Technology — Cyber Threat Activity
Technology is attacked twice over: once for its own data, and once as the shortest path into everyone else's. Our log records more than 1,650 incidents across 89 countries, over 480 in the trailing 180 days, with 98 groups attributed at least one claim. Qilin (167), Cl0p (146), RansomHub (126), LockBit (110) and Akira (109) lead. Cl0p's position is the sector's defining pattern: rather than intruding one victim at a time, it has repeatedly mass-exploited a single widely deployed file transfer or managed service product and harvested every customer behind it, turning one vulnerability into hundreds of downstream victims across unrelated industries. That is why technology claims cluster in bursts rather than arriving at a steady rate. The state-sponsored interest is equally real and less visible. CISA and allied agencies attributed a sustained campaign by Russian military intelligence against Western technology companies alongside logistics firms, pursued for the access and visibility those companies hold rather than for extortion. Our graph carries 372 groups associated with the sector in total once profile-level research is counted, the second-highest of any sector here, and the malware families linked through those actors number in the hundreds. Recorded geography is the widest we hold, with the United States at 661 claims followed by Germany, Canada, the United Kingdom, India and France. The practical reading for a technology company is that its own breach is rarely the end of the incident. Source code, signing certificates, build pipelines and customer tenancy are all leverage against a customer base, and the sector's incidents should be assessed for what they enable next, not only for what was taken.
- Recorded incidents: 2,280
- Incidents, trailing 180 days: 597
- Tracked threat actors: 382
- Malware families: 414
Recent incidents
- i2i-systems 2026-09-13
- watchops.com 2026-09-12
- Strad Solutions 2026-09-12
- Dustin Group 2026-09-11
- compunnel.com 2026-09-11
- M800 and CINNOX 2026-09-10
- Sys-kool 2026-09-10
- i2k2 Networks 2026-09-10
- Technology Dynamics 2026-09-09
- Logar Network Solutions 2026-09-09
- CreateASoft 2026-09-08
- GENESILICO 2026-09-07
- Chip7 2026-09-07
- G&S Technologies 2026-09-05
- MBT Telecom 2026-09-04
- Wolfram Research 2026-09-04
- teletekstructures.com 2026-09-03
- Chip 1 Exchange 2026-09-02
- Seasia Infotech 2026-09-02
- part1.simplexengg.in 2026-09-02
Threat actors targeting Technology
- Qilin 211 incidents
- Cl0p 160 incidents
- RansomHub 136 incidents
- Akira 126 incidents
- LockBit 119 incidents
- Play Ransomware 101 incidents
- INC Ransom 98 incidents
- The Gentlemen 69 incidents
- DragonForce 67 incidents
- SafePay 57 incidents
- KillSec 52 incidents
- Fog Ransomware 47 incidents
- Lynx Ransomware 42 incidents
- FunkSec 38 incidents
- Coinbase Cartel 37 incidents
- Hunters International 35 incidents
- Medusa Ransomware 34 incidents
- ShinyHunters 31 incidents
- Cactus 29 incidents
- NightSpire 27 incidents
- Black Basta 26 incidents
- Handala 23 incidents
- RansomHouse 21 incidents
- Nova 21 incidents
Where these victims are
- United States 736
- Germany 116
- United Kingdom 76
- Canada 73
- India 65
- Italy 62
- France 56
- Taiwan 55
- Singapore 43
- Spain 40
- Japan 37
- Brazil 34
Malware used against Technology
Families used by the threat actors that target this sector, derived from actor tooling rather than observed in these incidents directly.
- Agent Tesla Malware
- Black Basta Malware
- BlackCat Malware
- Clop Malware
- Cobalt Strike Malware
- Conti Malware
- Emotet Malware
- Impacket Tool
- Lumma Stealer Malware
- Metasploit Tool
- Mimikatz Tool
- PlugX Malware
Coverage. 95.3% of incidents in our log carry a sector classification; the remainder name a victim we have not placed in an industry. Counts here are a floor, not a total, and are not comparable between sectors of different sizes.