Exclusive insights into the latest Threat Intelligence. Keeping constant watch over the cyber and geopolitical landscapes so you don’t have to.
Monthly Threat Intelligence Report
Ransomware activity dips modestly, but AI enabled attacks and geopolitical instability continue to elevate risk
Q1 2026 key insights:
- Global ransomware activity declined slightly, down 3% quarter on quarter
- The Industrials sector remained the most targeted, accounting for 30% of attacks
- Qilin was the most prolific ransomware group, responsible for 16% of incidents
- North America continued to bear the brunt of activity, representing 52% of attacks, followed by Europe at 23%
Despite a modest decline in ransomware volume, activity remains resilient. Threat actors continue to adapt, with AI enabled techniques and geopolitical tensions sustaining risk levels.
Monthly webinar
Our team of Threat Intel experts keep a constant watch over the cyber and geopolitical landscape, so you don’t have to.
Introducing our monthly highlights webinar, giving you further insight and exclusive access to what's going on now. Join our Global Head of Threat Intelligence, Matt Hull, each month for:
- A deeper understanding of the latest report findings
- A look at emerging trends by region and sector
- Insight into new threat actors
- Spotlight on the most impactful active cyber threats
Our next webinar will take place on May 26th 2026, 4pm BST.
Matt Hull
VP, Cyber Intelligence and Response
Subscribe to our monthly reports and webinars for the latest on recent and emerging advances in the threat landscape and a deep understanding of the latest Tactics, Techniques and Procedures (TTPs) of threat actors.
Cyber Threat Intelligence report archive
On demand videos
Missed a webinar? Find every past recording in our showcase:
View now
Never miss any intelligence.
Hit the button below to get our monthly reports and highlight webinars straight to your inbox.