The Gentlemen ransomware, run by GOLD SHERWOOD, encrypts networks in under 24 hours. See the affiliate playbook and how to defend against it.
Related Posts:
PHP Web Server Rootkit Targets F5 BIG-IP Devices
StreamRat Banking Trojan Targets Spanish Android Users
Silver Fox Fake Software Installers Disable Windows Defender
The post The Gentlemen Ransomware Deploys in Under 24 Hours appeared first on Daily CyberSecurity.
An eight-month international operation targeting West African organized crime groups has resulted in 58 arrests and the identification of 263 suspects across 22 countries, according to INTERPOL. Operation Jackal IV, conducted from November 2025 to June 2026, focused on disrupting criminal networks, tracing illicit funds, identifying high-value targets and supporting arrests and prosecutions.
The operation brought together countries across six continents to tackle the growing global threat pos
An eight-month international operation targeting West African organized crime groups has resulted in 58 arrests and the identification of 263 suspects across 22 countries, according to INTERPOL. Operation Jackal IV, conducted from November 2025 to June 2026, focused on disrupting criminal networks, tracing illicit funds, identifying high-value targets and supporting arrests and prosecutions.
The operation brought together countries across six continents to tackle the growing global threat posed by West African criminal networks, including Black Axe and similar groups.
These networks have been linked to a significant share of global cyber-enabled financial fraud, including romance scams, cryptocurrency and investment scams, and business email compromise fraud.
Operation Jackal IV Targets West African Organized Crime Groups
Operation Jackal IV also targeted money laundering activities used to move and conceal criminal proceeds across borders.
INTERPOL coordinated cross-border intelligence sharing, analysis and operational support during the operation. It also provided specialized training to strengthen international investigations into financial crime.
Tomonobu Kaya, Director of the INTERPOL Financial Crime and Anti-Corruption Centre, said the operation showed the importance of international cooperation in following illicit financial flows and disrupting criminal networks.
[caption id="attachment_113806" align="aligncenter" width="600"] Image Source: INTERPOL[/caption]
Major Arrests and Financial Crime Investigations
In Argentina, authorities identified 196 individuals linked to a major Crime-as-a-Service network suspected of providing website domains and money laundering support to West African organized crime groups. The investigation resulted in 17 arrests, with an INTERPOL Operational Support Team assisting with analysis of seized data and identification of suspects and criminal networks.
South African authorities raided seven locations in Johannesburg linked to a syndicate involved in romance and investment scams targeting retirees in English-speaking countries. Investigators arrested 39 people, seized USD 2.67 million and blocked 257 bank accounts.
In Italy, investigators identified an individual connected to a pan-European money laundering network that used shell companies, remittance services and cash withdrawals. One account processed EUR 845,000, or about USD 736,000, through 560 transactions involving 20 financial instruments.
Romanian authorities dismantled a criminal group operating an investment scam through a call centre. The group promoted high returns from stocks and cryptocurrencies, with victims' money transferred to electronic wallets controlled by perpetrators.
Authorities estimated that EUR 143 million had been stolen and laundered globally. Eleven people were arrested, while cash, cryptocurrency, six real estate properties and luxury watches were seized.
Sextortion and Crime-as-a-Service Emerge
Beyond individual investigations, the operation highlighted emerging threats involving sextortion and Crime-as-a-Service. INTERPOL identified an increase in West African organized crime groups using sextortion to target minors, including victims as young as 14.
In these cases, offenders typically contacted minors through social media, established trust and persuaded them to share explicit images or videos. They then threatened to distribute the material to the victim's contacts unless a ransom was paid.
Investigators also found that some criminal syndicates were procuring Crime-as-a-Service from external providers, including through the dark web. These services were used to outsource activities such as money laundering and other operational functions.
While several cases from Operation Jackal IV remain under investigation, the preliminary results demonstrate the scale and international reach of the networks targeted during the eight-month operation.
The participating countries were Austria, Argentina, Australia, Canada, Côte d'Ivoire, France, Germany, Indonesia, Ireland, Italy, Japan, Malaysia, the Netherlands, Nigeria, Portugal, South Africa, Spain, Sweden, Switzerland, the United Arab Emirates, the United Kingdom and the United States.
When Cameron Curry discovered that his contract as a data analyst wasn't going to be renewed, he could have updated his LinkedIn profile. He could have started sending out his resume.
But what the 27-year-old from Charlotte, North Carolina, did instead was turn to extortion.
Read more in my article on the Hot for Security blog.
When Cameron Curry discovered that his contract as a data analyst wasn't going to be renewed, he could have updated his LinkedIn profile. He could have started sending out his resume.
But what the 27-year-old from Charlotte, North Carolina, did instead was turn to extortion.
Read more in my article on the Hot for Security blog.
CISA and five agencies warn that Gunra ransomware is hitting critical infrastructure with double extortion. A Linux flaw may let victims recover free.
Related Posts:
Apple Sends Mercenary Spyware Alerts to Users in 110+ Countries
ChainDrop npm Worm Hits 400+ Packages via Blockchain C2
Fake Zoom Installer Drops Overlord RAT on macOS
The post Gunra Ransomware Hits Critical Infrastructure, CISA Warns appeared first on Daily CyberSecurity.
UNC6671 vishing extortion group rebrands across five names, using AiTM credential phishing to hit financial services and enterprise cloud accounts.
Related Posts:
Lazarus Exploits Windows Zero-Day in Operation Dream Job Attacks
Greatness PhaaS Platform Steals Microsoft 365 Tokens Past MFA
SMOKE#SCREEN Campaign Abuses ScreenConnect RMM for Stealthy Remote Access
The post UNC6671 Vishing Extortion Rebrands Across 5 Brands appeared first on Daily CyberSecurity.
A Canadian man pleaded guilty to a cloud hacking extortion scheme that hit 165 companies and stole billions of records. DOJ confirms the plea.
Related Posts:
SMOKE#SCREEN Campaign Abuses ScreenConnect RMM for Stealthy Remote Access
Astaroth WhatsApp Spambot Turns Brazil Victims Into Unwitting Malware Distributors
DarkSword iOS Exploit Spreads Across 100+ Sites and Drops GHOSTBLADE
The post Canadian Man Pleads Guilty to Cloud Hacking Extortion Scheme That Hit 165 Companies appeared first on Da
LeakNet claims it stole 11TB of NYC Health + Hospitals data containing sensitive medical, financial and biometric records linked to more than 12 million people.
LeakNet claims it stole 11TB of NYC Health + Hospitals data containing sensitive medical, financial and biometric records linked to more than 12 million people.
EY confirmed the theft of client tax documents from its third-party support platform. ShinyHunters claims responsibility and is threatening to publish the data.
EY confirmed the theft of client tax documents from its third-party support platform. ShinyHunters claims responsibility and is threatening to publish the data.
Ransomware’s biggest story in the first half of 2026 was not only about established names maintaining dominance. A newer player, The Gentlemen ransomware group, emerged as one of the most geographically active operators, expanding its reach across Europe, Asia-Pacific, the Middle East & Africa, and the Americas.
According to research from Cyble Research and Intelligence Labs (CRIL), The Gentlemen became one of the top ransomware actors globally, demonstrating how quickly emerging ransomw
Ransomware’s biggest story in the first half of 2026 was not only about established names maintaining dominance. A newer player, The Gentlemen ransomware group, emerged as one of the most geographically active operators, expanding its reach across Europe, Asia-Pacific, the Middle East & Africa, and the Americas.According to research from Cyble Research and Intelligence Labs (CRIL), The Gentlemen became one of the top ransomware actors globally, demonstrating how quickly emerging ransomware-as-a-service (RaaS) groups can scale through affiliate-driven operations.Unlike older ransomware brands that rely on a narrow set of preferred targets, The Gentlemen displayed a broad targeting strategy. The group impacted organizations across Manufacturing, Construction, Healthcare, Government, and IT sectors — industries where operational disruption, sensitive information, and regulatory pressure create strong incentives for victims to respond quickly.
The Gentlemen Ransomware Group Becomes a Regional Threat
The group’s strongest activity was observed in Europe and the UK, where it was responsible for 144 ransomware attacks during H1 2026. The region’s Manufacturing, Construction, Healthcare, and Professional Services sectors were among the most affected, highlighting the group’s preference for organizations with valuable data and limited tolerance for downtime.In Asia-Pacific, The Gentlemen became the leading ransomware threat, accounting for 114 attacks — nearly one-quarter of the region’s ransomware activity. Manufacturing was among the primary targets, with additional campaigns affecting IT services, Professional Services, Healthcare, and government entities.The group also gained significant attention in the Middle East & Africa, where it accounted for 56 attacks, representing more than 26% of ransomware incidents in the region. Construction, BFSI, and Government organizations were frequent targets, demonstrating the group’s interest in sectors linked to critical services and economic activity.South America also saw notable activity, with The Gentlemen responsible for 46 attacks, making it one of the region’s leading ransomware operators.Also Read:One Country Absorbed Nearly Half of the World’s Ransomware Attacks in Just Six Months – The United States
Double Extortion Remains the Core Strategy
The rise of The Gentlemen reflects a broader ransomware trend: encryption alone is no longer the primary weapon. Like most modern ransomware operations, the group relies on double extortion — stealing sensitive information before encrypting systems and using the threat of public exposure as additional pressure.This approach allows ransomware groups to target organizations even when companies maintain effective backup and recovery capabilities. Stolen data can be leveraged for financial gain, reputational damage, regulatory pressure, or further attacks.
What Makes The Gentlemen a Growing Concern?
The group’s rapid expansion highlights the resilience of the RaaS ecosystem. Modern ransomware operations no longer depend solely on a single team’s technical capabilities. Instead, affiliates, access brokers, and specialized cybercrime services allow operators to expand quickly across industries and regions.The Gentlemen’s activity also reinforces a key security challenge: organizations cannot rely only on historical threat rankings. New ransomware groups can rapidly become major players by exploiting exposed systems, purchasing initial access, and adopting proven extortion tactics.For security teams, monitoring emerging ransomware operators and tracking changes in attacker behavior is becoming as important as defending against established groups.To explore the complete ransomware landscape, including regional attack trends, targeted industries, and the activity of leading ransomware groups, download the full Cyble H1 2026 Cyber Threat Landscape Report.
Former ransomware negotiator Angelo Martino gets 70 months in prison for helping BlackCat extort US victims and misuse confidential client data in cyberattacks.
Former ransomware negotiator Angelo Martino gets 70 months in prison for helping BlackCat extort US victims and misuse confidential client data in cyberattacks.
A U.S. government agency paid $1M to Kairos, a group focused on data theft and extortion rather than ransomware, Ransom-ISAC reports.
A new case study from Ransom-ISAC reconstructs a complete data-extortion incident involving a U.S. government body and a threat actor called Kairos, using a leaked negotiation transcript and blockchain tracing of the ransom payment. The victim paid roughly $1 million in Bitcoin on June 13, 2025. The uncomfortable detail: Kairos has never been confirmed to have
A U.S. government agency paid $1M to Kairos, a group focused on data theft and extortion rather than ransomware, Ransom-ISAC reports.
A new case study from Ransom-ISAC reconstructs a complete data-extortion incident involving a U.S. government body and a threat actor called Kairos, using a leaked negotiation transcript and blockchain tracing of the ransom payment. The victim paid roughly $1 million in Bitcoin on June 13, 2025. The uncomfortable detail: Kairos has never been confirmed to have deployed ransomware at all.
“On 19 May 2025, a U.S. government entity was reportedly targeted by Kairos. Kairos later claimed the access was obtained through a brute-force credential attack. The entity was listed on Kairos’s victim site on 21 May 2025.” reads the report published by Ransom-ISAC.
“Rather than deploying encryption, Kairos appears to have focused on data exfiltration and public-exposure pressure. The group claimed to hold more than 1.6 million files — 1,602,775 files in total — and 2 TB of data before making contact.”
No encryptor, no locker binary, no decryption key demand. What Kairos appears to have done is steal data, then charge the victim not to publish it. As the Ransom-ISAC report states:
“No ransomware sample, encryptor, or locker binary has been obtained or confidently linked to Kairos.” continues the reprot. “On the available evidence, the U.S. government body paid a seven-figure ransom to a threat actor whose “ransomware group” status remains unverified and whose leverage appears to have been based on data-theft and publication pressure rather than demonstrated ransomware capability.”
The victim called the incident ransomware. The word no longer means what most people think it means.
The report doesn’t name the victim, citing privacy concerns. The transcript does the naming itself. The requested sample files include documents called Union.xlsx, “1 union co psi template.doc,” and a final archive delivered post-payment called union.rar. The victim describes itself as “a small county with limited resources.”
The timeline fits: in May 2025, Union County, Ohio, disclosed it had detected a network intrusion and later notified 45,487 residents and employees that their data had been stolen, covering most of a county of roughly 70,000 people. The stolen records included Social Security numbers, financial details, fingerprints, and passport numbers. Neither the county nor Kairos has confirmed the connection.
I conducted personal research and I can confirm that Union Count stated cybercriminals accessed the County’s network between May 6 and 18, 2025 and stole some data. By August 25, officials had finished reviewing the breach and had begun notifying affected individuals. However, the Government entity at the time confirmed a ransomware attack, as reported in the data breach notification letter.
“On May 18, 2025, the County detected ransomware on our computer network. As soon as we learned this, we immediately launched an investigation with assistance from nationally recognized third-party cybersecurity and data forensics consultants to secure our network and investigate the scope of the incident. We also alerted federal law enforcement.” reads the data breach notification letter sent to the impacted individuals and shared with the Maine General Attorney. “Through our investigation, we determined that the cyber criminals accessed our network from May 6, 2025 through May 18, 2025, and took some County data.”
Kairos listed the victim on its leak site on May 21, 2025, two days after first contact. The group claimed to hold more than 2 terabytes of data, specifically 1,602,775 files. Kairos later claimed the access was obtained through a brute-force credential attack, a single-guessed password.
The transcript covers 28 days of back-and-forth. Kairos opened at $3 million. The victim countered at $100,000 on June 4, then raised to $255,000, then $430,000. Kairos dropped to $2 million, held there briefly, then issued a hard deadline: $1 million by Friday or the files go public. The victim paid. The final payment was 33 times the first offer and 2.3 times the highest recorded counter.
Kairos ran a disciplined negotiation. Responses came within minutes to a few hours throughout the 28-day window, suggesting an actively monitored channel. The pressure tactics were textbook: a countdown timer, escalating deadlines, selective reference to the most sensitive material. Kairos specifically highlighted a folder marked “prosecutors office,” warning that leaking it would help criminals avoid prosecution and cause a public outcry.
“Kairos maintained leverage by controlling deadlines, publication threats, and proof-of-access artefacts. The affected entity’s responses are consistent with an organization buying time while legal, leadership, financial, and communications decisions were coordinated.” continues the report. “Phrases such as “we appreciate your patience” and “we respect the effort you’ve made” should be read as channel-preservation language, not endorsement of the attacker’s conduct.”
Public-sector incident response requires coordinating legal, financial, leadership, and communications teams simultaneously, and the transcript shows exactly that process playing out in slow motion under deadline pressure.
After payment, Kairos sent over a “proof of deletion” file: a 238 MB text file listing filenames. That list proves the attacker once had the files. It proves nothing about whether they were destroyed. There was no hash verification, no cryptographic binding, no exit-code logging. The same list could be generated by running a script against a copy of the stolen data sitting on a different server. As Ransom-ISAC’s report puts it directly:
“The provided “proof of deletion” was not technically verifiable and should not be treated as evidence that the stolen data was destroyed.” continues the report.
Paying to make stolen data disappear is an act of faith, and the receipt is written by the thief.
Krishnan traced the approximately 9.44 BTC from the Kairos payment wallet through its subsequent movement. Within hours of receipt, the funds split into two branches: 6.61 BTC went to a wallet Ransom-ISAC calls the “Main Guy,” and 2.83 BTC went to a “Helper” wallet. The Main Guy branch moved 6.50 BTC toward a ByBit deposit address three days later. The Helper branch fragmented through a series of intermediate wallets before touching addresses associated with OKX and a Russian exchange called BELQI.
The entire active transfer window ran from June 16 at 15:52 UTC to 19:26 UTC, three hours and 34 minutes. The speed and structure of the movement, rapid splitting into branches, repeated use of the same OKX deposit addresses, routing toward a Russian exchange, reflect deliberate operational tradecraft. The report identifies four high-confidence wallet addresses associated with the payment flow and linked to ByBit, OKX, and BELQI. These are investigative leads, not attribution. Exchange records and subpoenas are what convert blockchain tracing into named individuals.
Kairos first appeared in November 2024 and has listed 88 victims on its leak site. The group operated through a Tor onion address and an email contact at kairossup@onionmail.com, a naming convention that echoes LockBit’s “LockBitSupp” handle, though Ransom-ISAC notes that’s a branding similarity only.
In January 2026, infrastructure hunting identified a likely backend server for the Kairos leak site resolving to 62.182.81.38, hosted on Virtual Systems LLC in Ukraine, an ASN that has appeared in previous malware and Cobalt Strike-related infrastructure reporting. The server was later found displaying a seizure notice attributed to Ukraine’s Security Service Cyber Department. The leak site is now down. A wallet tied to the operation was still moving funds as recently as May 2026. A seized website and an active wallet are two different things.
The broader shift Kairos represents is real and documented. The operational disruption is limited. The legal, reputational, and public-trust pressure is severe, particularly for a county government holding law enforcement records.
“This case illustrates how data-only extortion can create significant pressure even without encryption or operational disruption. Kairos used file-access claims, publication threats, staged concessions, and deadline pressure to secure a successful seven-figure ransom payment from a U.S. government body.” concludes the report. “The blockchain activity provides useful investigative leads, including rapid fund splitting and exchange touchpoints, but it should not be treated as standalone attribution. The strongest finding is operational: public-sector organizations need pre-authorized escalation paths, negotiation support, egress monitoring, and a clear understanding that attacker deletion claims are not independently verifiable.”
Hackers claim they stole 1.3TB of Novo Nordisk data, including clinical trial and AI model information, after issuing a $25 million demand.
The post Ozempic Maker Novo Nordisk Confirms Security Incident After $25M Hacker Demand appeared first on TechRepublic.
ShinyHunters claims it stole 297GB of data from the Council of Europe, including payroll and medical records, but the organization has not confirmed a breach.
The post ShinyHunters Claims Council of Europe HR Data, Threatens Leak appeared first on TechRepublic.
ShinyHunters claims it stole 297GB of data from the Council of Europe, including payroll and medical records, but the organization has not confirmed a breach.
Cybersecurity firm Resecurity reports Silent Ransom Group is using a fast flux botnet to hide data leak sites while targeting law firms with theft and vishing.
Cybersecurity firm Resecurity reports Silent Ransom Group is using a fast flux botnet to hide data leak sites while targeting law firms with theft and vishing.
Cybersecurity researchers are warning businesses about Pink Extortion Group, a threat actor that uses voice phishing to bypass multi-factor authentication and steal files from cloud environments.
Cybersecurity researchers are warning businesses about Pink Extortion Group, a threat actor that uses voice phishing to bypass multi-factor authentication and steal files from cloud environments.
Ransomware attacks surged 30% in the first half of 2026 compared to the same period in 2025, with Qilin and INC Ransom emerging as two of the most prolific and dangerous operators in a crowded criminal ecosystem. Healthcare continues to be the top targeted industry, with 27 incidents in January 2026 alone, a figure that reflects both the sector's operational sensitivity and the premium value of health records on darknet markets.
Qilin: The Dominant Force
Qilin — also known as Agenda — is a ran
Ransomware attacks surged 30% in the first half of 2026 compared to the same period in 2025, with Qilin and INC Ransom emerging as two of the most prolific and dangerous operators in a crowded criminal ecosystem. Healthcare continues to be the top targeted industry, with 27 incidents in January 2026 alone, a figure that reflects both the sector's operational sensitivity and the premium value of health records on darknet markets.
Qilin: The Dominant Force
Qilin — also known as Agenda — is a ransomware group that entered 2026 accelerating, not slowing down. By early 2026, Qilin had already posted 55 confirmed victims, placing it ahead of its own 2025 pace. By June 2026, tracking data, Qilin had accumulated 168 confirmed victims in the healthcare sector alone, behind only manufacturing (291) and business services (245) in overall victim count.
Qilin operates as a Ransomware-as-a-Service (RaaS) platform, recruiting affiliates who conduct attacks using Qilin's ransomware builder and infrastructure in exchange for a percentage of ransom proceeds. This model allows the core group to expand operational throughput without directly executing every attack.
The group's double extortion model — encrypting victim data while simultaneously exfiltrating it and threatening public release on their leak site — has proven effective at pressuring victims into paying ransom demands even when robust backups exist. Public exposure of sensitive patient records creates regulatory, legal, and reputational pressure that many healthcare organisations find more immediately damaging than operational downtime.
A notable recent case involves Covenant Health, which suffered a Qilin ransomware breach that exposed 478,188 patient records. The Covenant Health incident highlights Qilin's willingness to attack hospitals and health systems regardless of the direct patient safety implications.
INC Ransom: Targeting Critical Sectors
INC Ransom is another highly active operator that was among the top ransomware groups by victim count in January 2026, with 47 known attacks that month. The group targets organisations across multiple sectors, including healthcare, legal services, and public administration.
INC Ransom gained significant attention in 2025 for its attack on NHS Scotland, which exposed 3 terabytes of patient data. The group continues to operate aggressively in 2026, targeting entities including healthcare practices, municipal agencies, and regional service providers.
Recent INC Ransom victims include healthcare organisations such as Lymphedema Therapy Specialists, Inc. (February 2026, affecting 378 Texas patients) and various municipal and public sector entities, including Champaign-Urbana Public Health District.
AI-assisted operations: Multiple ransomware groups are now using AI tools to accelerate phishing campaign creation, target research, and initial access operations, reducing the operational cost of launching attacks.
Healthcare as a premium target: Patient records sell for up to 10 times as much as financial records on darknet markets, making it a persistently attractive target. Operational disruption of healthcare services also creates patient-safety leverage that can pressure organisations to make faster payment decisions.
The Play and SafePay operators were also confirmed in recent June 2026 attack disclosures, targeting organisations including Clínica Maitenes and various regional businesses.
Why It Matters
The 30% year-over-year increase in ransomware incidents confirms that neither law enforcement action nor improved defensive capabilities has materially reduced the operational tempo of ransomware criminal enterprises. The professionalisation of RaaS platforms, combined with AI-assisted tooling and shortened attack timelines, is creating conditions in which even well-defended organisations face materially elevated risk.
For healthcare specifically, the combination of operational sensitivity, high data value, and historically underfunded security programmes creates a structural vulnerability that the industry has not yet resolved despite years of high-profile attacks.
The IOCTA 2026 report released by Europol offers a detailed look at how cybercrime is evolving across Europe, with criminals increasingly using artificial intelligence, encryption, and cryptocurrencies to scale their operations. The latest edition of the Internet Organised Crime Threat Assessment outlines key trends shaping the threat landscape and calls for stronger coordination among law enforcement agencies.
According to the IOCTA 2026 report, cybercrime is becoming more complex and interc
The IOCTA 2026 report released by Europol offers a detailed look at how cybercrime is evolving across Europe, with criminals increasingly using artificial intelligence, encryption, and cryptocurrencies to scale their operations. The latest edition of the Internet Organised Crime Threat Assessment outlines key trends shaping the threat landscape and calls for stronger coordination among law enforcement agencies.
According to the IOCTA 2026 report, cybercrime is becoming more complex and interconnected, driven by rapid technological advancements. The findings highlight how criminals are adapting quickly, making it harder for authorities to detect, track, and disrupt their activities.
The IOCTA 2026 report serves as a roadmap for understanding emerging cyber threats, covering areas such as online fraud, ransomware attacks, and child exploitation networks. Edvardas Šileris, Head of the European Cybercrime Centre at Europol, emphasized that the report is intended to help law enforcement agencies respond effectively to these evolving risks.
He noted that as cybercriminals continue to exploit new technologies, strengthening capabilities and improving collaboration will be essential to protect citizens and critical infrastructure.
Dark Web Fragmentation and Cryptocurrencies Fuel Crime
A key finding in the IOCTA 2026 report is the continued role of the dark web as a central hub for cybercriminal activity. Despite ongoing crackdowns, marketplaces and forums remain active, with criminals frequently shifting platforms to avoid detection.
The report highlights how fragmentation and specialization across these platforms make investigations more difficult. Encrypted messaging services and anonymized networks are increasingly connecting surface and dark web environments, reducing the visibility of criminal operations.
Cryptocurrencies also play a significant role, according to the IOCTA 2026 report. Privacy-focused coins and offshore exchanges are widely used to launder ransomware payments, making financial tracking more challenging. The report also points to a growing trend of younger individuals becoming involved in cryptocurrency-related activities, sometimes without understanding the legal risks.
AI-Driven Fraud Expands Across Europe
The IOCTA 2026 report identifies artificial intelligence as a major driver of online fraud. Cybercriminals are using generative AI tools to create highly targeted phishing campaigns and social engineering attacks.
These tools allow attackers to:
The report also highlights the use of caller ID spoofing and SIM farms, which enable attackers to send thousands of messages or calls simultaneously. This combination of AI and automation is increasing both the reach and success rate of fraud campaigns.
Ransomware and Data Extortion Remain Key Threats
Ransomware continues to be a dominant threat, as outlined in the IOCTA 2026 report. A large number of active ransomware groups were observed throughout 2025, with many adopting data extortion tactics.
Instead of relying solely on encryption, attackers are increasingly threatening to release stolen data to pressure victims into paying. This shift has made cyberattacks more damaging, particularly for public institutions and large organizations.
The report also notes growing links between state-sponsored actors and criminal groups, with some cybercriminals acting as proxies in broader geopolitical strategies. Emerging hacking coalitions are adding another layer of complexity to the threat landscape.
Rise in Online Child Exploitation and Criminal Networks
The IOCTA 2026 report highlights a concerning increase in online child sexual exploitation cases. The financial trade of child abuse material is growing, and the use of synthetic content is creating new challenges for investigators.
Encrypted messaging platforms are widely used by offenders, making it harder for authorities to monitor and intervene. The report also points to the emergence of organized online communities that engage in multiple forms of criminal activity.
These networks combine cybercrime with violent offenses, creating a complex and dangerous ecosystem that extends beyond digital spaces.
Need for Stronger Law Enforcement Collaboration
The findings of the IOCTA 2026 report reinforce the need for improved coordination between governments, law enforcement agencies, and industry stakeholders. As cyber threats become more advanced, isolated efforts are no longer sufficient.
The report provides actionable insights and recommendations aimed at strengthening investigative capabilities and improving response strategies. It also stresses the importance of innovation in tackling new forms of cybercrime.