
New data from Critical Start's H1 2026 Cyber Threat Intelligence Report shows the moment of compromise is no longer where the real story is happening.
Security teams have spent years optimizing for one moment: the point where an attacker gets in. New data from Critical Start's H1 2026 Cyber Threat Intelligence Report suggests that moment is no longer where the story is happening.
The Cyber Research Unit at Critical Start analyzed alert investigations across hundreds of organizations from January through June 2026, drawing on first-party telemetry, Security Operations Center (SOC) investigations, and open-source intelligence. The finding that stands out most: Execution, not Initial Access, is now the most common tactic showing up in high- and critical-severity alerts.
Here's what that shift means, and what else the data shows about where attackers are spending their time.
For three straight reporting periods, Initial Access held the top spot among MITRE ATT&CK tactics observed in Critical Start's alert data, peaking at 40.65% of mapped activity in H1 2025. In H1 2026, that changed. Execution became the most frequently observed tactic, accounting for 27.07% of mapped activity, with Initial Access falling to 21.41% and Credential Access close behind at 18.97%.
The report is careful not to overstate what this means. It doesn't necessarily mean attackers are breaking in less often. It could reflect changes in attacker behavior, changes in how activity gets detected, or both. What it does mean is that more of what analysts see now happens after an attacker already has access: command and scripting activity, user execution, and use of built-in tools like Windows Management Instrumentation.
For security leaders, the practical takeaway is that individual alerts matter less than the relationships between them. An Execution alert may look unremarkable on its own. Considered alongside a Credential Access alert from the same environment an hour earlier, it tells a very different story. That correlation work, done at scale and in real time, is where Critical Start sees the clearest current use for AI in the SOC.
Critical Start's top five most targeted industries in H1 2026 were Manufacturing, Banking and Finance, Retail, Business Services, and Construction. The lineup is the same as H1 2025, but the order shifted: Manufacturing reclaimed the top position from Banking and Finance, and Retail rose from fifth place to third.
| Rank | Industry (H1 2026) | Change from H1 2025 |
|---|---|---|
| 1 | Manufacturing | Up from #2 |
| 2 | Banking and Finance | Down from #1 |
| 3 | Retail | Up from #5 |
| 4 | Business Services | No change |
| 5 | Construction | No change |
Manufacturing's return to the top spot tracks with factors the report calls out directly: high-availability requirements that make downtime expensive, growing overlap between operational technology and enterprise IT, and long supply-chain dependencies. In March 2026, the Qilin ransomware group listed a French industrial supplier to Airbus and Boeing among its victims, an example of exactly that dynamic.
Retail's climb reflects a similar pattern of interconnected risk: third-party dependencies, e-commerce infrastructure, and valuable payment data all in one place. And organizations outside the top five aren't necessarily in the clear. Attackers routinely gain footholds through payment processors, suppliers, and other partners rather than direct targets, which means industry rank is a poor substitute for understanding your own exposure through the vendors and partners you depend on.
The report tracked the ransomware groups responsible for the largest share of claimed victims in H1 2026:
| Ransomware Group | Share of Claimed Victims (H1 2026) |
|---|---|
| Qilin | 14.42% |
| The Gentlemen | 9.79% |
| Akira | 6.19% |
| DragonForce | 5.52% |
| INC Ransom | 5.19% |
Qilin and Akira are the only two groups that have remained among the most active across all three of Critical Start's recent reporting periods. The Gentlemen, by contrast, didn't appear in either 2025 ranking and entered directly into second place in H1 2026.
The common thread across these groups is less about sophisticated malware and more about access. Valid accounts, phishing, and exploitation of internet-facing applications remain the dominant ways in. Once inside, groups like Akira are known to create new admin accounts, move laterally, and disable defenses before deploying ransomware. None of that requires a novel exploit. It requires patience and stolen credentials.
That pattern showed up starkly in a February 2026 breach confirmed by French authorities: roughly 1.2 million bank accounts were exposed after attackers used stolen credentials to access a national account registry. No malware, no custom tooling. Just valid access.
The report's new vulnerability landscape section identifies four themes from H1 2026:
The clearest evidence of that acceleration: the average gap between a vulnerability being added to the Known Exploited Vulnerabilities catalog and attackers actively exploiting it narrowed from 120 days to 80 days. Fewer vulnerabilities are involved overall, but the ones attackers do use are moving from disclosure to active exploitation much faster than most organizations can patch.
The report's recommendation here is direct: a high CVSS score doesn't automatically mean a vulnerability is a priority for your environment. Exploitability and business context matter as much as severity.
Critical Start's report includes a real example of SOC AI in action, its AI capability built to support, not replace, human analysts. In one incident, a ClickFix-style attack against an energy and utilities customer used a steganography loader, malicious code hidden inside image pixel data, to try to deliver a second-stage payload.
The investigating analyst had never seen this specific technique in the wild. SOC AI decoded the obfuscated command chain, identified the steganography technique in plain language, and drafted the initial escalation write-up. The analyst reviewed the findings, applied judgment, and made the final call to isolate the host.
That division of labor, AI accelerating investigation and correlation, humans retaining the decision, is central to how Critical Start approaches AI in the SOC. The report notes a deliberate, deterministic-first design choice: AI agents that behave predictably and stay explainable, rather than fully autonomous systems making unreviewed calls in a domain where mistakes carry real consequences.
A few practical implications follow from the data:
Alert volume has been trending down since H1 2023. That's a sign of better detection tuning, not a sign that risk is declining. The shift toward Execution and away from Initial Access means the alerts that remain carry more information about what's already happening inside an environment, if teams have the visibility and correlation to read them.
This post covers a fraction of the findings in Critical Start's H1 2026 Cyber Threat Intelligence Report, including the full industry breakdowns, ransomware group profiles, and vulnerability data referenced above.
Download the full H1 2026 Cyber Threat Intelligence Report →© 2026 Critical Start. All rights reserved.
