patch&proof.
← Research library

Case studies / Research chapter

The Cybersecurity Ecosystem and Case Studies

Research date: September 14–15, 2026. Who does what in cybersecurity, and the incidents and defenses that shaped 2023–2026. Evidence labels: Confirmed, Vendor,

From the supplied September 2026 research package. Historical figures and evolving policy require source review; see the correction record.

Research date: September 14–15, 2026. Who does what in cybersecurity, and the incidents and defenses that shaped 2023–2026. Evidence labels: [Confirmed], [Vendor], [Assessment].


Part A — Who does cybersecurity

A1. Security product vendors

The product market is dominated by a handful of platform vendors, and 2024–26 was defined by consolidation.

Microsoft has the largest security revenue of any vendor, above a $20B annual run rate by its own reporting [Vendor], and runs the Secure Future Initiative, which it describes as its largest engineering security mobilization since Trustworthy Computing in 2002. Palo Alto Networks pursues a platform strategy and closed its roughly $25B acquisition of identity leader CyberArk in February 2026. CrowdStrike leads endpoint detection and is also a major incident-response and threat-intelligence player; it recovered its market position after the July 19, 2024 faulty content update that crashed roughly 8.5 million Windows hosts — itself a canonical case study in software fragility, though not an attack. Google runs Mandiant and Chronicle under Google Cloud Security and closed its $32B acquisition of Wiz on March 11, 2026, the largest pure-cybersecurity acquisition ever. Others of scale: Fortinet, Zscaler (which acquired MDR firm Red Canary in 2025), SentinelOne, Check Point, Cisco (post-Splunk), Okta, Cloudflare, and Cyera.

[Assessment] The structural trend is platform consolidation versus best-of-breed. Buyers are reducing vendor count, and the largest 2025–26 deals — Wiz, CyberArk, and Zurich's acquisition of Beazley on the insurance side — all reflect large platforms absorbing category leaders. The buyer consequence is concentration risk, which 2024–26 events demonstrated runs in both directions.

A2. MSSPs, MDR, and penetration-testing firms

MDR is the fastest-growing services segment — outsourced 24/7 monitoring and response for organizations that cannot staff a SOC. Notable players: Arctic Wolf (which acquired BlackBerry's Cylance endpoint unit in February 2025), Sophos (which acquired Secureworks for $859M, closing February 2025), Huntress (SMB-focused and the price-transparency leader), Expel, Red Canary (now Zscaler), eSentire, plus the MDR arms of CrowdStrike and SentinelOne.

Penetration-testing and offensive-security firms: Bishop Fox, NCC Group, Trail of Bits — which also placed second in DARPA's AI Cyber Challenge — Synack, and the PTaaS platforms. Continuous and automated penetration testing (Horizon3.ai, Pentera) is increasingly AI-assisted.

A3. Incident response and ransomware negotiation

Mandiant (Google Cloud) anchors the IR retainer market and publishes M-Trends. CrowdStrike Services and Palo Alto Unit 42 combine IR with threat research. Coveware (a Veeam company) publishes the quarterly ransomware negotiation data that underpins the finding that payment rates have fallen to record lows. Chainalysis provides blockchain analytics to law enforcement and IR firms and produces the on-chain ransom-payment series.

A4. Cyber insurance

Market state, 2025 results reported mid-2026. US cyber premium was essentially flat in 2025, and the market has seen eight consecutive quarters of rate cuts through Q1 2026 — a soft market. But the industry loss ratio rose to roughly 53, above 50 for the first time since the pandemic-era ransomware spike, and third-party liability claims are up roughly 30% year over year. Chubb led 2025 direct premium; Zurich's acquisition of Beazley will make it the largest cyber insurer going forward [Confirmed].

Insurtech carriers Coalition and At-Bay pioneered "active insurance" — continuous external scanning of policyholders with alerting on exposed services as a condition of coverage. Cowbell, Corvus (acquired by Travelers in 2024), and Resilience follow similar models.

Underwriting requirements have become a de facto security baseline: MFA especially on remote access and privileged accounts, EDR, offline and tested backups, and increasingly managed detection are required or heavily priced in.

[Assessment] Analysts including AM Best and DUAL warn that 2026 is a turning point: falling prices plus rising loss ratios plus growing third-party and AI-related claims are not sustainable. Expect requirement tightening and possible re-hardening of rates.

A5. Government agencies

CISA (US). The FY2026 budget proposed cutting roughly $495M and about 1,000 positions — approximately a third of CISA's workforce. Independent reporting through 2025–26 indicates CISA lost roughly a third of staff through cuts, buyouts, and attrition, with senior leaders including the Secure by Design architects departing, and lawmakers warning of a widening national capability gap [Confirmed proposal; staffing losses widely reported, some sources advocacy-framed].

NSA and Cyber Command provide signals intelligence and, through the Cybersecurity Collaboration Center, defense-industrial-base support; leadership churn occurred in 2025. The FBI runs the cyber division and IC3, the public reporting channel for US cybercrime — victims file at ic3.gov, complaints are triaged to field offices, and the Recovery Asset Team can attempt to freeze fraudulent wires when reported quickly, having frozen $679M of $1.164B in attempted transfers in 2025. The US Secret Service covers financial cybercrime, BEC, and crypto seizures.

ENISA (EU) implements NIS2 technical guidance and the Cyber Resilience Act ecosystem and runs the EU vulnerability database launched in 2025. UK NCSC, part of GCHQ, was central in the 2025 UK retail attack wave and the JLR incident, publishes the Cyber Assessment Framework, and handled 429 incidents in its 2025 annual review, of which 204 were nationally significant — up from 89.

National CERTs and CSIRTs provide country-level coordination, connected through FIRST, which also stewards CVSS 4.0 and EPSS.

A6. Law enforcement

Europol EC3 anchors multinational takedowns including Operation Cronos against LockBit and Operation Endgame against the malware-delivery ecosystem. The UK NCA led Operation Cronos and made the four arrests in July 2025 in the M&S, Co-op, and Harrods case. US DOJ and FBI produce the indictments naming ransomware leaders — LockBit's Khoroshev, Qakbot's Gallyamov — plus seizures and the Snowflake prosecutions.

A7. Researchers, bug bounties, and open source

Bug-bounty platforms. HackerOne reported paying $81M in bounties over its 2025 report period, with a 210% spike in AI-vulnerability reports [Vendor, widely reported]. Google alone paid roughly $12M across its vulnerability reward programs in 2024. Bugcrowd and Europe-centric Intigriti complete the big three; crowdsourced penetration testing and AI-assisted triage of submissions are the platform-side trends.

Universities and NSF. The flagship federal workforce pipeline, CyberCorps: Scholarship for Service, was restructured in the FY2026 cycle as CyberAICorps (CyberAI SFS) with an explicit AI-security emphasis [Confirmed]. [Assessment] The rebrand signals AI-security workforce demand, though 2025 uncertainty around federal placements amid hiring cuts complicates the pipeline.

Open-source security. OpenSSF and the Linux Foundation — Scorecard, Sigstore, Alpha-Omega funding for critical projects — remain the main institutional response to the XZ Utils near-miss. OWASP now also runs the GenAI Security Project. The relevance was underscored by 2026 open-source build-chain compromises at Trivy, Bitwarden, and Checkmarx, with downstream impact reaching companies including OpenAI and Vercel [Confirmed].

A8. Cloud providers, identity providers, and standards bodies

Shared responsibility is the concept the ecosystem turns on: AWS, Azure, and GCP secure the infrastructure; customers secure configuration, identity, and data. The Snowflake 2024 campaign is the canonical teaching case — no platform breach, only customer credentials without MFA. Notable programs: Microsoft's Secure Future Initiative, AWS Security Hub and GuardDuty, and Google's 2025 mandatory-MFA push.

Identity providers: Okta, Microsoft Entra ID, Ping Identity, with CyberArk absorbed into Palo Alto and SailPoint re-listed in February 2025. Help-desk identity verification has become its own product category as a direct response to Scattered Spider.

Standards bodies: NIST, ISO/IEC, IETF, CIS, PCI SSC, and FIRST — covered in detail in 04-frameworks-and-standards.md.

A9. Venture investment

2024 rebounded from the 2022–23 trough and 2025 was strong on the AI-security thesis. H1 2026 saw roughly $10.6B raised by cybersecurity and privacy startups, though Q2 2026 at roughly $4.4B dipped about 30% quarter over quarter [Confirmed data].

Notable 2026 rounds: Cyera at $600M on a $12B valuation (AI and data security), NinjaOne at $400M+ on $12.3B, and Dream at $260M on $3B (critical-infrastructure AI defense). Notable exits: Google–Wiz at $32B, Palo Alto–CyberArk at roughly $25B, Motorola–D-Fend at $1.5B in counter-drone, and Zurich–Beazley in insurance. The IPO market was notably quiet in 2026 after Netskope's September 2025 listing.

[Assessment] Capital is concentrating in fewer, larger rounds, and AI security — both "AI for security" and "security for AI" — is the dominant thesis.


Part B — Case studies

B1. Major incidents

Change Healthcare / UnitedHealth (February 2024). ALPHV/BlackCat ransomware entered through a Citrix remote-access portal lacking MFA, knocking out claims and pharmacy processing for much of US healthcare for weeks. Final count: roughly 193 million people — the largest healthcare breach in US history. Total company costs approximately $2.9B; UnitedHealth confirmed paying a $22M ransom, after which ALPHV exit-scammed its own affiliate [Confirmed]. Lesson: single points of failure plus a missing MFA control, at systemic scale.

Snowflake customer attacks (April–June 2024). UNC5537 used infostealer-harvested credentials, some years old, against roughly 165 Snowflake customer tenants without MFA — AT&T, Ticketmaster, Santander and others. Not a Snowflake platform breach. Connor Moucka pleaded guilty in US court in August 2026, facing up to roughly 32 years and forfeiting about $18M; co-conspirators were also charged or convicted [Confirmed]. Lesson: shared responsibility, credential hygiene, and mandatory MFA. Snowflake subsequently made MFA default.

Salt Typhoon (disclosed late 2024, ongoing). Chinese state-linked espionage inside at least nine US telecoms, including lawful-intercept systems. By August 2025 the FBI said the campaign touched 80-plus countries and roughly 600 organizations, exploiting unpatched edge devices. A 13-nation joint advisory (CISA AA25-239A) was issued August 27, 2025 [Confirmed].

MOVEit (May–June 2023). Cl0p mass-exploited a zero-day in Progress MOVEit Transfer, ultimately affecting 2,700-plus organizations and roughly 95 million individuals [Confirmed]. Lesson: the template for "exploit one file-transfer product, extort thousands."

MGM Resorts and Caesars (September 2023). Scattered Spider vishing of IT help desks led to ALPHV ransomware at MGM, with roughly $100M in losses and days of casino and hotel outage; Caesars paid roughly $15M [Confirmed]. Lesson: the precursor of the 2025 UK retail wave, and the origin of help-desk verification as a product category.

CDK Global (June 2024). Ransomware at the SaaS provider serving roughly 15,000 North American car dealerships; approximately $25M reportedly paid; dealer losses estimated near $1B [Confirmed impact; payment reported]. Lesson: sector-wide SaaS concentration risk.

Synnovis / NHS London (June 2024). Qilin ransomware at a pathology provider postponed thousands of appointments and operations and affected the national blood supply. In 2025 the NHS confirmed the attack contributed to at least one patient death — the clearest documented cyber-attack-to-patient-harm link in the UK [Confirmed].

Ascension (May 2024). Black Basta ransomware across roughly 140 hospitals: ambulance diversions, weeks on paper charts, and approximately 5.6 million patients' data [Confirmed].

UK retail wave — M&S, Co-op, Harrods (April–May 2025). Scattered Spider-style help-desk social engineering, in M&S's case through a third-party IT contractor, led to DragonForce ransomware at M&S. Co-op pulled its own systems offline mid-intrusion — a successful containment decision worth teaching. Harrods restricted access. M&S estimated roughly £300M in profit impact; the Cyber Monitoring Centre put combined losses at £270–440M. The NCA arrested four suspects in July 2025, including teenagers [Confirmed].

Jaguar Land Rover (August 31–October 2025). A cyberattack forced a five-plus-week global production shutdown. JLR booked a £196M direct charge, while the Cyber Monitoring Centre estimated total UK economic impact around £1.9B — assessed as the most economically damaging cyber event in UK history. The UK government backed a £1.5B loan guarantee to stabilize JLR's supply chain. Attribution claims pointed to Scattered Spider and ShinyHunters-linked actors but were not officially confirmed [Confirmed impact; attribution = claims].

Microsoft SharePoint "ToolShell" (July 2025). A zero-day chain (CVE-2025-53770/53771), a patch bypass of flaws demonstrated at Pwn2Own, was exploited in the wild against on-premises SharePoint. More than 400 organizations were compromised, including the US National Nuclear Security Administration. Microsoft attributed activity to Chinese groups Linen Typhoon, Violet Typhoon, and Storm-2603, the last deploying ransomware [Confirmed].

F5 Networks (disclosed October 15, 2025). A nation-state actor had long-term access to F5's product development environment and stole BIG-IP source code and details of undisclosed vulnerabilities, plus some customer configuration data. CISA issued Emergency Directive ED 26-01 ordering federal agencies to inventory and patch. Reporting linked the activity to China-nexus tooling [Confirmed breach; attribution = assessment]. Lesson: the security vendor's own development environment is part of your attack surface.

Salesloft Drift → Salesforce data-theft wave (August 2025). UNC6395 stole OAuth tokens from the Salesloft Drift chatbot integration and used them to bulk-export Salesforce CRM data from more than 700 customer organizations, including security vendors Cloudflare, Zscaler, and Palo Alto Networks, then mined the exports for embedded AWS keys and Snowflake tokens. Later extortion was claimed by the ShinyHunters nexus, which also ran a parallel voice-phishing campaign against Salesforce tenants [Confirmed]. Lesson: SaaS-to-SaaS OAuth integrations are a supply chain; token scope and monitoring matter as much as passwords.

2026 to date. ShinyHunters-linked mass data thefts continued — Instructure/Canvas affecting 30 million-plus students and staff, Charter at roughly 40 million records, Carnival at 6 million-plus. The Klue breach (June 2026, "Icarus" extortion) exposed roughly 200 downstream companies' cloud service keys. Hasbro suffered weeks of downtime in March 2026. Russian-attributed destructive and OT attacks hit Polish energy and water utilities and Nordic facilities; Iranian actors remotely wiped devices at medtech firm Stryker; and multiple open-source projects had build-chain compromises [Confirmed reporting; some attributions preliminary].

B2. Successful defenses and disruptions

LockBit — Operation Cronos (February 2024). The NCA, FBI, and Europol seized infrastructure, obtained decryption keys, unmasked and sanctioned leader Dmitry Khoroshev, and trolled the brand on its own leak site. The honest outcome: the takedown shattered affiliate trust and LockBit's leading position, but the group returned with LockBit 5.0 in September 2025 — degraded, not destroyed [Confirmed].

ALPHV/BlackCat. The FBI seized infrastructure and released a decryptor in December 2023; the group "unseized" its site, then exit-scammed with the Change Healthcare ransom in March 2024 and dissolved. Disruption partly through induced distrust rather than direct takedown [Confirmed].

Qakbot — Operation Duck Hunt (August 2023). An FBI-led takedown removed the botnet from more than 700,000 machines, with alleged leader Rustam Gallyamov indicted in May 2025 and $24M in crypto seized [Confirmed].

Operation Endgame (May 2024, expanded May 2025). Europol, DOJ, and Microsoft's Digital Crimes Unit disrupted the malware-delivery ecosystem; the 2025 phase seized roughly 300 servers and 650 domains, dismantled DanaBot with 16 named actors, and took down Lumma Stealer across roughly 2,300 domains. Caveat: both Lumma and DanaBot showed partial resurgence within months [Confirmed].

Volt Typhoon exposure. The CISA/NSA/FBI advisory AA24-038A of February 2024 publicly detailed Chinese pre-positioning in US water, power, and transport networks, and the DOJ dismantled the KV-botnet of hijacked routers in January 2024. 2025–26 reporting indicates the actor remains active and adapting — exposure raised defenses but did not end the campaign [Confirmed].

Scattered Spider prosecutions. Arrests across the US, UK, and Spain between 2024 and 2026, including the July 2025 UK four and Noah Urban's ten-year US sentence, visibly suppressed but did not eliminate the ecosystem. Mandiant observed no new directly attributable intrusions for months following the arrests.

Vulnerability-disclosure wins. The XZ Utils backdoor (CVE-2024-3094) was caught pre-deployment by Microsoft engineer Andres Freund in March 2024 — a near-miss that would have backdoored much of the Linux ecosystem. Google's Big Sleep caught SQLite CVE-2025-6965 before threat actors could exploit it in July 2025 [Confirmed].

B3. Public-private partnership status

JCDC (Joint Cyber Defense Collaborative) continues to operate but [Assessment] has been materially weakened by 2025–26 CISA budget and staff losses and by reported private-sector participation friction.

Secure by Design. The voluntary pledge exceeded roughly 300 signatory companies, with CISA publishing progress reports and vendors self-reporting MFA-default and vulnerability-transparency gains [Confirmed program; outcomes largely vendor self-reported]. The program's champions left CISA in 2025, so momentum now rests with signatories, buyer-side "Secure by Demand" procurement pressure, and international counterparts at NCSC and ENISA.


Part C — Five teaching takeaways

1. Identity is the battleground. Snowflake, MGM, M&S, and Salesloft: credentials, MFA gaps, help desks, and OAuth tokens beat exploits in most 2023–26 mega-incidents, even as exploitation overtook credentials in aggregate breach statistics. Both things are true, and the distinction is between how most breaches start and how the biggest ones happened.

2. Concentration risk is systemic risk. Change Healthcare, CDK, MOVEit, the CrowdStrike outage, and Salesloft all show one vendor's failure cascading across entire sectors. This is now a board-level and a policy-level issue, and it is the reason DORA regulates critical ICT providers directly.

3. Takedowns disrupt, rarely destroy. LockBit 5.0 and DanaBot's return prove the point. But arrests of Western-based actors — Scattered Spider, Moucka — appear to change incentives more durably than infrastructure seizures, which is a genuinely useful policy finding.

4. The public backbone is weakening as threats grow. CISA lost roughly a third of its staff while Salt Typhoon and Volt Typhoon expanded. Private-sector and allied capability matters more as a result, and the site should report this factually rather than as advocacy.

5. AI shifted attacker economics before defender economics — but the defensive wins are real. Big Sleep, AIxCC, and AI-assisted triage are genuine. The honest frame is augmentation on both sides, with prompt injection as the new unpatched vulnerability class.

Evidence & dates

Follow the source.

Source published
See individual source / original research
Event date
No single confirmed day assigned
Site publication
Unpublished · local review
Make it useful

Turn the reading into a decision.

Open the interactive lab ↗
Search the evidence
Source image / inspection view

View original source ↗Local review · rights and provenance pending owner approval