Threat Economy
The attacker side is the demand generator for the industry. Security spend is downstream of a threat, and how attackers monetize indicates where defensive demand — and therefore M&A — concentrates next.
Related drill-downs: Ransomware-as-a-Service, Initial-Access Brokers, Nation-State & APTs, BEC, Fraud & Social Engineering, The Cybercrime Supply Chain & Laundering, Threat as a Leading Indicator, and Notable Breaches & Their Costs.
How attackers make money
| Method | Mechanism | Monetization |
|---|---|---|
| Ransomware / extortion | Encrypt + steal data ("double extortion") | Crypto ransom payments |
| Ransomware-as-a-Service (RaaS) | Platform licensed to affiliates | Affiliate keeps 70–80%, operator 20–30% |
| Initial Access Brokers (IABs) | Sell stolen credentials/access | Per-access sale on dark-web forums |
| Business Email Compromise (BEC) | Social-engineered wire fraud | Direct fund transfer (largest $ losses) |
| Data theft & resale | Steal PII/PHI/credentials | Sold in bulk on markets |
| Cryptojacking / fraud | Hijack compute / payment fraud | Mined crypto, carding |
| Nation-state / espionage | IP theft, sabotage, pre-positioning | Strategic (not always financial) |
| DDoS-for-hire / "booters" | Rent attack infrastructure | Subscription |
The cybercrime supply chain
The ecosystem is specialized and professionalized — developers, affiliates, IABs, negotiators, launderers — mirroring a legitimate software supply chain with revenue-sharing, "customer support," and SLAs.
2025–2026 economics
- On-chain ransomware payments fell ~8% to ~$820M in 2025, even as claimed attacks rose ~50% — victims paying less often, attackers compensating with volume.
- Recorded ransomware attacks reached a new high in the first half of 2026: 4,217 logged attacks (an average of ~23 per day), up ~11% on the second half of 2025 (3,809) — the volume-over-payment pattern continuing into 2026. Of the total, 484 were confirmed by the targeted organizations and 3,733 remain unconfirmed leak-site claims. The median ransom demand across confirmed attacks was $150,000 (average $1.36M, skewed by NetRunner's $100M demand on Japan's Nippon Medical School Musashi Kosugi Hospital in February 2026 — refused; the largest reported payment was up to $20M by US law firm Weil, Gotshal & Manges to the Silent Ransom Group in May 2026). Qilin was the most prolific group in the half (641 victims), followed by The Gentlemen (464) and Akira (317) — though The Gentlemen overtook Qilin in June (115 claims vs 78), its first month on top. Manufacturing remained the most targeted industry (822 attacks, +10% vs H2 2025, ~22% of business-sector attacks); the US remained the most targeted country (1,832 attacks) but was the only top-tier country to decline (−8%), partly because The Gentlemen's claims are less US-concentrated (~17% US vs Qilin's ~47%) (Comparitech H1 2026 ransomware roundup, Jul 2 2026).
- Broader illicit flows into ransomware-linked wallets exceeded $1.3B (incl. inter-group transfers and cybercrime-service payments).
- BEC remains the largest single category of reported financial loss.
- State-aligned proxies (e.g., Iranian, Russian, North Korean groups) increasingly blur criminal and geopolitical motives; North Korea funds the regime via crypto theft.
1H 2026 threat landscape in review
The first half of 2026 supports a strong cybersecurity demand environment into the second half of 2026 and beyond — the central conclusion of Wall Street research reviewing the period. The driver is a broad attack surface spanning on-premises, hybrid, multi-cloud, and now AI environments, combined with rising AI capability among attackers, including Chinese and open-source models closing the gap with frontier-model cyber capabilities. The half's events spanned supply-chain attacks, insider threats, software vulnerabilities, operational shutdowns, crypto theft, and geopolitically motivated operations, with AI playing a growing role on both the offensive and governance sides. Notable incidents grouped by theme:
Attacks with real-world operational impact. A provider of ignition-interlock devices (Intoxalock) was hit in March 2026, locking thousands of U.S. drivers out of starting their cars for over a week. A Massachusetts hospital system (Signature Healthcare Brockton) suffered an April 2026 ransomware attack that forced ambulance diversions and canceled chemotherapy appointments. Toy manufacturer Hasbro disclosed a March 2026 network intrusion that it expects to delay roughly $40–60M of Consumer Products revenue to the back half of the year, plus about $20M of one-time remediation operating expense in 2026. A North Dakota water-treatment plant serving about 80,000 people (Minot) suffered a March 2026 ransomware attack on its SCADA systems, running water operations manually for 16 hours.
AI-related incidents. In April 2026, an AI coding agent operating for software vendor PocketOS deleted the company's production database and backups in roughly nine seconds while attempting to resolve a credential mismatch, causing a 30-plus-hour outage; because the most recent backup was 90 days old, records were reconstructed manually from payment, email, and calendar data. Wall Street research also cited AI-lab data-governance failures, including reports that Anthropic inadvertently exposed unpublished internal files and, separately, a large volume of proprietary source code through human error rather than an external attack, and a report that a third-party contractor obtained unauthorized access to a preview model using existing credentials. The review noted these alongside its broader point that AI is increasingly both a target and a tool for attackers.
Geopolitically motivated operations. Combined cyber and physical operations were reported around the Venezuela conflict (a power-grid disruption in Caracas) and the Iran war (blackout-inducing electronic campaigns and retaliatory breaches on both sides). A China-aligned espionage group was reported to have breached at least 70 government agencies and critical-infrastructure organizations across 37 countries over 2025–2026 to collect geopolitical intelligence.
Attack vectors. Insider threat: a U.S. defense contractor (L3Harris) recorded a $35M loss after an employee sold trade secrets and exploit tools to foreign governments; the former employee was sentenced to over seven years and ordered to pay more than $10M in restitution. Supply chain: a web-hosting platform (Vercel) suffered an April 2026 OAuth supply-chain compromise exposing customer secrets, and the widely used Axios JavaScript library (100M+ weekly downloads) was briefly poisoned in March 2026 via a hijacked maintainer token. A severe Linux local-privilege-escalation vulnerability ("CopyFail") was disclosed in April 2026. A June 2026 credential-harvesting campaign ("FortiBleed") aggregated exposed credentials for roughly 74,000 Fortinet firewall URLs. The FBI disclosed a February 2026 breach of non-public surveillance-related data, and a healthcare-technology vendor (Xsolis) reported a January 2026 breach affecting nearly 1.4M patients.
Crypto. A North-Korea-linked group exfiltrated roughly $285M from Solana-based Drift Protocol in April 2026 after a months-long social-engineering operation; a separate January 2026 breach of Step Finance took about $40M and led to that platform's shutdown.
Financial consequences and enforcement. Comcast established a $117.5M settlement fund (April 2026) over a 2023 breach affecting ~31.6M customers; Flagstar Bank received preliminary approval for a $31.5M settlement over 2021 breaches; and China-based Hytera pleaded guilty to conspiracy charges tied to a trade-secret theft scheme, drawing a $50M criminal fine and $214M in restitution. On enforcement, individuals tied to the BlackCat ransomware group — including two ransomware negotiators who leaked clients' positions to attackers — were convicted in 2026, and several U.S. residents were sentenced for facilitating North Korea's "fake IT worker" scheme.
Industrial ransomware, Q2 2026
Industrial organizations are the segment where ransomware volume and operational consequence are most directly linked, and the quarterly count is one of the few consistently measured series in the threat economy. Dragos recorded 1,140 ransomware incidents affecting industrial organizations worldwide in Q2 2026, a 12% increase over the previous quarter, with manufacturing accounting for 747 of them — roughly two-thirds of the total (Dragos, Q2 2026).
The composition matters more than the count. Disruption continued to arrive through IT, ERP and virtualization systems, and Dragos found no cases in which attackers directly manipulated industrial control systems. Operational impact is therefore still being produced by ordinary enterprise ransomware reaching systems that industrial operations depend on, not by adversaries acquiring and using process-level capability. That distinction bears on how OT security demand should be read: the near-term budget driver is segmentation, visibility and recovery across the IT/OT boundary rather than defense against process manipulation, which remains the domain of state pre-positioning (15c) rather than of criminal monetization. See OT/ICS Security.
July 2026 edge-appliance exploitation cluster
Three concurrent exploitation waves against internet-facing enterprise infrastructure ran through July 2026, together illustrating the edge appliance and on-premises server as the dominant non-phishing entry path into corporate networks:
- Microsoft SharePoint (on-premises). CVE-2026-58644, a deserialization remote-code-execution flaw (CVSS 9.8) affecting all supported on-premises SharePoint versions, was exploited in the wild before being patched on July 14; CISA added it to the Known Exploited Vulnerabilities catalog on July 16 with an unusually short three-day federal remediation deadline, and its July 14 alert listed four SharePoint CVEs under active exploitation, with IIS machine-key theft used for persistence (CISA alert, Jul 14 2026).
- SonicWall SMA 1000 (remote-access appliance). CVE-2026-15409, an unauthenticated server-side request forgery (CVSS 10.0), chained with CVE-2026-15410, a post-authentication code injection, gave root access on SMA VPN appliances. Volexity attributed exploitation to a previously undocumented actor, UTA0533, active since June 22 — before disclosure; SonicWall issued urgent patch guidance July 14, and CISA added both CVEs to the KEV catalog with a July 17 federal deadline. No victims or attribution beyond the actor designation have been published (Volexity, Jul 17 2026 · SecurityWeek).
- Palo Alto Networks GlobalProtect (VPN gateway) → Qilin ransomware. Arctic Wolf Labs reported (July 20) multiple June-2026 intrusions in which CVE-2026-0257, an authentication-bypass flaw (CVSS 7.8) in PAN-OS GlobalProtect portals and gateways, served as the initial access vector for Qilin ransomware deployment — unauthenticated VPN sessions established via authentication-override cookies, followed by LSASS and Active Directory credential harvesting, PsExec lateral movement, ransomware staging in C:\PerfLogs\, and domain-wide encryption, with data theft and double extortion in some cases (Arctic Wolf Labs, Jul 20 2026 · BleepingComputer).
The cluster echoes the July-2025 ToolShell SharePoint wave and the 2024–25 Ivanti and Fortinet episodes: security and connectivity appliances themselves are recurring points of entry, and the most prolific ransomware group of 1H 2026 (Qilin, above) now runs edge-appliance exploitation as an initial-access motion alongside its affiliate phishing. The pattern sustains demand for exposure management and validation (03k), attack-surface reduction, and the patch-speed economics discussed in AI Security.
Why the criminal cyber economy exists
The criminal cyber economy is a rational market, driven by incentives that favor attackers:
- Asymmetric economics. An attacker needs one success; a defender must stop every attempt. Tooling (RaaS kits, IAB access) is cheap and reusable; the payoff (a single ransom or wire fraud) can be enormous. ROI is extreme.
- Low cost of entry, high specialization. The supply chain (developers, affiliates, brokers, launderers) lets low-skill actors participate by renting capability — exactly like SaaS lowered the barrier to building software.
- Cryptocurrency enabled scalable payment & laundering. Pseudonymous, borderless value transfer made monetization and cash-out viable at scale.
- Near-impunity / jurisdictional arbitrage. Many operators sit in jurisdictions that won't extradite or that tolerate (or direct) attacks on adversaries. Enforcement is slow and cross-border.
- A vast, soft attack surface. Cloud, SaaS, remote work, IoT/OT, and supply chains expand the target set faster than defenses mature.
- State sponsorship & blurred lines. Some governments run, fund, or shelter criminal groups, blending espionage, revenue, and deniable coercion (see Sovereign).
In short: demand exists because crime pays, capability is rentable, money moves anonymously, and accountability is weak. Every one of these conditions also guarantees durable, growing demand for defense — the economic engine under the entire security industry.
Red, blue, and purple teams
Because attackers hold the structural advantage described above, defenders rely on continuous testing that emulates an adversary rather than on passive controls. This is the origin of team-based security operations:
| Team | Role | Mindset |
|---|---|---|
| Red team | Offensive — simulate real attackers (pen-test, adversary emulation, social engineering) to find what actually breaks | "Think like the attacker" |
| Blue team | Defensive — detect, respond, harden; run the SOC, monitoring, IR | "Defend and recover" |
| Purple team | The feedback loop — red and blue working together so every attack technique becomes a new detection | "Attack to improve defense" |
Why they exist: real-world adversaries are the only honest test of a defense. Red teams expose gaps before criminals do; blue teams turn those findings into controls; purple teaming institutionalizes the loop. This dynamic is itself a market — it powers the offensive-security/PTaaS, BAS, and MDR sub-segments (Pentera, Cymulate, Cobalt, Synack, NetSPI, Bishop Fox — see Service Providers) and is increasingly productized into continuous, automated, and now AI-driven testing.
Why the threat economy maps to M&A demand
Every threat maps to a control the CISO must fund — the threat→control→budget logic that turns a headline breach into a board-approved line item. Acquirers read the same map forward as a deal pipeline (below). The linkages:
- Ransomware → demand for backup/recovery, EDR/XDR, MDR, cyber insurance, IR services.
- Identity-based attacks (the #1 vector) → demand for IAM, PAM, MFA, ITDR, machine identity — explaining the identity-segment M&A wave (Palo Alto–CyberArk). Sophos research published July 2026 quantifies the shift: compromised identities were the entry vector in 79% of ransomware attacks, overtaking exploited vulnerabilities, and MFA was enabled in 97% of breaches involving stolen credentials — indicating implementation gaps rather than absence of controls; 56% of attacks reached the encryption stage, and smaller organizations disrupted only 34% of attacks before encryption or extortion (SC Media, Jul 16 2026).
- Cloud attacks → demand for CNAPP/DSPM (the Wiz thesis).
- AI-enabled attacks → demand for AI security and autonomous defense (the 2026 frontier; The Agentic Edge). Threshold crossed (Jul 2026): the first documented end-to-end agentic ransomware operation. Sysdig's JADEPUFFER research (disclosed Jul 1–2 2026) documents an LLM agent that autonomously exploited an internet-facing Langflow instance (CVE-2025-3248, unauthenticated RCE), chained recon → credential theft → lateral movement → persistence, then ran a destructive database-extortion playbook — encrypting 1,300+ configuration elements, deleting originals, and dropping a Bitcoin ransom note. Telltales of machine operation: LLM-style annotated payloads, natural-language reasoning in code, and a 31-second self-correcting fix when a backdoor attempt errored. Notably, the encryption key was generated, printed once and never stored — the victim couldn't recover even by paying, i.e., competence limits, not intent, still bound the damage. Economic read: ransomware's skill barrier just collapsed — an agent chains the full kill chain without the operator being expert in any step, which expands the affiliate pool and compresses attack cost the way RaaS did in 2019–21 (Sysdig · The Register, Jul 2 2026 · The Hacker News). Defensive read-through: machine-speed offense is the demand engine for machine-speed defense (agentic SOC, autonomous patching — cf. Aikido–Root, 11).
- AI build-chain / software-supply-chain attacks → demand for package/registry integrity, provenance/SBOM, dependency governance, AI-SPM. Live proof (Jun 2026): North Korea's Sapphire Sleet (APT38/BlueNoroff) backdoored 144 npm packages in the
@mastraAI-agent framework scope in ~88 minutes via a compromised maintainer account, dropping credential/crypto-wallet-stealing malware (compromise Jun 17; Microsoft attribution Jun 19; linked to an April 2026 Axios npm attack) — the same actor logic as RaaS (rent/automate capability, monetize via crypto) now aimed at the AI developer ecosystem (Infosecurity · SecurityWeek). Read-through to the Security-for-AI pool: see AI Security.
→ Cyber insurance linkage: Ransomware economics drive the cyber-insurance market (Coalition, At-Bay, Corvus/Travelers, Resilience), which is itself consolidating and overlaps with security vendors — a deal-adjacent space to monitor.
Sensitivity note: this describes the criminal economy at a market-structure level for defensive and investment-analysis purposes only.
Updated 2026-08-16 18:13 UTC · © El Dorado Capital · el-doradocapital.com · Market intelligence for informational purposes only; not investment advice.