Surge in AI-enabled cybercrime and a 389% increase in ransomware

May 2026 News & Events, Information Security

Fortinet released the Global Threat Landscape Report from FortiGuard Labs. Derived exclusively from FortiGuard Labs telemetry, the latest annual report is a snapshot of the active threat landscape and trends from 2025, including a comprehensive analysis across all tactics used in cyberattacks, as outlined in the MITRE ATT&CK; framework.

The data reveals that cybercrime no longer functions as a series of isolated campaigns; it operates as a system, with malicious hackers operating across an end-to-end life cycle and compressing the attack life cycle with shadow agents.

“Cybercrime is one of the world’s most pervasive and costly threats, and our latest Global Threat Landscape Report reveals how malicious actors are beginning to leverage agentic AI to execute more sophisticated attacks. As cybercriminals increasingly use AI to bolster their tactics, cyber defenders must evolve cybersecurity operations into an industrialised defence and adopt AI-enabled tools that respond at the same velocity as modern threats,” said Derek Manky, chief security strategist and global VP of Threat Intelligence, Fortinet FortiGuard Labs.

Attack techniques and targeted sectors

Modern cybercrime crosses borders and sectors, and even traditional definitions of crime itself. As attacks grow more sophisticated and interconnected, key findings from the latest FortiGuard Labs Global Threat Landscape Report reveal:

Velocity defines risk as time-to-exploit (TTE) shrinks: As AI accelerates reconnaissance, weaponisation, and execution, FortiGuard intelligence shows that TTE is 24-48 hours for critical outbreaks, a sharp increase from earlier reports that revealed a TTE of 4.76 days. Real-world incidents reflect how minutes can define outcomes: Active exploitation attempts were made within hours of the React2Shell vulnerability public disclosure.

Ransomware victims skyrocket: FortiRecon adversary intelligence identified 7831 confirmed ransomware victims globally, up from approximately 1600 in the Fortinet 2025 Global Threat Landscape Report. The availability of crime service kits such as WormGPT, FraudGPT, and BruteForceAI contributed to this 389% year-over-year (YoY) increase. The top three targeted sectors include manufacturing (1284), business services (824), and retail (682). Geographic concentration includes the U.S. (3381), Canada (374), and Germany (291).

Identity sprawl defines cloud exposure: FortiCNAPP intelligence confirms that throughout 2025, most confirmed cloud incidents originated from stolen, exposed, or misused credentials rather than from infrastructure exploitation. Sector analysis shows hospitals/physician clinics and retail establishments as the #1 target. Large identity populations, federated access models, and complex cloud integrations make these prime targets for malicious hackers.

Inside the habits of modern, AI-enabled cybercriminals

As FortiGuard Labs Cyberthreat Predictions for 2026 projected, the most capable threat groups function as semi-autonomous enterprises, supported by shadow agents, access brokers, and botnet operators who provide services on demand. Key findings from the report show:

Shadow agents reduce operator skill requirements, while increasing workflow speed. FortiRecon dark web signals captured AI-enabled offensive tooling advertised as services and products, including enhanced versions of WormGPT and FraudGPT, and novel services like HexStrike AI, an offensive AI tool with automated reconnaissance attack path generation, and BruteForceAI, a penetration testing tool that integrates large language models (LLMs) for intelligent form analysis and can execute sophisticated multi-threaded attacks.

With AI, criminals work smarter, not harder. FortiGate IPS telemetry recorded a 22% decrease in brute-force attempts YoY, pointing to efficiency gains: With optimised, intelligent brute-force techniques, threat actors are making fewer attempts against better-selected targets, increasing the probability of success per credential tested. This activity translates to about 67,65 billion brute-force events globally, with approximately 185 million attempts per day, 1,3 billion per week, and 5,6 billion per month. At the same time, intelligence revealed a 25,49% YoY increase in global exploitation attempts.

Stolen datasets are more popular than leaked credentials. In the 2025 report, FortiGuard Labs observed a 500% increase in the number of logs available from systems compromised by infostealer malware. In 2026, FortiRecon intelligence found an additional 79% increase and revealed a shift toward theft of more comprehensive data sets, enabled by agentic AI. Within dark web “database” activity, stealer logs dominated advertised and shared datasets (67,12%), exceeding combolists (16,47%) and leaked credentials (5,96%). Stealer logs reduce attacker effort by bundling identity material with contextual artefacts, including browser-resident data, thereby enabling immediate replay and faster conversion than brute-force or password-spraying attacks.

Credential-stealer malware persists. Credential-stealer malware remains a lucrative industry and a primary upstream engine for generating exposure. FortiRecon telemetry shows stealer activity dominated by RedLine: 911 968 infections (50,80%); Lumma: 499 784 infections (27,84%); and Vidar: 236 778 infections (13,19%).

Putting awareness into action

Fortinet is committed to disrupting cybercrime by collecting and sharing threat intelligence and actively working to combat cyberthreats on a global scale.

A recent collaborative effort spearheaded by INTERPOL and supported by Fortinet through the World Economic Forum Cybercrime Atlas resulted in the takedown of a cybercriminal network. Operation Red Card 2.0 took down infrastructure and operators behind online scams, mobile money fraud, and fraudulent loan applications in Africa.

Fortinet is a founding member of the Cybercrime Atlas, a global public-private collaboration effort hosted by the World Economic Forum that uses open-source intelligence to map cybercriminal networks, identify infrastructure vulnerabilities, and support joint disruption operations with law enforcement, such as the recent Operation Red Card 2.0 and Operation Serengeti 2.0.

The 2026 Global Threat Landscape Report reveals that incentivising the disruption of cybercrime has never been more important. To empower defenders to stay ahead of cybercriminals, Fortinet and Crime Stoppers International launched the Cybercrime Bounty programme to provide a secure, anonymous channel for citizens and ethical hackers to report cyberthreats.

Download the 2026 Global Threat Landscape Report.




Share this article:
Share via emailShare via LinkedInPrint this page



Further reading:

From the editor's desk: The high price of cheap
Technews Publishing News & Events
Bringing fire and safety, along with intrusion and perimeter protection, into the same publication is an interesting exercise. At their core, all these systems exist for one reason: to warn people ...

Read more...
Southern Africa’s security leaders honoured at the 2026 OSPAs
News & Events
The winners of the 2026 Southern Africa Outstanding Security Performance Awards (OSPAs) were announced at a virtual ceremony on 23 June 2026. The winners in seven categories will progress to the third Global OSPAs in 2027.

Read more...
MPT unveils R50m customer experience centre
News & Events Power Management
Master Power Technologies has unveiled its new Customer Experience Centre, also home to its new regional headquarters in Midrand, Gauteng. The facility spans 6 000 m2 and houses approximately 200 employees.

Read more...
Duxbury Cybersecurity sharpens reseller offering
Duxbury Networking Information Security News & Events
Duxbury Networking has strengthened its Duxbury Cybersecurity business unit by adding WatchGuard and Cynet, giving South African resellers broader, more integrated coverage for the security risks customers are now asking them to address.

Read more...
Disconnect between confidence in identity security and operational reality
Access Control & Identity Management News & Events
New FIDO Alliance and HID study reveals gap between identity security confidence and reality; 94% of enterprises claim they can revoke employee access within 24 hours, yet 35% experienced delays or failures in the past two years.

Read more...
Paxton Solo training available to security installers
Paxton Access Control & Identity Management News & Events
Following the launch of Solo, Paxton’s brand-new access control system, the security manufacturer is rolling out dedicated Solo training sessions across South Africa to support security installers working with the system.

Read more...
Echoes of 2018? Follow-up on Woolworths explosions
Technews Publishing News & Events Security Services & Risk Management Retail (Industry) Facilities & Building Management
SMART Security Solutions follows up with Jimmy Roodt to find out more about an old connection to the Woolworths bombings from 2018. The investigation remains ongoing.

Read more...
Increase in cyberattacks on the manufacturing sector
Security Services & Risk Management News & Events Industrial (Industry)
According to a new Kaspersky ICS CERT report, in the first quarter of 2026, the percentage of industrial control systems (ICS) on which malicious objects were blocked reached 19,6% globally.

Read more...
Next-generation cash-in-transit vehicle
News & Events Security Services & Risk Management
Fidelity Services Group has unveiled a new, purpose-engineered Cash-in-Transit (CIT) vehicle designed to redefine crew protection, deter threats, and enhance operational resilience in an increasingly complex criminal environment.

Read more...
Sara AI Pentesting available in South Africa
Information Security News & Events
Synack and Wolfpack Information Risk are offering Sara AI Pentesting to organisations across South Africa, helping companies move from point-in-time testing to continuous security validation with AI and human expertise.

Read more...










While every effort has been made to ensure the accuracy of the information contained herein, the publisher and its agents cannot be held responsible for any errors contained, or any loss incurred as a result. Articles published do not necessarily reflect the views of the publishers. The editor reserves the right to alter or cut copy. Articles submitted are deemed to have been cleared for publication. Advertisements and company contact details are published as provided by the advertiser. Technews Publishing (Pty) Ltd cannot be held responsible for the accuracy or veracity of supplied material.




© Technews Publishing (Pty) Ltd. | All Rights Reserved.