HomeCyber BalkansRansomware Attacks Increase 3% in Q2 Amid Escalating Supply Chain Compromises, Warns...

Ransomware Attacks Increase 3% in Q2 Amid Escalating Supply Chain Compromises, Warns NCC Group

Published on

spot_img

Global Ransomware Attacks See Incremental Rise as Supply Chain Threats Escalate

According to the latest findings from NCC Group’s Quarterly Cyber Threat Intelligence Report, ransomware incidents globally surged by 3% in the second quarter of 2026, rising from 2,165 reported attacks in the first quarter to 2,229 in Q2. While this increase might seem modest, the security firm has expressed concerns over a significant uptick in the scale and sophistication of supply chain attacks, highlighting a troubling trajectory in ransomware activity.

In June alone, the report cataloged a staggering 665 ransomware attacks, with the industrial sector emerging as the prime target, accounting for 30% of all attacks over the quarter and 28% in June. Following this sector, Consumer Discretionary and Information Technology also emerged prominently among the top three targeted sectors for that period.

Geographically, North America was the most affected region, absorbing a striking 44% of all ransomware attacks in Q2, including 41% during June. Europe followed as the second most targeted region, contributing 26% of the attacks for the quarter and 23% in June, with Asia coming in third.

Dominating the ransomware landscape for the fifth consecutive quarter, the Qilin group was implicated in 14% of all Q2 attacks, accounting for 301 victims. Following closely were The Gentlemen and DragonForce, with 238 and 145 victims, respectively. The report also highlighted the emergence of KryBit, a nascent Ransomware-as-a-Service operation that achieved notoriety by claiming 56 victims in its first full quarter of activity.

VPN Exploitation: A Key Entry Point

The report’s focal section pinpointed corporate virtual private networks (VPNs) and internet-facing edge devices as major entry points exploited within the ransomware ecosystem in 2026. Notable groups, including Akira, Qilin, and The Gentlemen, have been recorded targeting various vulnerabilities in products from prominent vendors such as Fortinet, SonicWall, Citrix, and Check Point. These tactics enable the attackers to bypass authentication processes and secure unauthorized access to victim networks.

NCC Group observed that vulnerabilities affecting VPN products constituted approximately 15% of the over 150 Threat Intelligence Alerts it has disseminated thus far this year, with many alerts classified as high or critical severity. Highlighting the potential for future exploitation, the report pointed to "FortiBleed," a notable credential exposure incident unveiled in June that impacted roughly half of all publicly exposed FortiGate devices.

Under Siege: Software Supply Chains

Alongside the findings on ransomware, NCC Group’s analysts reported a marked escalation in attacks targeting the software development ecosystem during Q2. Campaigns affecting platforms like GitHub Actions, npm, PyPI, Docker Hub, Open VSX, and the Visual Studio Code Marketplace surged. The financially motivated group TeamPCP was identified as one of the most active participants, linked to the self-propagating "Mini Shai-Hulud" worm which has spawned derivative campaigns known as Miasma and Hades after its source code was released on GitHub in May.

The report warns that these malicious campaigns exploit “transitive trust” within software supply chains, transforming maintainer accounts, Continuous Integration/Continuous Deployment (CI/CD) tokens, and cloud credentials into high-value targets. The ramifications of these compromises can ripple far beyond the organizations directly impacted, leading to cascading failures across interconnected systems.

Cybersecurity: A Board-Level Matter

Matt Hull, who serves as the Vice President and Head of Cyber Intelligence and Response at NCC Group, articulated the growing risks associated with supply chain attacks, stating that they present one of the most enticing avenues for threat actors to cause substantial operational, financial, and reputational damage. He underscored the necessity for businesses to embrace continuous, rather than ad hoc, monitoring and resilience programs.

Hull acknowledged that while there hasn’t been a significant uptick in ransomware volume this past quarter, the overall trend in attacks remains upward. He emphasized the need for organizations to regard cybersecurity as “the board-level issue it is,” particularly in light of geopolitical tensions and the rapidly evolving capabilities of artificial intelligence, both of which intensify the challenges faced by defense teams.

Additionally, the report scrutinized the increasing professionalization of ransomware operations, especially highlighting The Gentlemen, a Ransomware-as-a-Service group whose leaked internal database divulged structured negotiation strategies and a dedicated array of tools for disabling Endpoint Detection and Response (EDR) systems distributed to affiliates.

Furthermore, another alarming trend noted in the report is the rising convergence of commodity infostealer malware with advanced intrusion techniques. New malware variants are adopting rootkit-style concealment methods, employing browser-extension-based credential theft, and utilizing off-host decryption to enhance their evasion strategies against detection mechanisms.

NCC Group’s report also touches upon broader geopolitical dynamics, including the intensifying tensions between China and Taiwan, changes in Belarus’s diplomatic direction toward Russia, and Ireland’s upcoming presidency in the EU Council. These developments are forecasted to influence targeting patterns for state-linked threat actors in the latter half of the year.

In conclusion, the data presented by NCC Group paints a concerning picture of the current cybersecurity landscape, calling upon organizations to reinforce their defenses and adopt more proactive measures in the face of evolving threats. As the specter of ransomware looms larger, the imperative for comprehensive cybersecurity strategies has never been clearer.

Source link

Latest articles

Ubuntu Snap-Confine Vulnerability Allows Local Root Access

Major Vulnerability Discovered in Ubuntu's Application Isolation A recently uncovered security vulnerability within the Ubuntu...

Proofpoint Research Reveals 65% of Organizations Impacted by Ransomware Believe AI Enhanced Attack Effectiveness

Global Study Reveals AI’s Role in Amplifying Phishing, Impersonation, and Credential Theft, Transforming Ransomware...

ApolloMD Reaches $4 Million Settlement in Hack Lawsuit

Settlement With Revenue Cycle Vendor Stems From Qilin Gang Attack Affecting 627,000 Patients In a...

HHS Requests Feedback on CLIA Cybersecurity Updates

CMS and CDC Seek Public Input on Modernizing CLIA Regulations In a significant move towards...

More like this

Ubuntu Snap-Confine Vulnerability Allows Local Root Access

Major Vulnerability Discovered in Ubuntu's Application Isolation A recently uncovered security vulnerability within the Ubuntu...

Proofpoint Research Reveals 65% of Organizations Impacted by Ransomware Believe AI Enhanced Attack Effectiveness

Global Study Reveals AI’s Role in Amplifying Phishing, Impersonation, and Credential Theft, Transforming Ransomware...

ApolloMD Reaches $4 Million Settlement in Hack Lawsuit

Settlement With Revenue Cycle Vendor Stems From Qilin Gang Attack Affecting 627,000 Patients In a...