Skip to main content
THREAT INTELLIGENCE REPORT

2026 Cyber Threat Landscape Report

How attackers got in, who they hit, and what it cost.

24 pages • Direct PDF download • Verified sources
Lorikeet Security 2026 Cyber Threat Landscape Report open spread
31%
of breaches began with vulnerability exploitation, now the top entry point
96%
of ransomware victims were small and mid-sized businesses (where size was known)
$11.5M
average cost of a data breach in the United States
EXECUTIVE OVERVIEW

A definitive look at the 2026 threat landscape

Built entirely on public, verifiable research from 39 industry sources, regulatory enforcement actions, and real-world case studies.

  • 01 How attackers got in during 2026, and the CVEs they kept coming back to
  • 02 Which company sizes got hit, and what it cost each tier
  • 03 Certified vs. non-compliant: what compliance did and did not change
  • 04 Four case studies and seven prioritized recommendations

Report Specifications

Published September 2026
Length 24 pages
Cited Sources 39 primary sources
Format PDF (Instant download)
Client Data Zero client data used
INITIAL ACCESS VECTORS

Exploitation took the lead.

Exploiting known vulnerabilities became the single most frequent path into corporate environments, surpassing stolen credentials and credential stuffing.

88%
of exploitation of vulnerabilities with a public PoC happened within 48 hours of the PoC's release (Jan to Jun 2026)
Source: CrowdStrike 2026 Threat Hunting Report
43 days
median time to fully remediate a critical vulnerability, up from 32
2x
vishing intrusions in H1 2026 vs H2 2025
Source: CrowdStrike 2026 Threat Hunting Report
Chart showing 2026 initial access breakdown with vulnerability exploitation leading
Figure 1.1: Initial access vector distribution across confirmed breaches
TARGET DEMOGRAPHICS

Small businesses take the hits. Enterprises take the losses.

Ransomware actors scaled volume attacks on resource-constrained organizations while escalating extortion demands against multi-billion dollar targets.

48%
of breaches involved ransomware
69%
of ransomware victims did not pay; median payment $139,875
+74%
quarter-over-quarter rise in ransomware victims with $1B+ revenue (23 to 40, Q2 2026)
Chart depicting affected industry sectors and organization revenue tiers
Figure 2.1: Targeted industry sectors and enterprise impact breakdown
COMPLIANCE REALITY

Certified isn't the same as secure.

Passing an audit checks boxes for historical controls, but regulatory bodies and adversary intrusions demonstrated that paper certification cannot replace adversarial testing.

$409M
record fine for Coupang, which was ISMS-P certified when breached
Source: The Record
+$201,112
added to average breach cost when noncompliance with regulations is a factor
4 of 4
April 2026 OCR ransomware settlements cited no accurate HIPAA risk analysis ($1.165M total)
Source: HHS OCR
Report page 13 preview showing compliance certification comparison table

Excerpt from Page 13: Analysis of certified entities breached in 2026 and subsequent regulatory penalties.

ARTIFICIAL INTELLIGENCE

AI lowered the floor.

Adversaries accelerated social engineering scripts and automated reconnaissance, while uncontrolled employee adoption created unmonitored shadow attack vectors.

1 in 4
malicious breaches were AI-enabled, averaging about $6M
Source: IBM newsroom
43%
of breaches involved shadow AI, up from 20%
THREAT ACTORS OF 2026

Four adversary profiles defining 2026 attack patterns

These groups demonstrated the tactics dominating intrusion data: identity-first extortion, weaponized device management, high-volume ransomware, and upstream dependency poisoning.

ShinyHunters

Extortion (eCrime)
Attacker claims unverified
Vishing into SSO, then data theft from SaaS apps. Canvas, McKesson (claimed).

Handala

Iran MOIS-linked persona
Abused Microsoft Intune admin access to wipe Stryker devices worldwide.

Qilin and The Gentlemen

Ransomware-as-a-service
The two most active ransomware operations of 2026. SMBs are their core market.

TeamPCP

Supply chain (eCrime)
Poisoned Trivy; the compromise spread to LiteLLM and Checkmarx KICS.
Source: VulnCheck
ACTIONABLE INTELLIGENCE

Know how attackers got in. Close those doors first.

Download the complete 24-page research report for root-cause analyses, targeted CVE inventories, and seven prioritized engineering recommendations.

Lorikeet Security 2026 Threat Report spread preview
FREQUENTLY ASKED QUESTIONS

Report Methodology & Details

Where does the data in this report come from?

Public industry research (Verizon, IBM, CrowdStrike, Sophos, Check Point, NordStellar, VulnCheck, NetDiligence), regulatory filings and enforcement actions (SEC, HHS OCR, Korea PIPC), and news reporting, all cited. It contains no Lorikeet Security client data.

Which size of company is most targeted?

Small and mid-sized businesses. They made up 96% of ransomware victims where size was known in the Verizon 2026 DBIR, while large enterprises accounted for most of the dollar losses.

Does being SOC 2 or ISO 27001 certified prevent a breach?

No. Instructure and Coupang were both certified when they were breached. Certification proves a scoped set of controls was tested. Organizations that skipped required controls were also breached, then fined.

What did a breach cost in 2026?

IBM puts the global average at a record $4.99M and the US average at $11.5M.

OFFENSIVE SECURITY PLATFORM

Turn Threat Intelligence into Autonomous Defense

Lorikeet Security combines continuous penetration testing with agentic AI to find and fix exploitable vulnerabilities before adversaries can weaponize them.

AUTONOMOUS OFFENSIVE SECURITY

Lory AI Pentester

Agentic AI pentesting that autonomously maps attack surfaces, discovers zero-day and logic flaws, and validates exploitable vectors across web apps and APIs 24/7 with zero false positives.

  • Autonomous reconnaissance and vulnerability exploitation
  • Step-by-step developer reproduction steps and PoC evidence
  • Instant retesting to verify fixes in minutes
CONTINUOUS PENETRATION TESTING AS A SERVICE

Talon PTaaS Platform

Continuous penetration testing combining human offensive security engineers with automated validation to unblock enterprise sales and guarantee compliance readiness.

  • On-demand human offensive testing and rapid retesting
  • Audit-ready attestation reports for SOC 2, ISO 27001, and PCI DSS
  • Direct collaboration with senior offensive security testers
Lory waving

Hi, I'm Lory! Need help finding the right service? Click to chat!