Executive Summary
During the past 30-days, a total of 2,896 cyberattacks were recorded globally across all tracked categories. This represents a notable decline of 17.7%, compared to the previous month, where 3,520 incidents were logged. Despite the volumetric reduction, the threat landscape remained highly varied and operationally significant, with activity spanning ransomware, large-scale data exfiltration campaigns, and coordinated DDoS operations targeting sovereign and commercial infrastructure simultaneously.

The dominant attack categories for this period were Data Leak/Exfiltration (1,193 incidents), DDoS (1,017 incidents), and Ransomware (678 incidents), collectively accounting for nearly the entirety of recorded events. The most targeted sector globally was Government (710 attacks), followed by Financial Services (294), Energy (274), and Manufacturing (247).
The most prolific threat actor of the period was NoName057(16), responsible for 284 recorded attacks, predominantly DDoS operations against NATO-aligned and European government targets, followed by the ransomware group Qilin, with 150 attributed incidents.
Geographically, the United States ranked first with 520 total attacks, driven primarily by ransomware and data exfiltration. Israel ranked second (208 attacks), subjected almost entirely to DDoS campaigns. Indonesia (190) and Thailand (152) featured prominently in the Asia-Pacific cluster, with government sectors bearing the heaviest burden in both nations.
The concentration of politically motivated DDoS activity across European and Middle Eastern targets, combined with sustained ransomware pressure on the US and France, underscores an environment where hacktivist and financially motivated actors are operating in parallel with comparable intensity.
Strategic Context
Geopolitical conflicts continue to fuel cyber disruptions targeting critical infrastructure, particularly in Europe, with Russia persisting in leveraging cyber capabilities to pressure NATO-aligned nations. This dynamic is directly reflected in the data: NoName057(16)'s concentrated DDoS campaigns against Austria, the UK, Ukraine, and France are consistent with the group's well-established pattern of politically motivated operations tied to European support for Ukraine. Cybercrime is also further internationalising, as AI-assisted translation tools and improved defences in traditional targets push threat actors to expand into newer regions and populations less experienced in countering cybercrime. This may explain the growing volume of attacks in Southeast Asia, particularly Indonesia and Thailand, where government and financial sectors face escalating data exfiltration campaigns from actors such as Mr. Hanz Xploit and ZxS3C.
The costs associated with the global epidemic of cybercrime rise into the trillions of dollars, and the growing scale and sophistication of these challenges mean that narrow, technical solutions to cybersecurity are no longer sufficient. The financial sector's exposure this period, 294 attacks globally, (349 when finance-adjacent subsectors are included) reflects the sector's enduring status as a high-value target for both ransomware groups and hacktivists.
April 2026 was dominated by supply-chain compromises and OAuth abuse, with two major US banks hit through a shared third-party vendor, and a French government identity agency having records on millions of citizens offered for sale. This pattern of third-party and supply-chain exploitation is directly consistent with the multi-organisation victim clusters observed in the US and French country breakdowns within the dataset. AI-assisted attacks are rising sharply, and zero-day vulnerabilities are being exploited faster than security teams can respond. Defenders and intelligence analysts must treat this reporting period's decline in volumetric attack count not as de-escalation, but as a potential redistribution of effort toward higher-impact, lower-noise intrusion campaigns.
Recent Headlines
- Canvas Hack: Company pays criminals to delete students' stolen data: In late April 2026, Canvas LMS, operated by Instructure, was affected by a data breach and outage, with the company disclosing a cybersecurity attack involving user data including names, email addresses, student ID numbers, and messages.
- Coinbase Breach Compromises Nearly 70K Customers' Data: Dark Reading: A data breach affecting nearly 70,000 Coinbase users led to firings, heightened security, and a $20 million bounty, with the incident attributed to the misconduct of a small group of external contractors.
- Booking.com customers warned of 'reservation hijacking' after hack: Booking.com, which offers lodging services across over 200 countries, became a victim of a data breach that exposed customer data, with the company notifying customers on April 12 that their reservation details were compromised.
- Global Rise of Cyberattacks Exposes Limits of Technical Solutions: UN News: The costs of the global cybercrime epidemic rise into the trillions, driving a shift toward cyber resilience: whereby systems and societies are collectively able to react, adapt, and recover when attacks occur.
- Biggest Cyber Attacks of 2026 & Their Impact: REVA University RACE Lab: A ransomware attack on the AZ Monica hospital network in Belgium locked down every server at the Antwerp and Deurne campuses, forcing surgeons to cancel 70 procedures and emergency-transferring seven critical care patients via the Red Cross.
Attack Statistics
| Metric | Value |
|---|---|
| Total Attacks (Period) | 2,896 |
| Prior Period Total | 3,520 |
| Week-over-Week Change | -17.7% |
| Top Threat Actor | NoName057(16) (284 attacks) |
| Top Targeted Country | United States (520 attacks) |
| Top Targeted Sector | Government (710 attacks) |
| Dominant Attack Category | Data Leak / Exfiltration (1,193 incidents) |
| Second Attack Category | DDoS (1,017 incidents) |
| Third Attack Category | Ransomware (678 incidents) |
Country by Country Breakdown
United States
| Metric | Detail |
|---|---|
| Total Attacks | 520 |
| Top Category | Ransomware (276) |
| Second Category | Data Leak / Exfiltration (199) |
| Third Category | DDoS (43) |
Top Threat Actors
| Threat Actor | Attacks |
|---|---|
| Qilin | 71 |
| akira | 29 |
| INC RANSOM | 27 |
| DragonForce | 17 |
| The Gentlemen | 15 |
Top Industries
| Industry | Attacks |
|---|---|
| Energy | 66 |
| Financial Services | 64 |
| Manufacturing | 53 |
| Retail | 52 |
| Critical Infrastructure | 50 |
Notable Organisations Targeted: GITHUB, COINBASE, U.S. CHAMBER OF COMMERCE, CUSHMAN & WAKEFIELD, OPENAI, MICROSOFT, INSTAGRAM
Commentary
The United States remains the single most attacked country in this reporting period, with ransomware accounting for over 53% of domestic incidents, the highest ransomware concentration of any tracked nation. The Financial Services and Energy sectors together absorbed 130 of 520 total attacks, underscoring persistent adversarial interest in high-value economic infrastructure. The appearance of Coinbase and OpenAI among notable targeted organisations reflects the dual focus of threat actors on both the financial technology and artificial intelligence sectors.
Israel
| Metric | Detail |
|---|---|
| Total Attacks | 208 |
| Top Category | DDoS (179) |
| Second Category | Data Leak / Exfiltration (28) |
| Third Category | Ransomware (1) |
Top Threat Actors
| Threat Actor | Attacks |
|---|---|
| RuskiNet Group | 42 |
| DieNet | 33 |
| RipperSec | 31 |
| BD Anonymous | 16 |
| ZxS3C | 16 |
Top Industries
| Industry | Attacks |
|---|---|
| Government | 41 |
| Energy | 21 |
| Financial Services | 21 |
| Retail | 17 |
| Education | 14 |
Notable Organisations Targeted: ISRAEL POST, MOSSAD, TZEVA ADOM, PORT OF HAIFA, WEIZMANN INSTITUTE OF SCIENCE, ALLCARGO LOGISTIC SERVICES LTD., GALEI ISRAEL RADIO
Commentary
Israel's attack profile is overwhelmingly DDoS-driven (86% of incidents), reflecting the activity of hacktivist collectives, RuskiNet Group, DieNet, and RipperSec, conducting politically motivated disruption campaigns against Israeli civilian, government, and logistical targets. The targeting of critical port infrastructure (Port of Haifa) and intelligence institutions (Mossad) suggests an intent to maximise symbolic impact alongside operational disruption.
Indonesia
| Metric | Detail |
|---|---|
| Total Attacks | 190 |
| Top Category | Data Leak / Exfiltration (160) |
| Second Category | DDoS (25) |
| Third Category | Ransomware (5) |
Top Threat Actors
| Threat Actor | Attacks |
|---|---|
| Mr. Hanz Xploit | 36 |
| JAX7 | 17 |
| Space Stresser | 15 |
| Xyph0rix | 13 |
| Kyyzo | 11 |
Top Industries
| Industry | Attacks |
|---|---|
| Government | 87 |
| Education | 30 |
| Financial Services | 11 |
| Energy | 10 |
| Technology | 10 |
Notable Organisations Targeted: KORBRIMOB POLRI, INDONESIAN NATIONAL POLICE (POLRI), BANK NEGARA INDONESIA, INSTITUT TEKNOLOGI BANDUNG, TOKOPEDIA, EAST KALIMANTAN SOCIAL SERVICES
Commentary
Indonesia stands out as the most data-exfiltration-focused country in this dataset, with 84% of its 190 incidents classified as Data Leak / Exfiltration. Government entities absorb nearly half of all Indonesian attacks (87 of 190), with repeated targeting of law enforcement bodies such as Korbrimob Polri and the Indonesian National Police, suggesting a deliberate focus on undermining state security institutions. The scale of Mr. Hanz Xploit's activity (36 attacks) warrants dedicated monitoring.
Thailand
| Metric | Detail |
|---|---|
| Total Attacks | 152 |
| Top Category | DDoS (113) |
| Second Category | Data Leak / Exfiltration (27) |
| Third Category | Ransomware (12) |
Top Threat Actors
| Threat Actor | Attacks |
|---|---|
| ZxS3C | 60 |
| Blue Shadow | 26 |
| NOTCTBER | 14 |
| taomarita | 12 |
| ZAHER INFINITY | 11 |
Top Industries
| Industry | Attacks |
|---|---|
| Government | 68 |
| Education | 18 |
| Financial Services | 15 |
| Manufacturing | 7 |
| Critical Infrastructure | 6 |
Notable Organisations Targeted: OFFICE OF THE COUNCIL OF STATE, ROYAL FOREST DEPARTMENT, BANGKOK BANK (BBL), UNITED OVERSEAS BANK (UOB), SIAM COMMERCIAL BANK (SCB), KASIKORN BANK (KBANK), CIMB THAI BANK (CIMB), KRUNG THAI BANK (KTB)
Commentary
Thailand's threat environment is characterised by a dual-pronged assault: ZxS3C-led DDoS campaigns against government entities account for the majority of incidents, while the financial sector faces a concentrated wave of attacks against multiple major retail banks simultaneously, with five distinct banking institutions appearing in the top-targeted organisations list. This pattern of parallel, multi-target banking sector disruption is an indicator of coordinated hacktivist campaign execution rather than opportunistic targeting.
Austria
| Metric | Detail |
|---|---|
| Total Attacks | 132 |
| Top Category | DDoS (126) |
| Second Category | Ransomware (5) |
| Third Category | Data Leak / Exfiltration (1) |
Top Threat Actors
| Threat Actor | Attacks |
|---|---|
| NoName057(16) | 105 |
| Dark Storm Team | 21 |
| payload | 2 |
| DragonForce | 1 |
| Qilin | 1 |
Top Industries
| Industry | Attacks |
|---|---|
| Government | 64 |
| Education | 13 |
| Energy | 12 |
| Manufacturing | 10 |
| Financial Services | 7 |
Notable Organisations Targeted: POINT OF CONTACT UKRAINE WIEDERAUFBAU, FEDERAL MINISTRY OF WOMEN, SCIENCE AND RESEARCH, LAND VORARLBERG, MARKTGEMEINDE KIRCHSCHLAG, AUSSCHREIBUNGSSUCHE, CITY OF HORN
Commentary
Austria's attack profile is almost entirely (95%) DDoS-driven, with NoName057(16) alone responsible for 105 of 132 incidents, the highest single-actor concentration in any tracked country this period. The targeting of Point of Contact Ukraine Wiederaufbau (a Ukraine reconstruction liaison body) alongside multiple federal and regional government ministries is directly indicative of the group's geopolitical targeting logic, penalising nations perceived as materially supporting Ukraine.
France
| Metric | Detail |
|---|---|
| Total Attacks | 123 |
| Top Category | Data Leak / Exfiltration (85) |
| Second Category | Ransomware (20) |
| Third Category | DDoS (18) |
Top Threat Actors
| Threat Actor | Attacks |
|---|---|
| ChimeraZ | 21 |
| NoName057(16) | 12 |
| NormalLeVrai | 8 |
| Qilin | 5 |
| Dark Storm Team | 4 |
Top Industries
| Industry | Attacks |
|---|---|
| Government | 20 |
| Retail | 15 |
| Financial Services | 14 |
| Energy | 14 |
| Education | 12 |
Notable Organisations Targeted: BOUYGUES TELECOM, NEMEA GROUP, STERIMED, LEDIL IMMOBILIER, THE NATIONAL COMMISSION FOR THE CONTROL OF INTELLIGENCE TECHNIQUES, CARTES BANCAIRES, CIFFCO
Commentary
France presents the most diversified attack-category profile of any European nation in this dataset, with a near-balance across exfiltration, ransomware, and DDoS. Notably, The National Commission for the Control of Intelligence Techniques and Cartes Bancaires (France's national bank card scheme) both appear as targeted organisations, highlighting adversarial interest in both surveillance oversight bodies and national payment infrastructure. The emergence of ChimeraZ as France's top threat actor by volume warrants further attribution analysis.
United Kingdom
| Metric | Detail |
|---|---|
| Total Attacks | 116 |
| Top Category | DDoS (56) |
| Second Category | Data Leak / Exfiltration (30) |
| Third Category | Ransomware (30) |
Top Threat Actors
| Threat Actor | Attacks |
|---|---|
| NoName057(16) | 45 |
| Qilin | 7 |
| Dark Storm Team | 4 |
| Akira | 3 |
| SAFEPAY | 3 |
Top Industries
| Industry | Attacks |
|---|---|
| Government | 26 |
| Energy | 14 |
| Transportation | 14 |
| Critical Infrastructure | 11 |
| Financial Services | 11 |
Notable Organisations Targeted: TRAFFORD COUNCIL, RAIL.CO.UK, QUALIFICATIONS WALES, PORT OF FELIXSTOWE, EVOLVE DYNAMICS, UBUNTU, FXPRO
Commentary
The United Kingdom faces a notably balanced threat environment, with DDoS, Data Leak / Exfiltration, and Ransomware each contributing meaningfully to the total incident count. The Transportation sector (14 attacks, on par with Energy) and the targeting of Rail.co.uk and Port of Felixstowe point to deliberate pressure on national logistics and supply chain infrastructure. NoName057(16)'s dominance (45 attacks) confirms the UK as a primary target of pro-Russian hacktivist operations in this period.
Ukraine
| Metric | Detail |
|---|---|
| Total Attacks | 99 |
| Top Category | DDoS (86) |
| Second Category | Data Leak / Exfiltration (11) |
| Third Category | Ransomware (2) |
Top Threat Actors
| Threat Actor | Attacks |
|---|---|
| NoName057(16) | 75 |
| Dark Storm Team | 8 |
| IT ARMY OF RUSSIA | 4 |
| 404 crew cyber team | 3 |
| Qilin | 2 |
Top Industries
| Industry | Attacks |
|---|---|
| Manufacturing | 24 |
| Government | 20 |
| Energy | 12 |
| Critical Infrastructure | 6 |
| Financial Services | 5 |
Notable Organisations Targeted: AUTOKRAZ, DNIPROAZOT, DNEPROSPETSSTAL, AMSTOR RETAIL GROUP, SPARING-VIST CENTRE, OCTAVA CAPITAL, BEZPEKA LTD
Commentary
Ukraine's incident profile is overwhelmingly DDoS-centric (87%), with NoName057(16) and IT ARMY OF RUSSIA collectively responsible for 79 of 99 incidents, a clear continuation of wartime cyber operations targeting Ukrainian industrial, governmental, and energy infrastructure. The Manufacturing sector leads with 24 attacks, reflecting strategic targeting of Ukrainian production capacity; organisations such as Autokraz (vehicle manufacturer), Dniproazot (chemical/fertiliser), and Dneprospetsstal (steel) represent dual-use industrial targets of military and economic significance.
Threat Actor Activity
| Rank | Threat Actor | Total Attacks | Primary Method | Primary Target Region |
|---|---|---|---|---|
| 1 | NoName057(16) | 284 | DDoS | Europe / Ukraine |
| 2 | Qilin | 150 | Ransomware | United States / Global |
| 3 | ZxS3C | 88 | DDoS | Thailand / Israel |
| 4 | The Gentlemen | 75 | Ransomware / Data Leak | United States |
| 5 | Keymous Plus | 67 | DDoS / Data Leak | Global |
| 6 | Dark Storm Team | 59 | DDoS | Europe / Israel |
| 7 | DieNet | 55 | DDoS | Israel |
| 8 | Hider_Nex | 47 | Data Leak | Global |
| 9 | RuskiNet Group | 47 | DDoS | Israel |
| 10 | Mr. Hanz Xploit | 43 | Data Leak | Indonesia / India |
Top Threat Actor Profile, NoName057(16):
NoName057(16) is a pro-Russian hacktivist collective that has been conducting politically motivated DDoS campaigns against NATO-aligned and EU member states since 2022.
In this reporting period, the group recorded 284 attacks, the highest of any tracked actor, concentrating its operations on Austria (105 attacks), the United Kingdom (45), Ukraine (75), and France (12), consistent with its established pattern of targeting governments and institutions perceived as opposing Russian strategic interests. The group's Austrian campaign, which included strikes on Ukraine reconstruction liaison bodies and multiple regional government entities, demonstrates an increasingly granular and symbolically deliberate target selection methodology. NoName057(16) should be considered the most operationally active hacktivist threat actor in the European theatre for this reporting period.
Analyst Notes
- DDoS resurgence is the defining structural trend of this period. With 1,017 DDoS incidents recorded, accounting for 35% of all events, and concentrated execution by NoName057(16), ZxS3C, RuskiNet Group, and DieNet, coordinated volumetric disruption campaigns are operating at a scale that demands dedicated DDoS mitigation infrastructure, particularly for government and financial sector organisations in Europe and Southeast Asia.
- The 17.7% volumetric decline should not be interpreted as de-escalation. The reduction from 3,520 to 2,896 incidents may reflect operational pauses, retooling, or a shift toward lower-volume but higher-impact intrusion activity. Ransomware (678 incidents) and data exfiltration (1,193 incidents) remain at elevated levels, and the presence of Lazarus Group in the incidents sample targeting GITHUB suggests continued state-sponsored interest in supply-chain attack vectors.
- Financial Services faces a multi-vector threat environment. With 349 finance-sector incidents recorded, spanning multiple attack types, it remains a focus for many threat actors across the landscape.

Threat Intelligence Reports
Our custom cyber threat intelligence reporting delivers strategic, operational, and tactical insights tailored to your organisation's unique needs. We help organisations understand and address specific threat landscapes across industries and geographies through detailed, actionable reports, enabling informed decisions to safeguard operations at all levels.
Insights

US is Most Attacked Nation, Driven by Ransomware and Data Exfiltration
Stay ahead of the curve with Cyber Series, your essential update on the evolving threat landscape.

Quiet, Scalable and Persistent Attacks Target Everyday Systems
Stay ahead of the curve with this month’s Cyber Risk Newsletter, your essential briefing on the evolving threat landscape.

Major Global Incidents Target Governments, Financial Institutions, Critical Infrastructure and Users
Stay ahead of the curve with this month’s Cyber Risk Newsletter, your essential briefing on the evolving threat landscape.

State‑Aligned Threat Actors Target Critical Infrastructure and Individuals
Stay ahead of the curve with this month’s Cyber Risk Newsletter, your essential briefing on the evolving threat landscape.
