Report by Cognyte

2026 Threat Landscape Report

13 FINDINGSPublished Apr 21, 2026
View Original Report →

Key Findings

In 2025, AI enabled attackers to automate up to 80–90% of a specific nation-state espionage campaign.

AINation State

In 2025, cybercriminal groups led threat activity in North America with 52%.

Threat ActorsNorth America

In 2025, ransomware groups claimed 7,809 victims, a 27.3% year-over-year increase.

Ransomware

In 2025, the U.S. accounted for roughly one-third of global ransomware incidents.

RansomwareUS

In 2025, the Linux Kernel recorded 2,257 reported vulnerabilities, the highest number among projects.

VulnerabilitiesLinux

In 2025, the Lumma infostealer was responsible for 2.2 million dark web listings, roughly 42% of the total.

InfostealerDark Web

In 2025, the Qilin group was responsible for 12.8% of ransomware attacks.

RansomwareThreat ActorsQilin

In 2025, nation-state activity accounted for 56.6% of threat activity in the Middle East.

Nation StateMiddle East

In 2025, stolen credentials were linked to 22% of data breaches.

Stolen CredentialsData Breach

In 2025, nation-state activity accounted for 67% of threat activity in APAC.

Nation StateAPAC

In 2025, AI generated 82.6% of phishing content.

AIPhishing

In 2025, nearly 50,000 new vulnerabilities were disclosed with an average CVSS score of 6.6.

VulnerabilitiesCVSS

In 2025, total ransomware payments fell 23%.

RansomwareFinancial Impact