Visualização normal

Antes de ontemStream principal
  • ✇ASEC BLOG
  • Ransom & Dark Web Issues Week 1, September 2026 ATCP
    ASEC Blog publishes Ransom & Dark Web Issues Week 1, September 2026           ZaWoo Data Extortion Attacks Against Multiple Organizations Worldwide Black X Ransomware Attack on a South Korean Automotive Parts Manufacturer Internal Data of a South Korean Asset Management and Investment Firm Offered for Sale
     

Ransom & Dark Web Issues Week 1, September 2026

Por:ATCP
2 de Setembro de 2026, 12:00
ASEC Blog publishes Ransom & Dark Web Issues Week 1, September 2026           ZaWoo Data Extortion Attacks Against Multiple Organizations Worldwide Black X Ransomware Attack on a South Korean Automotive Parts Manufacturer Internal Data of a South Korean Asset Management and Investment Firm Offered for Sale
  • ✇ASEC BLOG
  • Ransom & Dark Web Issues Week 4, August 2026 ATCP
    ASEC Blog publishes Ransom & Dark Web Issues Week 4, August2026           Saudi Arabian Digital Entertainment Streaming Service User Data Offered for Sale SAFEPAY Ransomware Attack on a South Korean Industrial Gas Manufacturer and Supplier NoName057(16) and BD Anonymous Claim DDoS Attacks Against Major Japanese Organizations and Companies [1] [2] [3] […]
     

Ransom & Dark Web Issues Week 4, August 2026

Por:ATCP
26 de Agosto de 2026, 12:00
ASEC Blog publishes Ransom & Dark Web Issues Week 4, August2026           Saudi Arabian Digital Entertainment Streaming Service User Data Offered for Sale SAFEPAY Ransomware Attack on a South Korean Industrial Gas Manufacturer and Supplier NoName057(16) and BD Anonymous Claim DDoS Attacks Against Major Japanese Organizations and Companies [1] [2] [3] […]
  • ✇ASEC BLOG
  • July 2026 Threat Trend Report on Ransomware ATCP
    Purpose and Scope The July 2026 Threat Trend Report on Ransomware summarizes major Korean & global ransomware issues based on statistics regarding the quantity of new ransomware samples, the number of compromised systems, and statistics on targeted businesses. Statistics on targeted businesses were compiled based on information published on DLS (Dedicated Leak Sites, also referred […]
     

July 2026 Threat Trend Report on Ransomware

Por:ATCP
23 de Agosto de 2026, 12:00
Purpose and Scope The July 2026 Threat Trend Report on Ransomware summarizes major Korean & global ransomware issues based on statistics regarding the quantity of new ransomware samples, the number of compromised systems, and statistics on targeted businesses. Statistics on targeted businesses were compiled based on information published on DLS (Dedicated Leak Sites, also referred […]
  • ✇ASEC BLOG
  • Security Issues in the Korean & Global Financial Sector in July 2026 ATCP
    Statistics on Malware Distributed to the Financial Sector In Attack Stage 1, phishing (a technique that tricks users into opening malicious links or attachments) had the highest rate at 1.7, Down from 2.3 The previous month. In Attack Stage 2, Dropper/Downloader (a type that downloads additional malware) was the most prevalent at 1.7, Up from […]
     

Security Issues in the Korean & Global Financial Sector in July 2026

Por:ATCP
9 de Agosto de 2026, 12:00
Statistics on Malware Distributed to the Financial Sector In Attack Stage 1, phishing (a technique that tricks users into opening malicious links or attachments) had the highest rate at 1.7, Down from 2.3 The previous month. In Attack Stage 2, Dropper/Downloader (a type that downloads additional malware) was the most prevalent at 1.7, Up from […]
  • ✇ASEC BLOG
  • Ransom & Dark Web Issues Week 3, August 2026 ATCP
    ASEC Blog publishes Ransom & Dark Web Issues Week 3, August 2026         Customer and Operational Data of a South Korean Delivery Platform Offered for Sale Unauthorized Access Incident at a Japanese Cloud and Data Center Services Company ShinyHunters Threatens Data Disclosure Against a U.S. Live-Streaming Platform
     

Ransom & Dark Web Issues Week 3, August 2026

Por:ATCP
19 de Agosto de 2026, 12:00
ASEC Blog publishes Ransom & Dark Web Issues Week 3, August 2026         Customer and Operational Data of a South Korean Delivery Platform Offered for Sale Unauthorized Access Incident at a Japanese Cloud and Data Center Services Company ShinyHunters Threatens Data Disclosure Against a U.S. Live-Streaming Platform
  • ✇ASEC BLOG
  • Ransom & Dark Web Issues Week 2, August 2026 ATCP
    ASEC Blog publishes Ransom & Dark Web Issues Week 2, August 2026.           DragonForce Ransomware Attack on a South Korean Online Education Company Qilin Ransomware Attack on a South Korean Motor and Robotics Manufacturer ShinyHunters Claims Data Leak from a U.S. Digital Healthcare Company
     

Ransom & Dark Web Issues Week 2, August 2026

Por:ATCP
12 de Agosto de 2026, 12:00
ASEC Blog publishes Ransom & Dark Web Issues Week 2, August 2026.           DragonForce Ransomware Attack on a South Korean Online Education Company Qilin Ransomware Attack on a South Korean Motor and Robotics Manufacturer ShinyHunters Claims Data Leak from a U.S. Digital Healthcare Company
  • ✇ASEC BLOG
  • July 2026 Dark Web Breach Incident Trend Report ATCP
    Note The July 2026 Dark Web Breach Incident Trend Report was compiled based on data breach cases posted on deep web and dark web forums. Due to the nature of some posts, it is difficult to fully verify their accuracy; some posts related to South Korea included AI-generated false data or cases where it could […]
     
  • ✇ASEC BLOG
  • July 2026 Dark Web Threat Actor Trend Report ATCP
    Note The July 2026 Dark Web Threat Actor Trend Report focuses on trends among threat actors—including hacktivists—active on the deep web and dark web. It is explicitly noted that the factual accuracy of some content could not be verified. Major Issues Handala claimed to have compromised the core infrastructure of an Internet service provider in […]
     

July 2026 Dark Web Threat Actor Trend Report

Por:ATCP
10 de Agosto de 2026, 12:00
Note The July 2026 Dark Web Threat Actor Trend Report focuses on trends among threat actors—including hacktivists—active on the deep web and dark web. It is explicitly noted that the factual accuracy of some content could not be verified. Major Issues Handala claimed to have compromised the core infrastructure of an Internet service provider in […]
  • ✇ASEC BLOG
  • July 2026 Dark Web Issue Trend Report ATCP
    Note The July 2026 Dark Web Issue Trend Report summarizes major issues that occurred on the deep web and dark web. Due to the nature of some sources, it may be difficult to fully verify the accuracy of certain information; therefore, it is necessary to cross-check these details against official announcements. Major Issues RaidForums changed […]
     

July 2026 Dark Web Issue Trend Report

Por:ATCP
10 de Agosto de 2026, 12:00
Note The July 2026 Dark Web Issue Trend Report summarizes major issues that occurred on the deep web and dark web. Due to the nature of some sources, it may be difficult to fully verify the accuracy of certain information; therefore, it is necessary to cross-check these details against official announcements. Major Issues RaidForums changed […]
  • ✇ASEC BLOG
  • Ransom & Dark Web Issues Week 1, August 2026 ATCP
    ASEC Blog publishes Ransom & Dark Web Issues Week 1, August 2026           South Korean Automotive Parts Manufacturer’s Internal Server Access and Database Offered for Sale Data of a Turkish HR Consulting Company Offered for Sale Gunra Ransomware Attack on a South Korean Heavy Equipment Parts and Advanced Materials Manufacturer
     

Ransom & Dark Web Issues Week 1, August 2026

Por:ATCP
5 de Agosto de 2026, 12:00
ASEC Blog publishes Ransom & Dark Web Issues Week 1, August 2026           South Korean Automotive Parts Manufacturer’s Internal Server Access and Database Offered for Sale Data of a Turkish HR Consulting Company Offered for Sale Gunra Ransomware Attack on a South Korean Heavy Equipment Parts and Advanced Materials Manufacturer
  • ✇ASEC BLOG
  • Ransom & Dark Web Issues Week 5, July 2026 ATCP
    ASEC Blog publishes Ransom & Dark Web Issues Week 5, July 2026           Termite Ransomware Attack on a U.S. Nonprofit Healthcare Provider ShinyHunters Claims Data Leak Involving a Global Accounting and Consulting Firm The Gentlemen Ransomware Attack on a South Korean IT Software Distributor and Infrastructure Service Provider
     

Ransom & Dark Web Issues Week 5, July 2026

Por:ATCP
29 de Julho de 2026, 12:00
ASEC Blog publishes Ransom & Dark Web Issues Week 5, July 2026           Termite Ransomware Attack on a U.S. Nonprofit Healthcare Provider ShinyHunters Claims Data Leak Involving a Global Accounting and Consulting Firm The Gentlemen Ransomware Attack on a South Korean IT Software Distributor and Infrastructure Service Provider
  • ✇ASEC BLOG
  • June 2026 Ransomware Trend Report ATCP
    Purpose and Scope This report summarizes the quantity of ransomware samples collected, the number of affected systems, statistics on targeted businesses, and major Korean & global issues during the month of June 2026. Statistics on targeted businesses were compiled based on information posted on DLS (Dedicated Leak Sites) operated by ransomware groups, which publish details […]
     

June 2026 Ransomware Trend Report

Por:ATCP
15 de Julho de 2026, 12:00
Purpose and Scope This report summarizes the quantity of ransomware samples collected, the number of affected systems, statistics on targeted businesses, and major Korean & global issues during the month of June 2026. Statistics on targeted businesses were compiled based on information posted on DLS (Dedicated Leak Sites) operated by ransomware groups, which publish details […]
  • ✇ASEC BLOG
  • Ransom & Dark Web Issues Week 4, July 2026 ATCP
    ASEC Blog publishes Ransom & Dark Web Issues Week 4, July 2026           Source Code Collection of a South Korean Autonomous Robot Manufacturer Shared on a Cybercrime Forum Qilin Ransomware Attack on a Spanish Public Wastewater Management Organization RansomHouse Ransomware Attack on a Japanese Frozen Food and Logistics Company
     

Ransom & Dark Web Issues Week 4, July 2026

Por:ATCP
22 de Julho de 2026, 12:00
ASEC Blog publishes Ransom & Dark Web Issues Week 4, July 2026           Source Code Collection of a South Korean Autonomous Robot Manufacturer Shared on a Cybercrime Forum Qilin Ransomware Attack on a Spanish Public Wastewater Management Organization RansomHouse Ransomware Attack on a Japanese Frozen Food and Logistics Company
  • ✇ASEC BLOG
  • June 2026 Security Issues in Korean & Global Financial Sector ATCP
    Statistics on Malware Distributed to the Financial Sector In the June threat analysis for the financial sector, phishing was the most prevalent attack method in Attack Stage 1, while droppers/downloaders (distribution tools that download additional malware) were the most prevalent in Attack Stage 2. Infostealers were identified in the third attack stage, indicating that multi-stage […]
     

June 2026 Security Issues in Korean & Global Financial Sector

Por:ATCP
15 de Julho de 2026, 12:00
Statistics on Malware Distributed to the Financial Sector In the June threat analysis for the financial sector, phishing was the most prevalent attack method in Attack Stage 1, while droppers/downloaders (distribution tools that download additional malware) were the most prevalent in Attack Stage 2. Infostealers were identified in the third attack stage, indicating that multi-stage […]
  • ✇ASEC BLOG
  • Ransom & Dark Web Issues Week 3, July 2026 ATCP
    ASEC Blog publishes Ransom & Dark Web Issues Week 3, July 2026           DragonForce Ransomware Attack on a Saudi Arabian Chemical Manufacturer AiLock Ransomware Attack on Japan’s Largest Taxi and Limousine Operator Cyberattack on Japan’s Largest Frozen Food Company Disrupts the Wider Food Supply Chain
     

Ransom & Dark Web Issues Week 3, July 2026

Por:ATCP
15 de Julho de 2026, 12:00
ASEC Blog publishes Ransom & Dark Web Issues Week 3, July 2026           DragonForce Ransomware Attack on a Saudi Arabian Chemical Manufacturer AiLock Ransomware Attack on Japan’s Largest Taxi and Limousine Operator Cyberattack on Japan’s Largest Frozen Food Company Disrupts the Wider Food Supply Chain
  • ✇ASEC BLOG
  • June 2026 Dark Web Breach Incident Trend Report ATCP
    Note The June 2026 Dark Web Breach Incident Trend Report is based on major data breach cases posted on the deep web and dark web forums. Due to the nature of some sources, it was difficult to fully verify the accuracy of certain information, so the report includes content that requires further verification. Major Issue […]
     

June 2026 Dark Web Breach Incident Trend Report

Por:ATCP
8 de Julho de 2026, 12:00
Note The June 2026 Dark Web Breach Incident Trend Report is based on major data breach cases posted on the deep web and dark web forums. Due to the nature of some sources, it was difficult to fully verify the accuracy of certain information, so the report includes content that requires further verification. Major Issue […]
  • ✇ASEC BLOG
  • June 2026 Dark Web Issue Trend Report ATCP
    Note The June 2026 Dark Web Issue Trend Report summarizes major issues that occurred on the deep web and dark web. Due to the nature of the sources, it is sometimes difficult to fully verify the accuracy of certain information, and this is noted accordingly. Major Issue On Hasan’s BreachForums, there was a series of […]
     

June 2026 Dark Web Issue Trend Report

Por:ATCP
8 de Julho de 2026, 12:00
Note The June 2026 Dark Web Issue Trend Report summarizes major issues that occurred on the deep web and dark web. Due to the nature of the sources, it is sometimes difficult to fully verify the accuracy of certain information, and this is noted accordingly. Major Issue On Hasan’s BreachForums, there was a series of […]
  • ✇ASEC BLOG
  • June 2026 Dark Web Threat Actor Trend Report ATCP
    Note The June 2026 Dark Web Threat Actor Trend Report focuses on trends among threat actors—including hacktivists—operating on the deep web and dark web. It is noted that the accuracy of some information could not be verified. Major Issues In Malaysia, a series of website defacement and compromise incidents targeting local development agencies and public […]
     
  • ✇Blog – Cyble
  • Inside the Underground Economy: 5 Dark Web Trends Shaping the 2026 Threat Landscape Ashish Khaitan
    The dark web is no longer just a marketplace for stolen credentials; it has grown far beyond that point and now affects nearly every phase of the cyberattack lifecycle. Markets that once traded only compromised accounts now also sell ransomware services, initial network access, exploit kits, phishing infrastructure, and even AI-powered attack tools.   What used to be a place for selling stolen data has become the operational backbone of modern cybercrime.  The first half of 2026 alone is i
     

Inside the Underground Economy: 5 Dark Web Trends Shaping the 2026 Threat Landscape

8 de Julho de 2026, 06:47

dark web trends

The dark web is no longer just a marketplace for stolen credentials; it has grown far beyond that point and now affects nearly every phase of the cyberattack lifecycle. Markets that once traded only compromised accounts now also sell ransomware services, initial network access, exploit kits, phishing infrastructure, and even AI-powered attack tools.  

What used to be a place for selling stolen data has become the operational backbone of modern cybercrime. 

The first half of 2026 alone is indicative of the trends we may continue to observe. The dark web has evolved into a highly organized ecosystem that facilitates cybercrime, underpins ransomware supply chains, fuels geopolitical campaigns, and accelerates identity-based attacks.  

Instead of serving as the endpoint for stolen data, it now functions as an operational hub where access, intelligence, and malicious services are traded before attacks even begin.  

The pace of activity reflects this shift: March 2026 alone recorded 702 ransomware attacks and 54 major publicly reported data breaches and leaks worldwide. 

Enterprise security teams must monitor such activities using continuous threat intel and underground monitoring. The current ecosystem is no longer optional as an intel exercise but an essential capability for spotting threats before they materialize.  

The dark web trends observed during the first half of 2026 reveal how underground ecosystems are reshaping the cyber threat landscape

1. Ransomware Operations Continue to Mature

During the first six months of 2026, ransomware remained one of the most disruptive cyber threats, but the infrastructure supporting it became noticeably more organized. Five ransomware operations—Qilin, Akira, The Gentlemen, DragonForce, and INC Ransom—accounted for more than 56% of ransomware activity recorded in March 2026.  

This concentration highlights the growing consolidation of the ransomware ecosystem, where a handful of established operators dominate attacks while relying on affiliates and underground service providers to scale their campaigns. 

Modern ransomware campaigns rarely focus on encrypting systems. Data theft has increasingly become a standard component in most attack scenarios, as it allows threat actors to pressure their victims with the threat of public exposure, even if the victims have proper backups and can restore their systems. Dark web leak sites play a major role in this, as they are where stolen information is published or auctioned when organizations do not want to pay.  

This shift will require businesses to monitor underground forum trends in H1 2026, including discussions about leaked data, targeted organizations, and early chatter about upcoming campaigns. Regional data reinforces the same trend. In the Americas alone, 1,305 cyber incidents were reported during Q1 2026, including 1,138 publicly claimed ransomware attacks. Nearly 58% of those attacks were attributed to just five ransomware groups. 

2. Access Brokers Are Powering the Underground Economy 

Many cyberattacks are now starting long before ransomware is deployed. Initial access brokers have become major players, specializing in one activity: network compromise and then selling that access to other threat actors. 

Underground marketplaces also showed growing demand for initial access. In March 2026 alone, researchers observed 80 separate listings advertising access to compromised corporate networks. Government & LEA remained the most targeted industry, with 11 tracked incidents. Governments, Professional services, Manufacturing, and Retail continued to be persistently targeted. 
 
The bulk of this activity traced back to Big-Bro, an initial access broker (IAB) who has operated on Russian-language cybercrime forums since 2022. Two newer actors followed: Saturned33, who appeared in 2025, and Vexin, who surfaced in early 2026 (primarily active in March) and built a reputation selling unauthorized access to corporate cloud environments across multiple countries. 

Ransomware groups and espionage operators don’t need to spend time and effort breaching organizations themselves; they can buy verified entry points into corporate environments. This new division of labor has made cybercrime much faster and more effective. 

Access is typically sold soon after a compromise, so defenders have less time to detect exposed credentials or compromised infrastructure. As such, dark web intelligence is valuable not only for identifying stolen data but also for indicating that access to an organization's network is already being traded on underground markets. 

To see how Cyble’s threat intelligence can help your organization detect external exposure and track threat activity, book a personalized demo

3. Identity Has Become the Primary Attack Surface 

With the rise of credential-based attacks over malware, the security perimeter is pretty much irrelevant. The most common enterprise infiltration paths include credential theft, session hijacking, bypassing multi-factor authentication, and abuse of third-party access. All those have one thing in common: valid credentials. 

From an attacker's perspective, logging in with legitimate credentials generates far less suspicion than exploiting software vulnerabilities. As organizations expand cloud adoption and remote work, identities have become a new perimeter. 

Compromised endpoints have always been a key initial access vector for a variety of illicit activities, ranging from data breaches to initial access brokerage (IAB) operations. Compromised Endpoint monitoring is essential to securing an organization’s digital surface in the current threat landscape.  

Over the last 6 months, Vision observed 9.7 billion compromised endpoints. This trend also explains why stolen usernames, passwords, authentication tokens, and corporate accounts continue to be traded on the dark web. Monitoring for exposed credentials allows organizations to respond before compromised identities are weaponized. 

Your executives are a prime target. → Discover how Cyble Executive Monitoring detects executive impersonation and deepfakes before they escalate.

4. Geopolitical Events Are Driving Cyber Activity 

The connection between global conflicts and dark web activity has become increasingly apparent during the first half of 2026. State-sponsored groups, hacktivists, and financially motivated criminals frequently operate in parallel during periods of geopolitical tension, creating a more complex threat environment. 

Rather than focusing exclusively on immediate disruption, many sophisticated actors are investing in long-term access to critical infrastructure, telecommunications, transportation, and energy systems. During the February 2026 escalation in the Middle East, cyber operations demonstrated how geopolitical events now extend into the digital domain.  

Internet connectivity in affected regions reportedly dropped to between 1% and 4% of normal levels; more than 70 hacktivist groups became active; over 8,000 conflict-themed domains were registered for scams and malware campaigns; and disruptions to navigation systems affected more than 1,100 vessels near the Strait of Hormuz. 

This convergence of political objectives and cybercrime makes attribution more difficult and raises the importance of monitoring underground discussions that may signal emerging campaigns before they reach production environments. 

When physical events become cyber risks, can you connect the dots? → Explore Cyble's Physical Security Intelligence

5. AI Is Accelerating Both Attackers and Defenders 

Artificial intelligence has moved from experimentation to operational use across the cybersecurity landscape. Threat actors are increasingly using AI-assisted techniques to automate reconnaissance, accelerate the exploitation of vulnerabilities, and scale phishing campaigns with greater precision. 

The dark web has become a marketplace for sharing AI-enabled attack tools alongside traditional malware, making advanced capabilities accessible to less experienced operators. This lowers the barrier to entry while increasing the overall speed of cyber operations. 

Dark web threat intelligence in 2026 is becoming increasingly AI-driven, with defenders using automated analysis to process large volumes of dark web data, identify indicators of compromise, and prioritize threats in near real time. As attacks unfold more rapidly, automation is becoming necessary to reduce detection and response times. 

The question is no longer whether your organization appears on the dark web. The real question is whether you'll discover it before your attackers do. 

Get Cyble’s Global Threat Landscape Report – H1 2026 for critical insights into the new cyber ecosystem and the actions security leaders should prioritize next.

Conclusion 

The first half of 2026 stresses that the dark web is no longer where stolen information appears after an incident. It has evolved into a live intelligence environment where attacks are planned, infrastructure is traded, identities are monetized, and emerging tactics become visible before they reach production networks. 

Organizations that incorporate dark web intelligence into broader security operations gain more than visibility into compromised data; they gain early warning of evolving threats.  

As ransomware groups become more coordinated, identity attacks continue to rise, and AI reshapes offensive capabilities. Proactive monitoring will play an important role in reducing cyber risk during the remainder of 2026. 

References: 

The post Inside the Underground Economy: 5 Dark Web Trends Shaping the 2026 Threat Landscape appeared first on Cyble.

  • ✇ASEC BLOG
  • Ransom & Dark Web Issues Week 2, July 2026 ATCP
    ASEC Blog publishes Ransom & Dark Web Issues Week 2, July 2026           Saudi Arabian Medical Records Breach, For Sale on Cybercrime Forum Irish ICT Company Data Leaked, For Sale on Cybercrime Forum LeakNet Breach Targets US Healthcare Insurer, Shared on Cybercrime Forums
     

Ransom & Dark Web Issues Week 2, July 2026

Por:ATCP
8 de Julho de 2026, 12:00
ASEC Blog publishes Ransom & Dark Web Issues Week 2, July 2026           Saudi Arabian Medical Records Breach, For Sale on Cybercrime Forum Irish ICT Company Data Leaked, For Sale on Cybercrime Forum LeakNet Breach Targets US Healthcare Insurer, Shared on Cybercrime Forums
❌
❌