crypto firms, funding the regime through salaries and enabling later theft. Incidents involving DPRK IT workers showed a 122-day median dwell time. The US DOJ ran multiple 2024–25 actions against domestic "laptop farm" facilitators. Actors now also recruit witting and unwitting collaborators on freelance platforms.
Warning signs. Hires who refuse video calls or whose on-camera appearance mismatches documents; company laptops shipped to third-party addresses; VPN-only access from unexpected regions; excessive data staging before resignation.
Controls. Identity verification in hiring with live video and document liveness checks; least privilege and just-in-time access; DLP on exfiltration paths; monitored offboarding; separation of duties for finance and code deployment.
The 2026 addition: DBIR 2026 flags unsanctioned shadow AI use as the third-most-common non-malicious insider action. Data pasted into personal AI tools is now a mainstream insider-risk channel, and the fix is a sanctioned alternative rather than a ban.
10. Fraud: investment scams, deepfakes, SIM swapping, identity theft
Investment fraud and pig butchering
The largest loss category: $8.65B reported to IC3 in 2025 across 72,984 complaints, with crypto the dominant payment rail (181,565 crypto-related complaints). Adults aged 60 and over reported $7.75B — 37% of all US losses.
The Prince Group takedown (Oct 14, 2025) was the largest action ever against Southeast Asian scam networks: the DOJ's biggest-ever forfeiture at roughly 127,271 BTC (about $15B) from wallets of indicted chairman Chen Zhi, 146 OFAC-sanctioned entities, and a FinCEN designation of Huione Group as a primary money-laundering concern. The network's compounds, staffed partly by trafficked forced labor, defrauded Americans of more than $16.6B. [Confirmed]
Pattern (high level). Long-con relationship building through dating apps, wrong-number texts, or social media → fake investment platforms displaying fabricated gains → escalating deposits → tax or fee demands → disappearance. Warning signs: unsolicited contact pivoting to investing, guaranteed returns, pressure to move to private chat apps, inability to withdraw. Response: stop payment, report to IC3 immediately since freezes work best within days, preserve chat and transaction records, and beware follow-on "recovery scams."
Deepfake-enabled fraud
2025 saw 1,567 verified incidents and more than $1.28B in documented losses — a floor, since over 80% of incidents had no disclosed damage. Pindrop measured a 680% year-over-year rise in deepfake activity in contact centers; Entrust put deepfakes at roughly one in five biometric fraud attempts in 2025. IC3 logged 22,364 AI-related complaints with $893M in losses. The landmark case remains Arup's Hong Kong office losing roughly $25M in 2024 to a deepfaked video call in which every other participant, including the CFO, was AI-generated. Attempted voice-clone frauds against Ferrari and WPP executives in 2024 were thwarted by challenge questions — which is the lesson.
Controls. Treat voice and video as unauthenticated channels for payment approval; establish code words and out-of-band callbacks; require dual authorization; brief executives and finance teams specifically. Detection tools are unreliable on their own; process controls outperform detectors.
SIM swapping and identity theft
Attackers socially engineer or bribe telecom staff to port a victim's number, defeating SMS-based MFA — a staple of crypto theft crews. Controls: carrier port-freeze and number-lock features, removing SMS as MFA for high-value accounts, and treating sudden loss of cell service as an active-attack indicator. Identity theft is fed by the stolen-data economy; IC3 logged 67,456 personal-data-breach complaints in 2025. Consumer defenses: credit freezes, breach vigilance, unique credentials, and IRS IP PINs in the US.
11. Nation-state operations
China
Salt Typhoon — compromise of telecom providers in the US and worldwide. The FBI says targets spanned more than 80 countries and it notified 600 organizations; access reportedly reached call data of senior US officials and lawful-intercept systems. A 13-nation joint advisory was issued August 27, 2025, one of the longest ever, with hunting guidance. [Confirmed, with PRC-linked contractor attribution as assessment]
Volt Typhoon — pre-positioning inside US critical infrastructure (energy, water, communications, transport) using living-off-the-land techniques for potential disruptive use in a crisis, per the CISA/NSA/FBI advisory AA24-038A of February 2024. The KV-botnet of hijacked routers was dismantled in January 2024. 2025–26 reporting indicates the actor remains active and adapting: exposure raised defenses but did not end the campaign. [Confirmed advisories; intent is assessment]
Momentum. China-nexus operations rose 38% in 2025 with logistics targeting up 85%. ENISA names UNC5221, Mustang Panda, and APT41 as top China-linked actors in Europe. M-Trends highlights edge-device zero-day exploitation — mean time-to-exploit fell seven days, meaning exploitation before patches — and the BRICKSTORM backdoor persisting roughly 400 days. High technology became Mandiant's most-targeted industry at 17%, displacing financial services.
Russia
The most active state-nexus actor in EU incidents per ENISA; continued targeting of Ukraine and NATO logistics; espionage against email and cloud systems; sabotage-adjacent hacktivist fronts; and the Doppelgänger disinformation network of cloned news sites, subject to DOJ domain seizures in September 2024 and EU sanctions in 2025. 2026 reporting attributes destructive and OT-focused attacks on Polish energy and water utilities and Nordic facilities to Russian actors.
Iran
Espionage plus hack-and-leak and hacktivist-front personas. After the June 2025 Israel–Iran conflict, CISA, the FBI, NSA, and DC3 issued a joint fact sheet warning of potential Iranian attacks on poorly secured US networks and OT devices. The historical pattern is opportunistic attacks on internet-exposed industrial devices, exemplified by CyberAv3ngers against Unitronics devices at water utilities in 2023. In 2026, Iranian actors were reported to have remotely wiped devices at medtech firm Stryker.
North Korea
Dual-track: revenue theft and espionage. $2.02B stolen in crypto in 2025, 76% of all exchange-compromise losses, led by the $1.5B Bybit heist of February 2025 attributed to TraderTraitor/Lazarus, laundered through a structured roughly-45-day pipeline of mixers, DeFi, and marketplaces — plus the IT-worker scheme covered in section 9.
Hacktivism and disinformation
ENISA 2025: hacktivists caused roughly 80% of EU incident volume, mostly nuisance DDoS, with about 2% disruptive, and campaigns synchronized to geopolitical events in Ukraine and the Middle East. Disinformation operations increasingly use AI-generated content; impact should be assessed separately from volume, since takedown data shows persistent but often low-engagement campaigns.
12. The criminal ecosystem and its actors
A specialized supply chain. Malware developers → phishing and vishing crews → initial-access brokers (prices up roughly 50% in 2024 per Europol; Chainalysis observed IAB-linked payment flows averaging around $14M) → RaaS affiliates → money-laundering networks including cash-for-crypto and sanctioned exchanges such as Garantex and Huione. Marketplaces include BreachForums, repeatedly seized and reborn, and Nulled and Cracked with more than 5 million users, seized in January 2025's Operation Talent.
The Com lineage — Scattered Spider, ShinyHunters, LAPSUS$. Thousands of mostly young, English-speaking actors organized in loose online communities, distinguished by elite social engineering against help desks, MFA fatigue, and SIM swaps. 2025 saw a "Scattered LAPSUS$ Hunters" convergence running the Salesforce extortion wave. After the UK's July 10, 2025 arrests of four suspects over the M&S and Co-op attacks, Mandiant observed no new directly attributable Scattered Spider intrusions for months and said the arrests "spooked other members," while warning that the broader Com persists. US member Noah Urban was sentenced to 10 years with roughly $13M restitution in August 2025.
Script kiddies becoming professionals. Low barriers — phishing kits, malware-as-a-service at $250–$1,000 a month, AI assistance — let unskilled actors cause outsized harm. DBIR 2026 found the median malicious actor used AI across 15 documented techniques, accelerating existing methods rather than inventing new ones.
Threat-actor taxonomy for the site: organized cybercrime groups, ransomware affiliates, initial-access brokers, state-sponsored groups, hacktivists, malicious and negligent insiders, opportunistic attackers, fraud networks, malware operators, and low-skill actors. Each entry should carry the same fields: typical targets, motive, capability level, characteristic tradecraft at a high level, and the controls that most reduce exposure to them.
13. Law-enforcement disruptions, 2023–2026
| Date | Action | Outcome |
|---|---|---|
| Apr 2023 | Genesis Market (Operation Cookie Monster) | Credential marketplace seized; ~1.5M compromised machines, 80M credential sets; 119 arrests |
| Aug 2023 | Qakbot (Operation Duck Hunt) | Botnet dismantled, malware removed from ~700K machines, $8.6M seized; alleged leader Rustam Gallyamov indicted May 2025 with $24M seized |
| Feb 2024 | LockBit (Operation Cronos) | Infrastructure and keys seized; "LockBitSupp" (Dmitry Khoroshev) sanctioned and charged. LockBit 5.0 reappeared Sept 2025 — degraded, not destroyed |
| May 2024 | Operation Endgame I | 100+ dropper servers down, 2,000+ domains seized |
| Dec 2024 | Operation Destabilise | 84 arrests dismantling Russian-linked crypto laundering networks; $25M seized |
| Jan–Feb 2025 | Operation Talent; 8Base/Phobos arrests; Zservers sanctions | Marketplace and RaaS disruption |
| May 2025 | Lumma Stealer takedown; Operation Endgame II | 2,300+ domains seized; DanaBot dismantled with 16 named actors; ~300 servers and 650 domains seized |
| Jul 2025 | UK Scattered Spider arrests; BlackSuit leak-site seizure | Months-long lull in attributable activity |
| Oct 2025 | Prince Group / Huione | ~$15B BTC forfeiture (largest ever); 146 sanctions; Chen Zhi indicted |
Net assessment. Takedowns rarely end groups outright — Lumma resurged, LockBit returned, DanaBot rebuilt — but they demonstrably corrode trust, fragment RaaS brands, depress payment rates, and push the ecosystem toward smaller, less professional operations running weaker, sometimes decryptable malware. Arrests of Western-based actors appear to change incentives more durably than infrastructure seizures.
14. Cryptojacking
Lower-profile than in 2021–22 but persistent: unauthorized mining monetizes stolen cloud compute and unpatched servers, and in cloud environments it usually signals broader credential compromise rather than being the whole incident. Warning signs: unexplained cloud-bill spikes, sustained CPU anomalies. Controls: budget and usage alerts, workload monitoring, locking down exposed APIs and CI/CD runners — note that the npm worm's harvesting of cloud keys directly feeds mining operations.
15. Cross-cutting defensive priorities
- Identity is the battleground. Phishing-resistant MFA, hardened help-desk verification, OAuth and app-grant governance, short token lifetimes.
- Patch what is actually exploited, fast. Exploits lead IR vectors six years running; CrowdStrike found 42% of exploited vulnerabilities were zero-days before disclosure; KEV remediation fell to 26%. Prioritize edge devices, which lack EDR telemetry.
- Assume 29-minute breakout and 22-second hand-offs. Treat minor alerts as critical; pre-authorize automated containment.
- Protect recovery itself. Immutable backups; Tier 0 treatment for hypervisor, backup, and identity planes.
- Manage third-party blast radius. Inventory OAuth integrations and vendor access now, not during an incident.
- Tune human-layer defenses to 2026 reality — vishing and deepfakes, not just email; payment-change verification rituals.
- Report fast. The FBI kill chain recovered 58% of attempted BEC transfers in 2025; early reporting materially changes outcomes.