Intel471-Logo-white.png

Intel 471: 2026 Cyber Threat Trends & Outlook

Our latest annual report is here. Explore our comprehensive assessment of 2025’s cyber threat landscape and a forward-looking view of what these developments signal for defenders in 2026. Use these insights prioritize monitoring and collections, align hunting to the techniques that surfaced rapidly.


Key Findings — 2025 at a Glance:

  • AI is an accelerator, not the engine: AI is boosting adversary efficiency — but it’s not the core driver of profit-motivated operations.
  • Forum gravity shifted: The DarkForums cybercrime forum emerged as the primary choice for English-speaking threat actors in 2025.
  • Key ransomware-as-a-service groups: Qilin emerged as the most dominant force in the market.
  • Extortion at an all time high: Supply chain attacks drove extortion figures up by 63% from last year, continuing an upward trend that began in 2022.
  • IAB activity declined: Although a commodity on the underground, we observed a 27% decrease in claims compared to 2024, but an increase in new entrants
  • Top stealers by downloads: Three information stealers dominated downloads this year: Lumma, Stealc and Vidar strains.
  • Weaponized CVEs: We reported over 500 vulnerabilities and 80% of these either were weaponized or productized.
  • Hacktivism disruption and noise: We tracked 700+ hacktivist responses in the cybercrime underground, of which over 80% were driven by propaganda and DDoS attacks,

Head Into the Year with Clarity

Download the 2026 Cyber Threat Trends & Outlook Report to prioritize the threats, techniques and underground dynamics most likely to shape 2026.

Note: This report is a redacted version of one released to Intel 471 customers on Dec. 23, 2025. It draws on information collected January 1-December 15, 2025. For full access, including links to related reporting on Verity471, Intel 471’s cyber intelligence platform, and sensitive source-derived details, contact us at sales@intel471.com