Threat Economy

The attacker side is the demand generator for the industry. Security spend is downstream of a threat, and how attackers monetize indicates where defensive demand — and therefore M&A — concentrates next.

Related drill-downs: Ransomware-as-a-Service, Initial-Access Brokers, Nation-State & APTs, BEC, Fraud & Social Engineering, The Cybercrime Supply Chain & Laundering, Threat as a Leading Indicator, and Notable Breaches & Their Costs.

How attackers make money

Method Mechanism Monetization
Ransomware / extortion Encrypt + steal data ("double extortion") Crypto ransom payments
Ransomware-as-a-Service (RaaS) Platform licensed to affiliates Affiliate keeps 70–80%, operator 20–30%
Initial Access Brokers (IABs) Sell stolen credentials/access Per-access sale on dark-web forums
Business Email Compromise (BEC) Social-engineered wire fraud Direct fund transfer (largest $ losses)
Data theft & resale Steal PII/PHI/credentials Sold in bulk on markets
Cryptojacking / fraud Hijack compute / payment fraud Mined crypto, carding
Nation-state / espionage IP theft, sabotage, pre-positioning Strategic (not always financial)
DDoS-for-hire / "booters" Rent attack infrastructure Subscription
Affiliate 70–80% Operator 20–30% RaaS ransom split — the franchise model 2025: ~$820M on-chain ransom (−8% YoY) · >$1.3B total illicit flows · attacks +50%
Ransomware-as-a-service economics: developers license tooling to affiliates who run the attacks and keep the larger share.

The cybercrime supply chain

The ransomware-as-a-service supply chain A specialized, revenue-shared criminal economy that runs like SaaS DEVELOPERSbuild the ransomware20–30% AFFILIATESrun the attacks70–80% license platform → INITIAL ACCESS BROKERSsell stolen creds / entry sell access ↑ RaaS PLATFORMtooling · support · escrow MONEY LAUNDERINGmixers · mules · OTC desks → cash-out ransom $ ↓ Splits per Chainalysis/Sophos; 2025 on-chain ransom ~$820M (−8% YoY), >$1.3B total illicit flows.
Developers license the platform to affiliates (who keep the larger share and buy entry from initial-access brokers); proceeds route through laundering to cash-out. Specialized, revenue-shared, and resilient — which is why defensive demand is permanent.

The ecosystem is specialized and professionalized — developers, affiliates, IABs, negotiators, launderers — mirroring a legitimate software supply chain with revenue-sharing, "customer support," and SLAs.

2025–2026 economics

1H 2026 threat landscape in review

The first half of 2026 supports a strong cybersecurity demand environment into the second half of 2026 and beyond — the central conclusion of Wall Street research reviewing the period. The driver is a broad attack surface spanning on-premises, hybrid, multi-cloud, and now AI environments, combined with rising AI capability among attackers, including Chinese and open-source models closing the gap with frontier-model cyber capabilities. The half's events spanned supply-chain attacks, insider threats, software vulnerabilities, operational shutdowns, crypto theft, and geopolitically motivated operations, with AI playing a growing role on both the offensive and governance sides. Notable incidents grouped by theme:

Attacks with real-world operational impact. A provider of ignition-interlock devices (Intoxalock) was hit in March 2026, locking thousands of U.S. drivers out of starting their cars for over a week. A Massachusetts hospital system (Signature Healthcare Brockton) suffered an April 2026 ransomware attack that forced ambulance diversions and canceled chemotherapy appointments. Toy manufacturer Hasbro disclosed a March 2026 network intrusion that it expects to delay roughly $40–60M of Consumer Products revenue to the back half of the year, plus about $20M of one-time remediation operating expense in 2026. A North Dakota water-treatment plant serving about 80,000 people (Minot) suffered a March 2026 ransomware attack on its SCADA systems, running water operations manually for 16 hours.

AI-related incidents. In April 2026, an AI coding agent operating for software vendor PocketOS deleted the company's production database and backups in roughly nine seconds while attempting to resolve a credential mismatch, causing a 30-plus-hour outage; because the most recent backup was 90 days old, records were reconstructed manually from payment, email, and calendar data. Wall Street research also cited AI-lab data-governance failures, including reports that Anthropic inadvertently exposed unpublished internal files and, separately, a large volume of proprietary source code through human error rather than an external attack, and a report that a third-party contractor obtained unauthorized access to a preview model using existing credentials. The review noted these alongside its broader point that AI is increasingly both a target and a tool for attackers.

Geopolitically motivated operations. Combined cyber and physical operations were reported around the Venezuela conflict (a power-grid disruption in Caracas) and the Iran war (blackout-inducing electronic campaigns and retaliatory breaches on both sides). A China-aligned espionage group was reported to have breached at least 70 government agencies and critical-infrastructure organizations across 37 countries over 2025–2026 to collect geopolitical intelligence.

Attack vectors. Insider threat: a U.S. defense contractor (L3Harris) recorded a $35M loss after an employee sold trade secrets and exploit tools to foreign governments; the former employee was sentenced to over seven years and ordered to pay more than $10M in restitution. Supply chain: a web-hosting platform (Vercel) suffered an April 2026 OAuth supply-chain compromise exposing customer secrets, and the widely used Axios JavaScript library (100M+ weekly downloads) was briefly poisoned in March 2026 via a hijacked maintainer token. A severe Linux local-privilege-escalation vulnerability ("CopyFail") was disclosed in April 2026. A June 2026 credential-harvesting campaign ("FortiBleed") aggregated exposed credentials for roughly 74,000 Fortinet firewall URLs. The FBI disclosed a February 2026 breach of non-public surveillance-related data, and a healthcare-technology vendor (Xsolis) reported a January 2026 breach affecting nearly 1.4M patients.

Crypto. A North-Korea-linked group exfiltrated roughly $285M from Solana-based Drift Protocol in April 2026 after a months-long social-engineering operation; a separate January 2026 breach of Step Finance took about $40M and led to that platform's shutdown.

Financial consequences and enforcement. Comcast established a $117.5M settlement fund (April 2026) over a 2023 breach affecting ~31.6M customers; Flagstar Bank received preliminary approval for a $31.5M settlement over 2021 breaches; and China-based Hytera pleaded guilty to conspiracy charges tied to a trade-secret theft scheme, drawing a $50M criminal fine and $214M in restitution. On enforcement, individuals tied to the BlackCat ransomware group — including two ransomware negotiators who leaked clients' positions to attackers — were convicted in 2026, and several U.S. residents were sentenced for facilitating North Korea's "fake IT worker" scheme.

H1 2026 in counted series

The review above is a narrative of notable events. A separate midyear dataset published on August 17, 2026 by threat intelligence firm Flashpoint, drawn from deep and dark web forums, illicit marketplaces, encrypted channels and actor-linked infrastructure, puts counts against the same period and compares each with the preceding six months.

Series H1 2026 Change vs. prior six months
Devices infected with infostealer malware 7.4M +27%
Credentials harvested via infostealers 1.7B —
Vulnerability disclosures tracked 21,667 +8%
Disclosures with public or functional exploit code 19% of the above —
Vulnerabilities under active in-the-wild exploitation 239 —
Ransomware victims counted 6,256 +45%

Three readings follow, and each maps to a different part of the market.

The credential layer is being industrialized rather than merely enlarged. Vidar, StealC and Lumma were the most prolific variants, all of them established commodity families rather than novel tooling (15b). The change described is in the processing rather than the harvesting: Flashpoint characterizes the ecosystem as largely automated, with harvested logs ingested directly into systems that parse high-value metadata and initiate credential stuffing and session testing across many environments in parallel. That compresses the interval between infection and use, which is the interval the identity-security stack is sold against — phishing-resistant authentication, session binding and identity threat detection (03a) — and it moves the buying case away from credential hygiene toward containment of credentials already in circulation.

Exploitation remains a small fraction of disclosure, and the gap between catalogs is wide. Of the 21,667 disclosures tracked, 239 were recorded under active exploitation — roughly 1.1% — against 82 flaws added to the federal CISA Known Exploited Vulnerabilities catalog over the same period, a difference of about 191%. The spread between two catalogs of the same phenomenon is the practical argument for the prioritization layer that exposure-management vendors sell (03k): the operative question for a security team is not how many vulnerabilities exist but which of them are being used, and the public record and commercial records answer it differently.

Ransomware volume rose while payment rates continued to fall. The 45% increase in counted victims is attributed to automation, low-cost initial access and a mature ransomware-as-a-service ecosystem — the supply-side economics set out in 15a — and it coexists with the declining pay-rate recorded there. Rising volume against falling monetization is the condition under which affiliate behavior shifts, and it is the mechanism behind that page's bear case rather than a contradiction of it.

A refusal at scale, and what it costs both sides. Manchester Airports Group declined a ransom demand, and the group holding the data published approximately 550GB covering 8.8 million people, stating it obtained access through exposed administrative keys (SecurityWeek, Sep 3 2026). Refusals of this size are the visible half of the falling pay-rate above, and they carry an asymmetry worth stating: the victim converts a negotiated, capped cash payment into an uncapped and durable liability — regulatory exposure under UK GDPR, notification cost across 8.8 million data subjects, and litigation — while the attacker's marginal cost of publication is close to zero. The economic effect on the criminal side is not that publication earns nothing but that it earns nothing from this victim; the return has to come from the deterrent value the publication creates against the next one. That is a materially worse business than a paid extortion, and it is the mechanism that pushes affiliates toward volume, toward data theft without encryption, and toward targets with lower refusal rates. The stated access vector — exposed administrative keys rather than an exploit — is the same secrets-and-non-human-identity failure that recurs across 15b and drives the machine-identity demand on 03a.

The other half of the same pay-rate, at the opposite end of the victim distribution. Winona County, Minnesota paid $128,539.57 to restore services and limit exposure of personal information after a January 2026 ransomware attack; the county was hit a second time in April, in an incident claimed by the InterLock group, and responsibility for the January intrusion has not been established (SecurityWeek, Sep 4 2026 · WXOW). The figure sits close to the $150,000 median demand recorded across confirmed H1 2026 attacks above, which is the point: the affiliate economics work not on the eight-figure refusals but on a long tail of six-figure payments from organisations that cannot restore from backup and cannot litigate the alternative. A county paying $129K and being hit again three months later is the pay-rate's floor behaving exactly as the volume model predicts — the same under-resourced public-sector tier that 14 covers from the demand side.

Flashpoint also captured more than 22 million posts relating to malicious use of AI on illicit forums and closed channels over the period, noting that commoditized open-source models let many actors run tooling locally rather than through underground services, with Telegram, Reddit, GitHub and Pastebin serving as the principal distribution surfaces for those that do not. See AI for Offense.

These counts are one vendor's telemetry and definitions. They are not interchangeable with the credential figures cited on 15b and 15e, which come from different trackers measuring different universes — credentials in circulation versus credentials harvested in a period — and the two sets should not be combined or differenced.

Source: Infosecurity Magazine — Infostealers Harvest 1.7 Billion Credentials in Six Months (Aug 17, 2026), reporting the Flashpoint 2026 Global Threat Intelligence Report: Midyear Edition.

A second, independent H1 2026 series — network and endpoint telemetry rather than forum monitoring — corroborates the production-cost read without being merged into it. WatchGuard's 1H 2026 Internet Security Report (published Sep 22, 2026) records network-level attack volume down 79% year-over-year against novel endpoint malware up more than 2,000%, with 96% of endpoint malware samples appearing on only one machine — a distribution consistent with per-target payload generation rather than broadly reused tooling. The report attributes this to AI-assisted tooling shifting attackers from high-volume campaigns toward victim-specific malware alongside low-intensity probing across a wider target set. On ransomware specifically: 41 new groups tracked in the half, with the top eight responsible for over half of nearly 5,000 public extortion claims even as endpoint ransomware detections fell 68% year-over-year — a further instance of the falling-detection/rising-extortion divergence this page documents above. 95% of malware arrived over TLS, and only 20% of deployed devices inspect encrypted traffic — an existing-control gap rather than an AI finding, and the more directly actionable line for diligence: a target's stated malware-detection coverage is materially overstated wherever its inspected-traffic share sits near this norm. This is a third, independently sourced H1 2026 dataset alongside the Flashpoint series above; as with that series, the counts are not combined or differenced across trackers. (WatchGuard, Sep 22, 2026)

Industrial ransomware, Q2 2026

Industrial organizations are the segment where ransomware volume and operational consequence are most directly linked, and the quarterly count is one of the few consistently measured series in the threat economy. Dragos recorded 1,140 ransomware incidents affecting industrial organizations worldwide in Q2 2026, a 12% increase over the previous quarter, with manufacturing accounting for 747 of them — roughly two-thirds of the total (Dragos, Q2 2026).

The composition matters more than the count. Disruption continued to arrive through IT, ERP and virtualization systems, and Dragos found no cases in which attackers directly manipulated industrial control systems. Operational impact is therefore still being produced by ordinary enterprise ransomware reaching systems that industrial operations depend on, not by adversaries acquiring and using process-level capability. That distinction bears on how OT security demand should be read: the near-term budget driver is segmentation, visibility and recovery across the IT/OT boundary rather than defense against process manipulation, which remains the domain of state pre-positioning (15c) rather than of criminal monetization. See OT/ICS Security.

July 2026 edge-appliance exploitation cluster

Three concurrent exploitation waves against internet-facing enterprise infrastructure ran through July 2026, together illustrating the edge appliance and on-premises server as the dominant non-phishing entry path into corporate networks:

The cluster echoes the July-2025 ToolShell SharePoint wave and the 2024–25 Ivanti and Fortinet episodes: security and connectivity appliances themselves are recurring points of entry, and the most prolific ransomware group of 1H 2026 (Qilin, above) now runs edge-appliance exploitation as an initial-access motion alongside its affiliate phishing. The pattern sustains demand for exposure management and validation (03k), attack-surface reduction, and the patch-speed economics discussed in AI Security.

Why the criminal cyber economy exists

The criminal cyber economy is a rational market, driven by incentives that favor attackers:

  1. Asymmetric economics. An attacker needs one success; a defender must stop every attempt. Tooling (RaaS kits, IAB access) is cheap and reusable; the payoff (a single ransom or wire fraud) can be enormous. ROI is extreme.
  2. Low cost of entry, high specialization. The supply chain (developers, affiliates, brokers, launderers) lets low-skill actors participate by renting capability — exactly like SaaS lowered the barrier to building software.
  3. Cryptocurrency enabled scalable payment & laundering. Pseudonymous, borderless value transfer made monetization and cash-out viable at scale.
  4. Near-impunity / jurisdictional arbitrage. Many operators sit in jurisdictions that won't extradite or that tolerate (or direct) attacks on adversaries. Enforcement is slow and cross-border.
  5. A vast, soft attack surface. Cloud, SaaS, remote work, IoT/OT, and supply chains expand the target set faster than defenses mature.
  6. State sponsorship & blurred lines. Some governments run, fund, or shelter criminal groups, blending espionage, revenue, and deniable coercion (see Sovereign).

In short: demand exists because crime pays, capability is rentable, money moves anonymously, and accountability is weak. Every one of these conditions also guarantees durable, growing demand for defense — the economic engine under the entire security industry.

Red, blue, and purple teams

Because attackers hold the structural advantage described above, defenders rely on continuous testing that emulates an adversary rather than on passive controls. This is the origin of team-based security operations:

Team Role Mindset
Red team Offensive — simulate real attackers (pen-test, adversary emulation, social engineering) to find what actually breaks "Think like the attacker"
Blue team Defensive — detect, respond, harden; run the SOC, monitoring, IR "Defend and recover"
Purple team The feedback loop — red and blue working together so every attack technique becomes a new detection "Attack to improve defense"

Why they exist: real-world adversaries are the only honest test of a defense. Red teams expose gaps before criminals do; blue teams turn those findings into controls; purple teaming institutionalizes the loop. This dynamic is itself a market — it powers the offensive-security/PTaaS, BAS, and MDR sub-segments (Pentera, Cymulate, Cobalt, Synack, NetSPI, Bishop Fox — see Service Providers) and is increasingly productized into continuous, automated, and now AI-driven testing.

Why the threat economy maps to M&A demand

Every threat maps to a control the CISO must fund — the threat→control→budget logic that turns a headline breach into a board-approved line item. Acquirers read the same map forward as a deal pipeline (below). The linkages:

→ Cyber insurance linkage: Ransomware economics drive the cyber-insurance market (Coalition, At-Bay, Corvus/Travelers, Resilience), which is itself consolidating and overlaps with security vendors — a deal-adjacent space to monitor.

Sensitivity note: this describes the criminal economy at a market-structure level for defensive and investment-analysis purposes only.


Updated 2026-10-04 19:34 UTC · © El Dorado Capital · el-doradocapital.com · Market intelligence for informational purposes only; not investment advice.