Increasingly, threat actors do not need to discover a new vulnerability or develop sophisticated malware to gain access to corporate environments.
In the CyOps ECHO Report 1H 2026, the CyOps team summarized findings from 304 incidents, supplementing them with external cyber threat intelligence. The report examines the primary initial-access paths, changes in the ransomware market, software supply chain risks, the impact of AI on the pace of threat development, and other key trends.
Below are the main findings from the report that illustrate how modern attacks are evolving. You can download the full report here.
Attackers Are Increasingly Abusing Existing Access Mechanisms Instead of Breaking Security Controls
One of the report’s most important findings is the continued shift away from exploited code and toward abused identity, access gateways, and trusted tools. In host-breach cases with a confirmed root cause, the initial foothold most often came from stolen or socially engineered identity rather than appliance-CVE exploitation.
incidents handled by CyOps in 1H 2026
~1,6:1
identity cases vs. host-breach cases
of host breaches entered via SSL-VPN
8 in 10
host breaches began with stolen identity
CyOps identifies three dominant initial access categories during the period:
- social engineering, particularly Microsoft Teams vishing;
- compromised credentials used for SSL-VPN and identity access;
- trusted tool and supply chain abuse.
Once access was established, however, the post access playbooks were remarkably similar. Living-off-the-land tools such as nltest, net.exe, and Advanced IP Scanner were used for reconnaissance. RDP from the VPN-internal subnet was the dominant lateral-movement mode. PowerShell appeared in most host-breach cases handled by CyOps.
Ransomware: Public Figures Show Only Part of the True Scale
The ransomware ecosystem in 1H 2026 remained consolidated at the top while also being crowded with a large number of smaller groups.
According to RansomLook tracked public leak site data, 4,180 claimed victim postings were recorded between January 1 and June 30, 2026. Approximately 65% of all postings were attributed to the ten largest groups.
Qilin led the period with 648 claimed postings, followed by The Gentlemen with 467 and Akira with 299.
Importantly, these figures represent adversary controlled public claims rather than independently verified victim counts. Organizations that paid, negotiated privately, or were never publicly posted on data leak sites may not appear in these statistics.
However, Cynet’s assessment, informed by analysis of open-source CTI, suggests that the gap between “posted” and “compromised” victims is considerably wider than leak site statistics alone would indicate. Analysis associated with The Gentlemen disclosure, for example, pointed to a substantially larger actual victim population than the publicly posted total.
RaaS Is Becoming More Accessible
Cynet highlights four shifts that are lowering the barrier to participation in top-tier Ransomware-as-a-Service (RaaS) operations:
- criminal-marketplace partnerships;
- insider recruitment at scale;
- AI-assisted tooling;
- better financial splits for affiliates.
Trusted Tools Became Weapons
Cynet observed attacks in which threat actors relied on the same remote support and system tools routinely used by IT teams rather than deploying purpose-built malware.
Tools observed in 1H 2026 cases included ScreenConnect, AnyDesk, Quick Assist, RemSupp, and Bomgar.
BYOVD (Bring Your Own Vulnerable Driver)
Bring Your Own Vulnerable Driver (BYOVD) was attempted in several of the most severe host-breach cases investigated by CyOps. Drivers mentioned in the report include poisonX3.sys, UnknownKiller.sys, and bdapiutil64.sys.
BYOVD has shifted from a rare and sophisticated technique to a reusable, repeatable stage that ransomware operators build into standard playbooks. First, they gain hands-on-keyboard access; they then stage a signed-but-vulnerable driver, load it through a newly created Windows service, and use the resulting kernel-level capabilities to blind and disable security tooling before deploying ransomware.
The Software Supply Chain Now Includes More Than Just Code – It Also Includes Everyday IT Tools
Software supply chain risk is no longer limited to npm/PyPI packages or build pipelines. It also includes the everyday open-source utilities that IT teams download from the open web and deploy into corporate environments.
One example involved a European defense contractor. Its IT help desk downloaded and deployed an open-source media-player installer that silently sideloaded an unauthorized ScreenConnect client and a renamed DLL. The ScreenConnect agent remained dormant for six weeks before an external operator used it to deploy a series of VBScripts followed by a heavily obfuscated PowerShell loader.
CyOps is also observing how AI coding tools are widening the attack surface. AI coding agents and automated build systems can install or update dependencies faster than a human can assess the associated risk. As a result, a compromised dependency may execute, harvest credentials, and spread through CI/CD before anyone notices.
Cynet’s Outlook for the Second Half of 2026
1. Identity-Led Intrusions Will Remain the Default
CyOps expects the share of attacks beginning with identity compromise to continue growing. Cynet points to Microsoft Teams help-desk impersonation, AiTM token theft, and SSL-VPN credential replay as three manifestations of the same broader trend.
2. Protecting the Network Edge Will Increasingly Depend on Protecting Credentials
In CyOps investigations, SSL-VPN intrusions primarily began with valid stolen credentials rather than appliance-CVE exploitation. Cynet expects this trend to continue: initial-access brokers will play an increasingly important role, while stolen VPN and identity credentials will remain valuable inventory. As a result, the defensive focus is expected to shift from patch cadence alone toward comprehensive credential-lifecycle management.
3. Ransomware Brands Will Change, but Their Methods Will Persist
Cynet expects continued rotation among leading ransomware operators. Qilin, The Gentlemen, Akira, LockBit 5.0, and other groups may gain or lose prominence, while new brands continue to emerge. At the same time, the underlying affiliate base and the tactics, techniques, and procedures used by these operations are expected to remain far more stable. Defenders should therefore plan around intrusion patterns and attacker behavior rather than focusing only on whichever ransomware brand currently leads the rankings.
4. AI Acceleration Will Outpace Remediation
Cynet expects AI to help attackers discover and weaponize vulnerabilities more quickly. At the same time, vulnerability identification, prioritization, and remediation in many organizations will continue to operate largely at a human pace. As a result, CyOps expects the gap between AI-driven discovery and human-paced remediation to widen throughout 2H 2026.
Download the Full CyOps ECHO Report 1H 2026
This overview covers only a portion of CyOps’ findings. Download the CyOps ECHO Report 1H 2026 to explore detailed attack paths, anonymized real-world case studies, threat-detection recommendations, and the measures Cynet recommends organizations implement now.







