Fortinet has released the 2026 Global Threat Landscape Report. Based on telemetry data from FortiGuard Labs, this latest annual report provides an overview of the current threat landscape and observed trends, especially ransomware, including a comprehensive analysis of all tactics used in cyberattacks, as described in the MITER ATT&CK framework.
The data reveals that cybercrime no longer functions as a series of isolated campaigns, but rather operates as a system, with malicious hackers acting throughout the entire life cycle and shortening the time needed to carry out attacks using shadow agents.
“Cybercrime is one of the world’s most widespread and costly threats, and our latest Global Threat Landscape Report reveals how malicious actors are beginning to leverage agentic AI to execute more sophisticated attacks. As cybercriminals increasingly use AI to bolster their tactics, defenders must evolve cybersecurity operations toward industrialized defense and adopt AI-based tools that respond at the same speed as modern threats,” said Derek Manky, Chief Security Strategist and Vice President of Global Threat Intelligence at Fortinet’s FortiGuard Labs.
Attack techniques and most affected sectors
Cybercrime crosses borders and industries, going beyond the traditional definition of crime. With attacks becoming more sophisticated and more interconnected; FortiGuard Labs’ latest Global Threat Landscape Report reveals:
- Speed determines risk as TTE decreases: With AI accelerating reconnaissance, weaponization, and execution, FortiGuard intelligence shows the TTE to be 24 to 48 hours for critical attacks, a sharp increase from previous reports that showed a TTE of 4.76 days. Actual incidents reflect how a few minutes can determine the results: active exploitation attempts occurred within hours of the public disclosure of the React2Shell vulnerability.
- Ransomware victim numbers skyrocket: FortiRecon intelligence identified 7,831 confirmed ransomware victims globally, a sharp increase from the approximately 1,600 victims identified in the Fortinet 2025 Global Threat Landscape Report. The availability of crime service kits such as WormGPT, FraudGPT, and BruteForceAI contributed to this 389% year-over-year increase (YoY). The three most affected sectors are manufacturing (1,284), business services (824) and retail (682). Geographic concentration includes the US (3,381), Canada (374), and Germany (291).
- Identity proliferation defines cloud exposure: FortiCNAPP data indicates that throughout 2025, the majority of confirmed cloud incidents were due to credential theft, exposure or misuse, rather than infrastructure exploitation. The sector analysis points to hospitals and medical centers, as well as the retail sector, as the main targets. Large numbers of users, federated access models, and complex cloud integrations make these environments prime targets for hackers.
Habits of Modern Cybercriminals, Powered by AI As FortiGuard Labs predicted in its 2026 Cyber Threat Predictions, the most effective threat groups operate as semi-autonomous enterprises, supported by shadow actors, gateway brokers, and botnet operators that provide on-demand services. Key findings from the 2026 Global Threat Landscape Report reveal:
- Shadow agents reduce user skill requirements and increase the speed of workflows. Dark web signals captured by FortiRecon detected offensive AI-based tools advertised as services and products, including enhanced versions of WormGPT and FraudGPT, and novel services such as HexStrike AI, an offensive AI tool with automated attack path recognition generation; and BruteForceAI, a penetration testing tool that integrates large language models (LLMs) for intelligent form analysis and can execute sophisticated multithreaded attacks.
- With AI, criminals work smarter, not harder. FortiGate IPS telemetry recorded a 22% year-over-year decrease in brute force attempts, pointing to greater efficiency: with optimized and intelligent brute force techniques, malicious actors make fewer attempts against better-selected targets, increasing the probability of success per credential tested. This activity translates into approximately 67.65 billion brute force events worldwide, with approximately 185 million attempts per day; 1.3 billion attempts per week; and 5.6 billion attempts per month. At the same time, a 25.49% year-on-year increase in exploitation attempts worldwide is revealed.
- Data set theft is more common than credential leaks. In the previous report, FortiGuard Labs saw a 500% increase in available logs from systems compromised by data-stealing malware. In 2026, FortiRecon data reveals a further increase of 79% and highlights a trend towards the theft of more complete data sets, facilitated by agent-based AI. Within dark web “database” activity, what is most advertised and shared are data theft records (67.12%), surpassing combined lists (16.47%) and leaked credentials (5.96%). Data theft logs reduce attacker effort by bundling identity information with contextual elements, including browser data, enabling immediate replay and faster conversion than brute force attack or password spraying.
- Credential-stealing malware persists. Credential theft malware remains a lucrative industry and the leading driver of exposures. FortiRecon telemetry shows that thief activity has been dominated by RedLine: 911,968 infections (50.80%); Lumma: 499,784 (27.84%); and Vidar: 236,778 (13.19%).
Dismantling cybercrime ecosystems
Fortinet is committed to combating cybercrime by collecting and sharing threat information, and actively working to address cyber threats on a global scale.
A recent collaborative initiative led by INTERPOL and supported by Fortinet through the World Economic Forum’s Cybercrime Atlas has resulted in the dismantling of a cybercriminal network. Operation Red Card 2.0 dismantled the infrastructure and arrested operators responsible for online scams, e-money fraud and fraudulent loan applications in Africa.
Credential-stealing malware remains a lucrative industry and the leading driver of exposures
Fortinet is a founding member of the Cybercrime Atlas, a global public-private collaboration initiative sponsored by the World Economic Forum that uses open source intelligence to map cybercriminal networks, identify vulnerabilities in infrastructure and support joint takedown operations in collaboration with law enforcement, such as the recent Operations Red Card 2.0 and Serengeti 2.0.
The 2026 Global Threat Landscape Report reveals that incentivizing the disruption of cybercrime has never been more important. To empower defenders to stay ahead of cybercriminals, Fortinet and Crime Stoppers International have launched the Cybercrime Bounty program, which provides a secure, anonymous channel for citizens and ethical hackers to submit information about cyber threats.
