Arete report flags ransomware shifts and rising AI use in extortion
Arete released its H1 2026 Crimeware Report on August 28, 2026, with findings on top ransomware groups, common access vectors, and tactics used by threat actors. The report says attackers are increasingly targeting third-party platforms, open-source ecosystems, and internet-facing systems while using AI to sift stolen data for extortion leverage.
Why it matters: - The report points to where ransomware and extortion risk is concentrating in 2026. - Enterprises, insurers, brokers, law firms, and financial institutions can use the findings to adjust defenses against the most common attack paths. - The report also suggests AI is becoming part of the extortion workflow, not just the intrusion phase.
What happened: - Arete released its H1 2026 Crimeware Report on August 28, 2026. - The report covers key threat groups, initial access vectors, threat actor tactics, and the growing role of AI in cyberattacks during the first half of 2026. - Arete’s global teams compiled the report from data gathered across thousands of engagements. - The company distributes the intelligence to enterprises, insurance carriers, brokers, law firms, and financial institutions.
The details: - Akira, Qilin, and INC Ransom were the top three threat groups observed in H1 2026. - Those three groups accounted for more than a third of all ransomware and extortion engagements Arete responded to. - Vulnerability exploitation remained one of the top initial access vectors. - Social engineering also stayed among the top initial access methods. - Software supply chain compromises remained a leading access path as well. - Threat actors focused more on trusted third-party platforms, open-source ecosystems, and internet-facing technologies to gain access and widen their reach. - Threat groups also appeared to use AI to analyze stolen victim data and identify high-value information for ransom demands. - Chris Martenson, Arete’s Chief Data Officer, said attackers increasingly targeted trusted third-party platforms, open-source ecosystems, and internet-facing technologies. - Martenson added that the shift raises the risk of high-impact supply chain attacks and increases the need for a dynamic, data-driven approach to cyber resilience. - Arete said it is committed to helping partners and clients with standardized, intelligence-led detection, response, resolution, and resilience capabilities. - The report is available for download as Arete’s H1 2026 Crimeware Report.
Between the lines: - The findings reinforce that attackers are not relying on a single entry point. - The mix of vulnerability exploitation, social engineering, and supply chain compromise suggests defenders need layered controls rather than a narrow focus on perimeter security. - The reported AI use in data analysis hints that extortion campaigns are becoming more targeted and more efficient.
What's next: - Organizations are likely to use the report to revisit third-party risk, internet-facing exposure, and incident response planning. - Arete is positioning its intelligence-led services as a response to faster-moving ransomware and extortion tactics. - The next shift to watch is whether AI-assisted extortion becomes more common across additional threat groups.
Disclaimer: This article was produced by AGP Wire with the assistance of artificial intelligence based on original source content and has been refined to improve clarity, structure, and readability. This content is provided on an “as is” basis. While care has been taken in its preparation, it may contain inaccuracies or omissions, and readers should consult the original source and independently verify key information where appropriate. This content is for informational purposes only and does not constitute legal, financial, investment, or other professional advice.
Sign up for:
World News Today
The daily local news briefing you can trust. Every day. Subscribe now.
Check Your Email!
We sent a one-time activation link to: .
Confirm it's you by clicking the email link.
If the email is not in your inbox, check spam or try again.
Welcome back!
is already signed up. Check your inbox for updates.