Skip to navigation Skip to main content Skip to footer

Cyber Threat
Intelligence Reports

Exclusive insights into the latest Threat Intelligence. Keeping constant watch over the cyber and geopolitical landscapes so you don’t have to.

 

Monthly Threat Intelligence Report

Ransomware activity increased during Q2 2026, while VPN-focused intrusions, supply chain compromises, and geopolitical developments continued to shape the threat landscape.

June 2026 key insights:

  • 665 global ransomware attacks were recorded in June, contributing to a 3% increase in ransomware activity across Q2 2026 compared to Q1
  • Industrials remained the most targeted sector in June, accounting for 183 attacks (28%), while representing 30% of all attacks across Q2
  • North America remained the most targeted region in June, accounting for 275 attacks (41%), followed by Europe with 153 attacks (23%). This trend was also reflected across Q2, where North America accounted for 980 attacks (44%) and Europe for 579 attacks (26%)
  • Qilin remained the most active ransomware group in June, responsible for 79 attacks (12%), closely followed by The Gentlemen at 11%. Across Q2, Qilin accounted for 14% of all recorded attacks
  • Supply chain attacks continued to increase in scale and sophistication throughout the quarter, highlighting growing risks across trusted software development ecosystems

Ransomware activity remained consistently high throughout the second quarter, while broader threat activity continued to reflect a shift towards more scalable and collaborative attack models. From the targeting of VPN infrastructure and edge devices to the compromise of software supply chains, threat actors increasingly leveraged trusted systems and established processes to expand their reach. These trends underscore how attackers are improving both the speed and efficiency of their operations, enabling them to achieve greater impact with fewer barriers to entry.

Mini Shai-Hulud and Open-Source Supply Chain Attacks

NCC Group is monitoring the ongoing and rapidly evolving wave of Shai-Hulud supply chain attacks.

This report covers the most recent wave of Shai-Hulud activity (Mini Shai-Hulud, Miasma and Hades), observed throughout May and early June 2026. As well as supporting triage of active infections, it provides guidance for defenders building security postures that address the structural risks of open-source package reliance, rather than simply ingesting wave-specific IOCs in response to each new campaign.


Download the full report

Monthly webinar

Our team of Threat Intel experts keep a constant watch over the cyber and geopolitical landscape, so you don’t have to.

Introducing our monthly highlights webinar, giving you further insight and exclusive access to what's going on now. Join our Global Head of Threat Intelligence, Matt Hull, each month for:

  • A deeper understanding of the latest report findings
  • A look at emerging trends by region and sector
  • Insight into new threat actors
  • Spotlight on the most impactful active cyber threats

Our next webinar will take place on August 25th 2026, 4pm BST.

Matt Hull

Matt Hull

VP, Cyber Intelligence and Response

Subscribe to our monthly reports and webinars for the latest on recent and emerging advances in the threat landscape and a deep understanding of the latest Tactics, Techniques and Procedures (TTPs) of threat actors.

Cyber Threat Intelligence report archive

On demand videos

Missed a webinar? Find every past recording in our showcase:

View now

Never miss any intelligence.

Hit the button below to get our monthly reports and highlight webinars straight to your inbox.