Global ransomware attacks continued to climb in the second quarter of 2026, increasing by 3% to a total of 2,229 incidents, as reported by NCC Group. The Qilin ransomware group maintained its position as the most prolific threat actor. A critical finding from the report is the continued dominance of corporate **VPN**s and other edge devices as the primary initial access vector for these attacks. Threat actors are systematically exploiting vulnerabilities in widely used VPN products to bypass perimeter defenses and gain an initial foothold in target networks. This underscores the urgent need for organizations to prioritize patching and hardening of all internet-facing infrastructure.
The second quarter of 2026 saw a sustained high tempo of ransomware operations. NCC Group recorded 2,229 attacks, with 665 in June alone. The industrial sector was the most heavily impacted, accounting for 30% of all incidents, followed by consumer discretionary and information technology.
The key players in Q2 2026 were:
A new Ransomware-as-a-Service (RaaS) group named KryBit also made its debut, claiming 56 victims. Geographically, North America was the most targeted region, suffering 44% of the attacks.
The report's most actionable intelligence for defenders is the focus on edge devices as the primary initial access vector. Ransomware groups including Qilin, Akira, and The Gentlemen are actively exploiting vulnerabilities in VPN products from major vendors such as Fortinet, SonicWall, Citrix, and Check Point. This tactic aligns with the MITRE ATT&CK technique T1190 - Exploit Public-Facing Application.
By exploiting a flaw in a VPN appliance, attackers can often bypass authentication mechanisms, including MFA, and gain direct access to the internal corporate network. This corresponds to T1133 - External Remote Services. Once inside, they proceed with standard ransomware TTPs: reconnaissance, lateral movement, privilege escalation, and eventual data exfiltration (T1048 - Exfiltration Over C2 Channel) and encryption (T1486 - Data Encrypted for Impact). NCC Group noted that VPN vulnerabilities accounted for roughly 15% of its high-priority threat alerts in 2026, indicating the severity and frequency of this attack vector.
The reliance on VPNs for remote work makes their exploitation a high-impact event. A successful breach can provide an attacker with a significant foothold inside the network perimeter, effectively neutralizing a key layer of defense. For the industrial sector, this is particularly dangerous as it can lead to attackers moving from the IT network to the OT network, potentially causing disruption to physical processes, production downtime, and safety risks. The financial and reputational damage from a successful ransomware attack remains substantial.
No specific Indicators of Compromise (IOCs) were mentioned in the source articles.
Security teams should hunt for signs of VPN exploitation and compromise:
VPN Server Logs/api/v1/remediation (example for a specific CVE)w3wp.exe or httpd spawning cmd.exe or powershell.exePsExec or WMI.Aggressively patch VPNs and other internet-facing devices to close known vulnerability-based entry points.
Mapped D3FEND Techniques:
Implement MFA on all VPN connections to protect against credential theft and brute-force attacks.
Mapped D3FEND Techniques:
Isolate VPN user networks and restrict access to only necessary resources to contain the blast radius of a compromise.

Cybersecurity professional with over 10 years of specialized experience in security operations, threat intelligence, incident response, and security automation. Expertise spans SOAR/XSOAR orchestration, threat intelligence platforms, SIEM/UEBA analytics, and building cyber fusion centers. Background includes technical enablement, solution architecture for enterprise and government clients, and implementing security automation workflows across IR, TIP, and SOC use cases.
CyberNetSec.io uses automation to assist source monitoring, deduplication, observable extraction, and structured intelligence generation. Published analysis follows human-defined editorial standards and adds defensive context including MITRE ATT&CK, D3FEND, STIX, and Sigma where applicable. Read our editorial policy.
Help others stay informed about cybersecurity threats
Every tactic, technique, and sub-technique used in this threat has been identified and mapped to the MITRE ATT&CK framework for consistent, actionable threat language.
Observables and indicators of compromise (IOCs) have been extracted and cataloged. Risk has been assessed and correlated with known threat actors and historical campaigns.
Detection rules, incident response steps, and D3FEND-aligned mitigation strategies are included so your team can act on this intelligence immediately.
Structured threat data is packaged as a STIX 2.1 bundle and can be visualized as an interactive graph — relationships between actors, malware, techniques, and indicators.
Sigma detection rules are derived from the threat techniques in this article and can be converted for deployment across any major SIEM or EDR platform.