Cyber Research Unit · H1 2026 Report

Attackers spent H1 2026 moving deeper, not just breaking in.

Critical Start's Cyber Research Unit analyzed high and critical severity alerts investigated by the SOC, more than 4,472 ransomware and extortion claims, and a corpus of over 5,000 breach related news items this half. Two findings anchor the report: Manufacturing reclaimed the top targeting spot, and Execution overtook Initial Access as the leading MITRE ATT&CK tactic for the first time. This preview covers the introduction and the two most targeted industries.

27.07%
Of mapped high and critical alerts tied to Execution (TA0002), now the leading tactic
4,472
Ransomware and extortion claim entries collected across H1 2026
5
Industries concentrated the majority of observed adversary activity

How the Rankings Moved

Recent Attacks Worth Watching

Manufacturing · Ransomware
Nitrogen Group Lists Foxconn in Ransomware Claim
In May 2026, the Nitrogen ransomware group claimed roughly 8 TB of data across more than 11 million files from Foxconn, the world's largest contract electronics manufacturer. Foxconn confirmed disruption to North American operations, tied to malvertising distributing trojanized remote access tools.
Manufacturing · Supply Chain
Qilin Group Lists LISI Group on Leak Site
In March 2026, the Qilin ransomware group listed LISI Group, a French industrial component supplier to Airbus and Boeing, on its leak site. The company confirmed an incident of limited scope, reflecting how supplier tier targeting gives adversaries leverage over larger downstream customers.
Banking & Finance · Credential Attack
Stolen Credential Exposes FICOBA Bank Registry
In February 2026, French authorities confirmed roughly 1.2 million bank accounts were exposed after attackers accessed the national FICOBA registry using a stolen government credential. No malware or forced entry was involved, only a compromised login.
Banking & Finance · Data Breach
Email Compromise Exposes First Harvest Members' Data
Beginning in January 2026, an unauthorized third party accessed an employee email account at First Harvest Federal Credit Union, detected in February and concluded in April. Exposed data included names, Social Security numbers, financial account details, and payment card numbers.
You're looking at 2 of 5 top targeted industries. The full report covers Retail, Business Services, and Construction, five ransomware groups plus two spotlights, the vulnerability landscape, MITRE timeline data, two SOC AI case studies, and CRU's mitigation steps.
See the Other Three Industries,
and the Five Groups Behind Most of It
Retail, Business Services, and Construction round out the top five. Qilin, Thegentlemen, Akira, DragonForce, and INC Ransom account for the largest share of documented ransomware claims this half.
Critical Start · Cyber Research Unit · H1 2026 Cyber Threat Intelligence Report