Visualização de leitura

1-15 August 2026 Cyber Attacks Timeline

Cyber crime dominated the first half of August 2026, driving 108 confirmed incidents in just fifteen days. Malware remained the attacker's weapon of choice, a third of breaches traced back to an exploited public-facing application, and Public Administration emerged as the hardest-hit sector.

July 2026 Cyber Attacks Statistics

July 2026 saw 188 confirmed cyber attacks across 69 countries, with financially motivated Cyber Crime driving three in four incidents. Malware remained attackers' weapon of choice, exposed public-facing applications were the most common way in, and Information & Communication infrastructure absorbed the heaviest share of targeting. Here's the full breakdown of who attacked, how, and where.

July 2026 Dark Web Threat Actor Trend Report

Note The July 2026 Dark Web Threat Actor Trend Report focuses on trends among threat actors—including hacktivists—active on the deep web and dark web. It is explicitly noted that the factual accuracy of some content could not be verified. Major Issues Handala claimed to have compromised the core infrastructure of an Internet service provider in […]

1-15 July 2026 Cyber Attacks Timeline Infographic

Cyber Crime dominated the first half of July 2026, driving 76.5% of all confirmed activity, with Malware the clear weapon of choice at 43.5% of attack techniques. Exploitation of public-facing applications (MITRE T1190) led initial access methods at 27.6%, while Information & Communication infrastructure bore the brunt of targeting, accounting for 32% of sector hits — well ahead of Public Administration and Financial Services.

1-15 July 2026 Cyber Attacks Timeline

85 confirmed cyber incidents shaped the first half of July 2026, with cyber crime accounting for more than three-quarters of all attacks. Malware — spanning RATs, infostealers, spyware, and backdoors — was the dominant weapon, involved in 37 of 85 incidents (43.5%). Information & Communication infrastructure emerged as the hardest-hit sector, targeted in nearly 1 in 3 sector mentions.

H1 2026 Cyber Attacks Statistics

In H1 I recorded 1,071 confirmed cyber incidents. Financially motivated Cyber Crime drove nearly 7 in 10 attacks, malware remained the top weapon (40.5% of attack-vector entries), and exploitation of public-facing applications was the leading initial access technique (23.7%). Cyber Espionage accounted for roughly 1 in 5 incidents, with the Information & Communication sector bearing the heaviest targeting (26.1% of classified events).

Spanish Police Arrest Man Linked to CARR, Z-Pentest, and NoName057(16)

Spain arrested a suspected CARR and Z-Pentest collaborator in an FBI-led probe for aiding pro-Russian hackers, coordinating attacks, and using crypto.

Spanish National Police arrested a man in Palencia last March on charges of membership in and collaboration with a terrorist organization, glorifying terrorism, and computer damage. The investigation, carried out jointly with the FBI, identified him as a collaborator of two pro-Russian hacktivist groups: CyberArmy of Russia Reborn (CARR) and Z-Pentest, both designated as terrorist organizations responsible for attacks against critical infrastructure in the United States and Europe.

“The investigation began last August when, thanks to information provided by the FBI, the National Police investigators were made aware of the alleged involvement of the detainee in actions aimed at providing logistical and support cover to a Ukrainian hacker, located in Ukraine, linked to the pro-Russian hacktivist group CyberArmy of Russia Reborn (CARR), in order to facilitate his escape to Russia, through Poland and Belarus.” reads the press release published by the Spanish Police.

The operational support the suspect allegedly provided — helping a foreign hacker evade capture by routing an escape through two countries — puts this well beyond keyboard activism.

“The suspect also used various encrypted messaging applications to maintain contact with other members of these terrorist groups, coordinating actions and providing support for their activities.” continues the report. “According to investigators, the detainee participated in actions attributed to the pro-Russian hacktivist group NoName057(16), whose operations were later claimed on specialized geopolitical websites, with the aim of disseminating pro-Russian and anti-Western narratives.”

Investigators also linked him to operations attributed to NoName057(16), another pro-Russian hacktivist group, whose attacks were subsequently claimed on geopolitical websites to spread pro-Russian and anti-Western messaging. The suspect was apparently keeping busy across multiple fronts simultaneously.

Police searched the suspect’s home in Palencia, seized computers and cryptocurrency storage devices, and froze a crypto wallet allegedly used to hold profits from selling stolen information.

The police pointed out that there was a financial dimension to the operation, with proceeds from the sale of stolen or compromised information flowing through crypto accounts.

The investigation was conducted by the General Information Commissariat of the National Police, the FBI, and the Provincial Information Brigade of Palencia, under the direction of the Central Court of Instance number One and the National Court’s Prosecutor’s Office. CARR and Z-Pentest have been active against water utilities, energy infrastructure, and industrial control systems across the US and Europe.

The arrest is one of the first in Spain connecting a domestic individual to the operational and logistical support layer that keeps these groups running, not just the keyboard operators, but the people helping them stay out of custody.

CyberArmy of Russia Reborn (CARR) is a pro-Russian hacktivist group known for targeting government agencies, critical infrastructure, and industrial systems across Europe and the United States, mainly through DDoS attacks and disruptive cyber operations.

Z-Pentest is another pro-Russian cyber group that supports similar campaigns, often coordinating attacks aligned with Moscow’s geopolitical interests. Both groups blend ideological messaging with offensive cyber activity and have been linked to attacks on energy, water, and public-sector organizations.

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, CARR)

2026 World Cup: Discussing The World’s Biggest Game’s Attack Surface

The 2026 World Cup presents major cyber risks from ransomware groups, state-aligned actors, and other groups targeting critical infrastructure. Learn more here.

The post 2026 World Cup: Discussing The World’s Biggest Game’s Attack Surface appeared first on Unit 42.

16-30 April 2026 Cyber Attacks Timeline

In the second timeline of April 2026 I collected 108 events, corresponding to an average of 7.2 events per day, a number that confirms a growing trend, driven by the increasing number of supply chain attacks, compared to the previous timeline, where I collected 94 events (6.27 events/day).

Q1 2026 Cyber Attack Statistics

I aggregated the statistics created from the cyber attacks timelines published in the first quarter of 2026. In this period, I collected a total of 528 events (5.87 events/day) dominated by Cyber Crime with 66%, followed by Cyber Espionage with 18%, Hacktivism with 3%, and finally Cyber Warfare with 2%.

1-15 April 2026 Cyber Attacks Timeline

The first timeline of April 2026 brings an evolution in terms of methodology: from now on I will map the initial access techniques with the MITRE ATT&CK model. I also decided to merge the categories of Finance and Fintech in the sectors chart. From an event perspective, the first half of April 2026 confirmed a sustained trend...
❌