Threat Economy
The attacker side is the demand generator for the industry. Security spend is downstream of a threat, and how attackers monetize indicates where defensive demand — and therefore M&A — concentrates next.
Related drill-downs: Ransomware-as-a-Service, Initial-Access Brokers, Nation-State & APTs, BEC, Fraud & Social Engineering, The Cybercrime Supply Chain & Laundering, Threat as a Leading Indicator, and Notable Breaches & Their Costs.
How attackers make money
| Method | Mechanism | Monetization |
|---|---|---|
| Ransomware / extortion | Encrypt + steal data ("double extortion") | Crypto ransom payments |
| Ransomware-as-a-Service (RaaS) | Platform licensed to affiliates | Affiliate keeps 70–80%, operator 20–30% |
| Initial Access Brokers (IABs) | Sell stolen credentials/access | Per-access sale on dark-web forums |
| Business Email Compromise (BEC) | Social-engineered wire fraud | Direct fund transfer (largest $ losses) |
| Data theft & resale | Steal PII/PHI/credentials | Sold in bulk on markets |
| Cryptojacking / fraud | Hijack compute / payment fraud | Mined crypto, carding |
| Nation-state / espionage | IP theft, sabotage, pre-positioning | Strategic (not always financial) |
| DDoS-for-hire / "booters" | Rent attack infrastructure | Subscription |
The cybercrime supply chain
The ecosystem is specialized and professionalized — developers, affiliates, IABs, negotiators, launderers — mirroring a legitimate software supply chain with revenue-sharing, "customer support," and SLAs.
2025–2026 economics
- On-chain ransomware payments fell ~8% to ~$820M in 2025, even as claimed attacks rose ~50% — victims paying less often, attackers compensating with volume.
- Recorded ransomware attacks reached a new high in the first half of 2026: 4,217 logged attacks (an average of ~23 per day), up ~11% on the second half of 2025 (3,809) — the volume-over-payment pattern continuing into 2026. Of the total, 484 were confirmed by the targeted organizations and 3,733 remain unconfirmed leak-site claims. The median ransom demand across confirmed attacks was $150,000 (average $1.36M, skewed by NetRunner's $100M demand on Japan's Nippon Medical School Musashi Kosugi Hospital in February 2026 — refused; the largest reported payment was up to $20M by US law firm Weil, Gotshal & Manges to the Silent Ransom Group in May 2026). Qilin was the most prolific group in the half (641 victims), followed by The Gentlemen (464) and Akira (317) — though The Gentlemen overtook Qilin in June (115 claims vs 78), its first month on top. Manufacturing remained the most targeted industry (822 attacks, +10% vs H2 2025, ~22% of business-sector attacks); the US remained the most targeted country (1,832 attacks) but was the only top-tier country to decline (−8%), partly because The Gentlemen's claims are less US-concentrated (~17% US vs Qilin's ~47%) (Comparitech H1 2026 ransomware roundup, Jul 2 2026).
- Broader illicit flows into ransomware-linked wallets exceeded $1.3B (incl. inter-group transfers and cybercrime-service payments).
- BEC remains the largest single category of reported financial loss.
- State-aligned proxies (e.g., Iranian, Russian, North Korean groups) increasingly blur criminal and geopolitical motives; North Korea funds the regime via crypto theft.
1H 2026 threat landscape in review
The first half of 2026 supports a strong cybersecurity demand environment into the second half of 2026 and beyond — the central conclusion of Wall Street research reviewing the period. The driver is a broad attack surface spanning on-premises, hybrid, multi-cloud, and now AI environments, combined with rising AI capability among attackers, including Chinese and open-source models closing the gap with frontier-model cyber capabilities. The half's events spanned supply-chain attacks, insider threats, software vulnerabilities, operational shutdowns, crypto theft, and geopolitically motivated operations, with AI playing a growing role on both the offensive and governance sides. Notable incidents grouped by theme:
Attacks with real-world operational impact. A provider of ignition-interlock devices (Intoxalock) was hit in March 2026, locking thousands of U.S. drivers out of starting their cars for over a week. A Massachusetts hospital system (Signature Healthcare Brockton) suffered an April 2026 ransomware attack that forced ambulance diversions and canceled chemotherapy appointments. Toy manufacturer Hasbro disclosed a March 2026 network intrusion that it expects to delay roughly $40–60M of Consumer Products revenue to the back half of the year, plus about $20M of one-time remediation operating expense in 2026. A North Dakota water-treatment plant serving about 80,000 people (Minot) suffered a March 2026 ransomware attack on its SCADA systems, running water operations manually for 16 hours.
AI-related incidents. In April 2026, an AI coding agent operating for software vendor PocketOS deleted the company's production database and backups in roughly nine seconds while attempting to resolve a credential mismatch, causing a 30-plus-hour outage; because the most recent backup was 90 days old, records were reconstructed manually from payment, email, and calendar data. Wall Street research also cited AI-lab data-governance failures, including reports that Anthropic inadvertently exposed unpublished internal files and, separately, a large volume of proprietary source code through human error rather than an external attack, and a report that a third-party contractor obtained unauthorized access to a preview model using existing credentials. The review noted these alongside its broader point that AI is increasingly both a target and a tool for attackers.
Geopolitically motivated operations. Combined cyber and physical operations were reported around the Venezuela conflict (a power-grid disruption in Caracas) and the Iran war (blackout-inducing electronic campaigns and retaliatory breaches on both sides). A China-aligned espionage group was reported to have breached at least 70 government agencies and critical-infrastructure organizations across 37 countries over 2025–2026 to collect geopolitical intelligence.
Attack vectors. Insider threat: a U.S. defense contractor (L3Harris) recorded a $35M loss after an employee sold trade secrets and exploit tools to foreign governments; the former employee was sentenced to over seven years and ordered to pay more than $10M in restitution. Supply chain: a web-hosting platform (Vercel) suffered an April 2026 OAuth supply-chain compromise exposing customer secrets, and the widely used Axios JavaScript library (100M+ weekly downloads) was briefly poisoned in March 2026 via a hijacked maintainer token. A severe Linux local-privilege-escalation vulnerability ("CopyFail") was disclosed in April 2026. A June 2026 credential-harvesting campaign ("FortiBleed") aggregated exposed credentials for roughly 74,000 Fortinet firewall URLs. The FBI disclosed a February 2026 breach of non-public surveillance-related data, and a healthcare-technology vendor (Xsolis) reported a January 2026 breach affecting nearly 1.4M patients.
Crypto. A North-Korea-linked group exfiltrated roughly $285M from Solana-based Drift Protocol in April 2026 after a months-long social-engineering operation; a separate January 2026 breach of Step Finance took about $40M and led to that platform's shutdown.
Financial consequences and enforcement. Comcast established a $117.5M settlement fund (April 2026) over a 2023 breach affecting ~31.6M customers; Flagstar Bank received preliminary approval for a $31.5M settlement over 2021 breaches; and China-based Hytera pleaded guilty to conspiracy charges tied to a trade-secret theft scheme, drawing a $50M criminal fine and $214M in restitution. On enforcement, individuals tied to the BlackCat ransomware group — including two ransomware negotiators who leaked clients' positions to attackers — were convicted in 2026, and several U.S. residents were sentenced for facilitating North Korea's "fake IT worker" scheme.
H1 2026 in counted series
The review above is a narrative of notable events. A separate midyear dataset published on August 17, 2026 by threat intelligence firm Flashpoint, drawn from deep and dark web forums, illicit marketplaces, encrypted channels and actor-linked infrastructure, puts counts against the same period and compares each with the preceding six months.
| Series | H1 2026 | Change vs. prior six months |
|---|---|---|
| Devices infected with infostealer malware | 7.4M | +27% |
| Credentials harvested via infostealers | 1.7B | — |
| Vulnerability disclosures tracked | 21,667 | +8% |
| Disclosures with public or functional exploit code | 19% of the above | — |
| Vulnerabilities under active in-the-wild exploitation | 239 | — |
| Ransomware victims counted | 6,256 | +45% |
Three readings follow, and each maps to a different part of the market.
The credential layer is being industrialized rather than merely enlarged. Vidar, StealC and Lumma were the most prolific variants, all of them established commodity families rather than novel tooling (15b). The change described is in the processing rather than the harvesting: Flashpoint characterizes the ecosystem as largely automated, with harvested logs ingested directly into systems that parse high-value metadata and initiate credential stuffing and session testing across many environments in parallel. That compresses the interval between infection and use, which is the interval the identity-security stack is sold against — phishing-resistant authentication, session binding and identity threat detection (03a) — and it moves the buying case away from credential hygiene toward containment of credentials already in circulation.
Exploitation remains a small fraction of disclosure, and the gap between catalogs is wide. Of the 21,667 disclosures tracked, 239 were recorded under active exploitation — roughly 1.1% — against 82 flaws added to the federal CISA Known Exploited Vulnerabilities catalog over the same period, a difference of about 191%. The spread between two catalogs of the same phenomenon is the practical argument for the prioritization layer that exposure-management vendors sell (03k): the operative question for a security team is not how many vulnerabilities exist but which of them are being used, and the public record and commercial records answer it differently.
Ransomware volume rose while payment rates continued to fall. The 45% increase in counted victims is attributed to automation, low-cost initial access and a mature ransomware-as-a-service ecosystem — the supply-side economics set out in 15a — and it coexists with the declining pay-rate recorded there. Rising volume against falling monetization is the condition under which affiliate behavior shifts, and it is the mechanism behind that page's bear case rather than a contradiction of it.
A refusal at scale, and what it costs both sides. Manchester Airports Group declined a ransom demand, and the group holding the data published approximately 550GB covering 8.8 million people, stating it obtained access through exposed administrative keys (SecurityWeek, Sep 3 2026). Refusals of this size are the visible half of the falling pay-rate above, and they carry an asymmetry worth stating: the victim converts a negotiated, capped cash payment into an uncapped and durable liability — regulatory exposure under UK GDPR, notification cost across 8.8 million data subjects, and litigation — while the attacker's marginal cost of publication is close to zero. The economic effect on the criminal side is not that publication earns nothing but that it earns nothing from this victim; the return has to come from the deterrent value the publication creates against the next one. That is a materially worse business than a paid extortion, and it is the mechanism that pushes affiliates toward volume, toward data theft without encryption, and toward targets with lower refusal rates. The stated access vector — exposed administrative keys rather than an exploit — is the same secrets-and-non-human-identity failure that recurs across 15b and drives the machine-identity demand on 03a.
The other half of the same pay-rate, at the opposite end of the victim distribution. Winona County, Minnesota paid $128,539.57 to restore services and limit exposure of personal information after a January 2026 ransomware attack; the county was hit a second time in April, in an incident claimed by the InterLock group, and responsibility for the January intrusion has not been established (SecurityWeek, Sep 4 2026 · WXOW). The figure sits close to the $150,000 median demand recorded across confirmed H1 2026 attacks above, which is the point: the affiliate economics work not on the eight-figure refusals but on a long tail of six-figure payments from organisations that cannot restore from backup and cannot litigate the alternative. A county paying $129K and being hit again three months later is the pay-rate's floor behaving exactly as the volume model predicts — the same under-resourced public-sector tier that 14 covers from the demand side.
Flashpoint also captured more than 22 million posts relating to malicious use of AI on illicit forums and closed channels over the period, noting that commoditized open-source models let many actors run tooling locally rather than through underground services, with Telegram, Reddit, GitHub and Pastebin serving as the principal distribution surfaces for those that do not. See AI for Offense.
These counts are one vendor's telemetry and definitions. They are not interchangeable with the credential figures cited on 15b and 15e, which come from different trackers measuring different universes — credentials in circulation versus credentials harvested in a period — and the two sets should not be combined or differenced.
Source: Infosecurity Magazine — Infostealers Harvest 1.7 Billion Credentials in Six Months (Aug 17, 2026), reporting the Flashpoint 2026 Global Threat Intelligence Report: Midyear Edition.
A second, independent H1 2026 series — network and endpoint telemetry rather than forum monitoring — corroborates the production-cost read without being merged into it. WatchGuard's 1H 2026 Internet Security Report (published Sep 22, 2026) records network-level attack volume down 79% year-over-year against novel endpoint malware up more than 2,000%, with 96% of endpoint malware samples appearing on only one machine — a distribution consistent with per-target payload generation rather than broadly reused tooling. The report attributes this to AI-assisted tooling shifting attackers from high-volume campaigns toward victim-specific malware alongside low-intensity probing across a wider target set. On ransomware specifically: 41 new groups tracked in the half, with the top eight responsible for over half of nearly 5,000 public extortion claims even as endpoint ransomware detections fell 68% year-over-year — a further instance of the falling-detection/rising-extortion divergence this page documents above. 95% of malware arrived over TLS, and only 20% of deployed devices inspect encrypted traffic — an existing-control gap rather than an AI finding, and the more directly actionable line for diligence: a target's stated malware-detection coverage is materially overstated wherever its inspected-traffic share sits near this norm. This is a third, independently sourced H1 2026 dataset alongside the Flashpoint series above; as with that series, the counts are not combined or differenced across trackers. (WatchGuard, Sep 22, 2026)
Industrial ransomware, Q2 2026
Industrial organizations are the segment where ransomware volume and operational consequence are most directly linked, and the quarterly count is one of the few consistently measured series in the threat economy. Dragos recorded 1,140 ransomware incidents affecting industrial organizations worldwide in Q2 2026, a 12% increase over the previous quarter, with manufacturing accounting for 747 of them — roughly two-thirds of the total (Dragos, Q2 2026).
The composition matters more than the count. Disruption continued to arrive through IT, ERP and virtualization systems, and Dragos found no cases in which attackers directly manipulated industrial control systems. Operational impact is therefore still being produced by ordinary enterprise ransomware reaching systems that industrial operations depend on, not by adversaries acquiring and using process-level capability. That distinction bears on how OT security demand should be read: the near-term budget driver is segmentation, visibility and recovery across the IT/OT boundary rather than defense against process manipulation, which remains the domain of state pre-positioning (15c) rather than of criminal monetization. See OT/ICS Security.
July 2026 edge-appliance exploitation cluster
Three concurrent exploitation waves against internet-facing enterprise infrastructure ran through July 2026, together illustrating the edge appliance and on-premises server as the dominant non-phishing entry path into corporate networks:
- Microsoft SharePoint (on-premises). CVE-2026-58644, a deserialization remote-code-execution flaw (CVSS 9.8) affecting all supported on-premises SharePoint versions, was exploited in the wild before being patched on July 14; CISA added it to the Known Exploited Vulnerabilities catalog on July 16 with an unusually short three-day federal remediation deadline, and its July 14 alert listed four SharePoint CVEs under active exploitation, with IIS machine-key theft used for persistence (CISA alert, Jul 14 2026).
- SonicWall SMA 1000 (remote-access appliance). CVE-2026-15409, an unauthenticated server-side request forgery (CVSS 10.0), chained with CVE-2026-15410, a post-authentication code injection, gave root access on SMA VPN appliances. Volexity attributed exploitation to a previously undocumented actor, UTA0533, active since June 22 — before disclosure; SonicWall issued urgent patch guidance July 14, and CISA added both CVEs to the KEV catalog with a July 17 federal deadline. No victims or attribution beyond the actor designation have been published (Volexity, Jul 17 2026 · SecurityWeek).
- Palo Alto Networks GlobalProtect (VPN gateway) → Qilin ransomware. Arctic Wolf Labs reported (July 20) multiple June-2026 intrusions in which CVE-2026-0257, an authentication-bypass flaw (CVSS 7.8) in PAN-OS GlobalProtect portals and gateways, served as the initial access vector for Qilin ransomware deployment — unauthenticated VPN sessions established via authentication-override cookies, followed by LSASS and Active Directory credential harvesting, PsExec lateral movement, ransomware staging in C:\PerfLogs\, and domain-wide encryption, with data theft and double extortion in some cases (Arctic Wolf Labs, Jul 20 2026 · BleepingComputer).
The cluster echoes the July-2025 ToolShell SharePoint wave and the 2024–25 Ivanti and Fortinet episodes: security and connectivity appliances themselves are recurring points of entry, and the most prolific ransomware group of 1H 2026 (Qilin, above) now runs edge-appliance exploitation as an initial-access motion alongside its affiliate phishing. The pattern sustains demand for exposure management and validation (03k), attack-surface reduction, and the patch-speed economics discussed in AI Security.
Why the criminal cyber economy exists
The criminal cyber economy is a rational market, driven by incentives that favor attackers:
- Asymmetric economics. An attacker needs one success; a defender must stop every attempt. Tooling (RaaS kits, IAB access) is cheap and reusable; the payoff (a single ransom or wire fraud) can be enormous. ROI is extreme.
- Low cost of entry, high specialization. The supply chain (developers, affiliates, brokers, launderers) lets low-skill actors participate by renting capability — exactly like SaaS lowered the barrier to building software.
- Cryptocurrency enabled scalable payment & laundering. Pseudonymous, borderless value transfer made monetization and cash-out viable at scale.
- Near-impunity / jurisdictional arbitrage. Many operators sit in jurisdictions that won't extradite or that tolerate (or direct) attacks on adversaries. Enforcement is slow and cross-border.
- A vast, soft attack surface. Cloud, SaaS, remote work, IoT/OT, and supply chains expand the target set faster than defenses mature.
- State sponsorship & blurred lines. Some governments run, fund, or shelter criminal groups, blending espionage, revenue, and deniable coercion (see Sovereign).
In short: demand exists because crime pays, capability is rentable, money moves anonymously, and accountability is weak. Every one of these conditions also guarantees durable, growing demand for defense — the economic engine under the entire security industry.
Red, blue, and purple teams
Because attackers hold the structural advantage described above, defenders rely on continuous testing that emulates an adversary rather than on passive controls. This is the origin of team-based security operations:
| Team | Role | Mindset |
|---|---|---|
| Red team | Offensive — simulate real attackers (pen-test, adversary emulation, social engineering) to find what actually breaks | "Think like the attacker" |
| Blue team | Defensive — detect, respond, harden; run the SOC, monitoring, IR | "Defend and recover" |
| Purple team | The feedback loop — red and blue working together so every attack technique becomes a new detection | "Attack to improve defense" |
Why they exist: real-world adversaries are the only honest test of a defense. Red teams expose gaps before criminals do; blue teams turn those findings into controls; purple teaming institutionalizes the loop. This dynamic is itself a market — it powers the offensive-security/PTaaS, BAS, and MDR sub-segments (Pentera, Cymulate, Cobalt, Synack, NetSPI, Bishop Fox — see Service Providers) and is increasingly productized into continuous, automated, and now AI-driven testing.
Why the threat economy maps to M&A demand
Every threat maps to a control the CISO must fund — the threat→control→budget logic that turns a headline breach into a board-approved line item. Acquirers read the same map forward as a deal pipeline (below). The linkages:
- Ransomware → demand for backup/recovery, EDR/XDR, MDR, cyber insurance, IR services.
- Identity-based attacks (the #1 vector) → demand for IAM, PAM, MFA, ITDR, machine identity — explaining the identity-segment M&A wave (Palo Alto–CyberArk). Sophos research published July 2026 quantifies the shift: compromised identities were the entry vector in 79% of ransomware attacks, overtaking exploited vulnerabilities, and MFA was enabled in 97% of breaches involving stolen credentials — indicating implementation gaps rather than absence of controls; 56% of attacks reached the encryption stage, and smaller organizations disrupted only 34% of attacks before encryption or extortion (SC Media, Jul 16 2026). BeyondTrust's Phantom Labs Research Index, released at Black Hat USA 2026, put the same pattern at a wider scope: 75% of attacks involved an identity or privilege issue — credential exposure, privilege escalation and identity misconfiguration — which typically compounded rather than appearing in isolation, standing privilege and escalation frequently occurring together (37).
- Cloud attacks → demand for CNAPP/DSPM (the Wiz thesis).
- AI-enabled attacks → demand for AI security and autonomous defense (the 2026 frontier). Threshold crossed (Jul 2026): the first documented end-to-end agentic ransomware operation. Sysdig's JADEPUFFER research (disclosed Jul 1–2 2026) documents an LLM agent that autonomously exploited an internet-facing Langflow instance (CVE-2025-3248, unauthenticated RCE), chained recon → credential theft → lateral movement → persistence, then ran a destructive database-extortion playbook — encrypting 1,300+ configuration elements, deleting originals, and dropping a Bitcoin ransom note. Telltales of machine operation: LLM-style annotated payloads, natural-language reasoning in code, and a 31-second self-correcting fix when a backdoor attempt errored. Notably, the encryption key was generated, printed once and never stored — the victim couldn't recover even by paying, i.e., competence limits, not intent, still bound the damage. Economic read: ransomware's skill barrier just collapsed — an agent chains the full kill chain without the operator being expert in any step, which expands the affiliate pool and compresses attack cost the way RaaS did in 2019–21 (Sysdig · The Register, Jul 2 2026 · The Hacker News). Defensive read-through: machine-speed offense is the demand engine for machine-speed defense (agentic SOC, autonomous patching — cf. Aikido–Root, 11). The counterweight, measured (Aug 2026). Palo Alto Networks' Unit 42 cross-referenced 405 AI-linked malware samples against endpoint telemetry and alert records and found 12 on live endpoints — about 3%, with roughly 97% never leaving a sandbox, a research repository or an internal test environment. All 12 alerted, and none required a detection method that did not already exist; the remainder was dominated by academic proof-of-concept code, defenders testing their own controls, and ordinary payloads using AI branding as bait. The demand implication is narrower than the headline: on this sample AI lowers the cost of producing and varying offensive tooling without raising its success rate against defended endpoints, so the budget it creates lands on triage capacity and detection engineering at volume rather than on replacing the endpoint control set (20a, 04c). It is one vendor's telemetry over one corpus, and JADEPUFFER above shows the ceiling is not fixed (Unit 42 · SecurityWeek, Aug 26 2026).
- Attacks on operational technology → demand for OT asset inventory and discovery, network segmentation, protocol-aware monitoring and secure remote access. The 2026 instance is a campaign rather than an incident. CISA reported malicious activity in July 2026 against more than 100 internet-exposed systems in the water and wastewater sector, typically programmable logic controllers reachable through a cellular modem, with disruption at community water systems across at least twelve US states; a joint advisory (AA26-231A, Aug 19 2026, NSA/CISA/FBI/DOE/EPA) subsequently recorded attackers using AI coding assistants and open-source automation libraries to build custom tooling against internet-exposed Siemens S7 Series controllers, which the agencies said lowers the operational-technology knowledge an attacker needs. The Telegraph reported on Aug 22 2026 that Iranian actors disabled a UK power plant for four days the previous month; the facility has not been named and the report has not been confirmed by the UK government, so it is recorded as a press account rather than an established fact. The prescribed controls are inventory, patching, removal of internet exposure and anomaly detection on the S7comm protocol — asset visibility and segmentation, which is what the sub-segment's three 2026 exits were bought for (03h, Sovereign). (CISA AA26-231A · The Register, Aug 19 2026 · Infosecurity Magazine, Aug 24 2026)
- AI build-chain / software-supply-chain attacks → demand for package/registry integrity, provenance/SBOM, dependency governance, AI-SPM. Live proof (Jun 2026): North Korea's Sapphire Sleet (APT38/BlueNoroff) backdoored 144 npm packages in the
@mastraAI-agent framework scope in ~88 minutes via a compromised maintainer account, dropping credential/crypto-wallet-stealing malware (compromise Jun 17; Microsoft attribution Jun 19; linked to an April 2026 Axios npm attack) — the same actor logic as RaaS (rent/automate capability, monetize via crypto) now aimed at the AI developer ecosystem (Infosecurity · SecurityWeek). Read-through to the Security-for-AI pool: see AI Security.
→ Cyber insurance linkage: Ransomware economics drive the cyber-insurance market (Coalition, At-Bay, Corvus/Travelers, Resilience), which is itself consolidating and overlaps with security vendors — a deal-adjacent space to monitor.
Sensitivity note: this describes the criminal economy at a market-structure level for defensive and investment-analysis purposes only.
Updated 2026-10-04 19:34 UTC · © El Dorado Capital · el-doradocapital.com · Market intelligence for informational purposes only; not investment advice.