Technology — Cyber Threat Activity
Technology is attacked twice over: once for its own data, and once as the shortest path into everyone else's. Our log records more than 1,650 incidents across 89 countries, over 480 in the trailing 180 days, with 98 groups attributed at least one claim. Qilin (167), Cl0p (146), RansomHub (126), LockBit (110) and Akira (109) lead. Cl0p's position is the sector's defining pattern: rather than intruding one victim at a time, it has repeatedly mass-exploited a single widely deployed file transfer or managed service product and harvested every customer behind it, turning one vulnerability into hundreds of downstream victims across unrelated industries. That is why technology claims cluster in bursts rather than arriving at a steady rate. The state-sponsored interest is equally real and less visible. CISA and allied agencies attributed a sustained campaign by Russian military intelligence against Western technology companies alongside logistics firms, pursued for the access and visibility those companies hold rather than for extortion. Our graph carries 372 groups associated with the sector in total once profile-level research is counted, the second-highest of any sector here, and the malware families linked through those actors number in the hundreds. Recorded geography is the widest we hold, with the United States at 661 claims followed by Germany, Canada, the United Kingdom, India and France. The practical reading for a technology company is that its own breach is rarely the end of the incident. Source code, signing certificates, build pipelines and customer tenancy are all leverage against a customer base, and the sector's incidents should be assessed for what they enable next, not only for what was taken.
- Recorded incidents: 2,308
- Incidents, trailing 180 days: 602
- Tracked threat actors: 386
- Malware families: 414
Recent incidents
- TOWILL 2026-09-20
- Schneider’s Computing 2026-09-19
- voltgames.io 2026-09-19
- Inovapy 2026-09-18
- Stim 2026-09-18
- AT&T 2026-09-18
- ANYTHINGIT 2026-09-18
- Ascend Com 2026-09-18
- kit-e.jp 2026-09-18
- Inter (Venezuela's largest internet provider) 2026-09-18
- Quest Group 2026-09-18
- Silicon Integrated Systems 2026-09-17
- Vetta 2026-09-17
- Promantra, Inc 2026-09-17
- Techwise 2026-09-17
- sym.com.mx 2026-09-17
- xpera.ca 2026-09-17
- Invincible GG 2026-09-17
- Vigatec 2026-09-17
- Wise IT 2026-09-16
Threat actors targeting Technology
- Qilin 215 incidents
- Cl0p 160 incidents
- RansomHub 136 incidents
- Akira 127 incidents
- LockBit 120 incidents
- Play Ransomware 101 incidents
- INC Ransom 99 incidents
- The Gentlemen 74 incidents
- DragonForce 67 incidents
- SafePay 58 incidents
- KillSec 52 incidents
- Fog Ransomware 47 incidents
- Lynx Ransomware 42 incidents
- FunkSec 38 incidents
- Coinbase Cartel 37 incidents
- Hunters International 35 incidents
- Medusa Ransomware 34 incidents
- ShinyHunters 31 incidents
- Cactus 29 incidents
- NightSpire 27 incidents
- Black Basta 26 incidents
- Handala 23 incidents
- RansomHouse 21 incidents
- Nova 21 incidents
Where these victims are
- United States 740
- Germany 118
- United Kingdom 76
- Canada 75
- India 66
- Italy 62
- Taiwan 57
- France 56
- Singapore 45
- Spain 40
- Japan 39
- Brazil 34
Malware used against Technology
Families used by the threat actors that target this sector, derived from actor tooling rather than observed in these incidents directly.
- Agent Tesla Malware
- Black Basta Malware
- BlackCat Malware
- Clop Malware
- Cobalt Strike Malware
- Conti Malware
- Emotet Malware
- Impacket Tool
- Lumma Stealer Malware
- Metasploit Tool
- Mimikatz Tool
- PlugX Malware
Coverage. 94.9% of incidents in our log carry a sector classification; the remainder name a victim we have not placed in an industry. Counts here are a floor, not a total, and are not comparable between sectors of different sizes.