惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

D
DataBreaches.Net
F
Fortinet All Blogs
D
Docker
让小产品的独立变现更简单 - ezindie.com
让小产品的独立变现更简单 - ezindie.com
WordPress大学
WordPress大学
罗磊的独立博客
Y
Y Combinator Blog
Cyber Security Advisories - MS-ISAC
Cyber Security Advisories - MS-ISAC
J
Java Code Geeks
T
The Blog of Author Tim Ferriss
U
Unit 42
N
Netflix TechBlog - Medium
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
V
V2EX
云风的 BLOG
云风的 BLOG
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
T
Tailwind CSS Blog
Hugging Face - Blog
Hugging Face - Blog
Stack Overflow Blog
Stack Overflow Blog
爱范儿
爱范儿
酷 壳 – CoolShell
酷 壳 – CoolShell
P
Proofpoint News Feed
G
Google Developers Blog
H
Help Net Security

Cybersecurity Dive - Latest News

Dozens of Red Hat npm packages targeted in supply chain attack Turning tension into collaboration: How CIOs and CISOs can lead together Trump signs EO seeking early government access to powerful AI models Anthropic shares Mythos with 150 more organizations, including critical infrastructure operators Without strong governance, companies put credit ratings at risk in AI era CISA adds critical Palo Alto Networks firewall flaw to KEV as company, researchers warn of exploitation How Canva scaled to 260+M users while elevating security and productivity Top 4 data security best practices for the AI-enabled enterprise CISA urges security teams to check for software development compromises How CISOs can manage sovereign-cloud security risks IBM’s new $5B initiative will help enterprises rapidly patch open-source vulnerabilities Enterprise data is creeping its way into shadow AI tools Coordinated operation takes down Glassworm botnet Leading AI models are more vulnerable to malicious prompts than vendors claim Iranian government, not hacktivist group, breached LA Metro system, security firm says FBI warns about PhaaS platform used to access Microsoft 365 environments Iran-linked hackers target key US, allied sectors with sophisticated spear-phishing messages New York regulator calls for additional cyber mitigation amid heightened threat environment CISA asks cybersecurity community to alert it to vulnerability exploitation Grafana Labs links GitHub environment breach to TanStack npm supply chain attack 7-Eleven hit by data breach Microsoft disrupts cybercrime operation that hid behind legitimate software Compromised coding tool helped hackers breach thousands of GitHub repositories Telecom sector launches its own private ISAC Patch bypass allows hackers to exploit prior flaw in SonicWall SSL-VPN Grafana Labs says hacker gained access to codebase through leaked token How a government contest launched a revolution in AI-based bug hunting Attackers exploit critical flaw in Cisco Catalyst SD-WAN Controller MSPs need AI to fight AI-fueled cyberthreats: Guardz More money is going to physical security, but it’s often CISOs that oversee it: EY
Businesses hide vast majority of ransomware attacks, repo...
Eric Geller · 2026-05-07 · via Cybersecurity Dive - Latest News

An article from site logo

Dive Brief

The security firm BlackFog said the number of disclosed incidents it tracked in Q1 was roughly one-tenth of the number of undisclosed incidents.

Published May 7, 2026

Ransomware spelled out in a creative depiction.

Getty Images

Dive Brief:

  • Companies around the world have been keeping the vast majority of ransomware attacks secret, according to a new report from the security firm BlackFog.
  • The number of undisclosed attacks in the first quarter of 2026 was almost 10 times as large as the number of disclosed attacks, according to the report published Wednesday.
  • BlackFog’s report, based on information from dark-web leak sites, also includes data on the most targeted sectors and new tools that have emerged in the cybercrime ecosystem.

Dive Insight:

BlackFog’s threat intelligence team identified 264 publicly disclosed ransomware attacks in the first three months of 2026, but it also identified 2,160 undisclosed attacks. While the number of disclosed attacks represented a 15% year-over-year decrease, the number of undisclosed attacks ticked up slightly from Q1 2025.

The U.S. was by far hackers’ dominant target, with U.S. organizations accounting for half of all undisclosed attacks (1,070) and 61% of all disclosed attacks.

The Qilin ransomware gang was the most active group in both segments, accounting for 16% of undisclosed attacks and 8% of disclosed attacks. But the second- and third-most active groups differed between segments. A relatively new group called The Gentlemen accounted for the second-most undisclosed attacks, followed by Akira, while ShinyHunters accounted for the second-most disclosed attacks, followed by INC.

Manufacturing was the most targeted sector among undisclosed attacks, accounting for more than one-fifth of all such incidents, while healthcare was the most commonly targeted sector among disclosed attacks, accounting for 27% of those incidents. Among disclosed attacks, government organizations (12%) and information technology companies (11%) were the next most targeted. 

Virtually all (96%) disclosed attacks involved data exfiltration, BlackFog said, highlighting attackers’ focus on data theft as a source of leverage and profit.

“While the decline in total attacks may suggest incremental progress,” BlackFog researchers wrote, “the sustained volume of incidents, high rate of data exfiltration, and significant proportion of unattributed activity demonstrate that ransomware continues to evolve and pose a significant risk to organizations worldwide.”

In the first quarter of the year, hackers increasingly favor “more accessible and scalable tooling that reduces complexity and shortens the path from compromise to impact,” according to the report.

One popular tool was the Venom Stealer infostealer, which hackers delivered using the ClickFix infection technique and which BlackFog said “turns social engineering into a continuous data exfiltration pipeline.” Researchers also identified a new command-and-control framework, dubbed Lotus C2, that features ready-to-use infrastructure for managing malware and maintaining access to victim networks. “Its modular design and ease of use lower the barrier to entry for less sophisticated actors, enabling broader adoption of advanced attack capabilities,” BlackFog said.

One of the most concerning new attack surfaces is shadow AI, which has proliferated as employees race to adopt new AI tools without the necessary permissions or security measures. According to prior BlackFog research, 49% of employees use AI programs that their companies haven’t approved, 51% have connected AI tools to other platforms without approval and 58% use free AI tools that lack enterprise security protections. Six in 10 respondents also said the speed benefits of AI were worth the security risks.