Archive for Check Point

The Check Point Q2 2026 Ransomware Report Is Out

Posted in Commentary with tags on August 13, 2026 by itnerd

Ransomware kept its grip on organizations through the second quarter of 2026, and the headline number barely moved. What changed underneath that number is more interesting: new research gave us a rare look inside a top tier operation as it was being built, and it revealed just how little it now takes for a small and skilled group to reach the top of the field. Here’s what the quarter actually showed, and what it means for how you defend against it. 

Key takeaways 
  • Data leak sites recorded 2,139 ransomware victims in Q2 2026, essentially flat versus Q1 and up 33% year over year
  • The top 10 groups still controlled 57.6% of all victims, but the number of active groups jumped from 71 to 93, a new high
  • Leaked chats from The Gentlemen ransomware operation showed how a core team of roughly nine people, aided by AI coding tools, built a top three global operation in a matter of months
  • Ransom payment rates fell to about 23%, yet on chain ransomware payments still topped $820 million in 2025, pushing operators toward data theft over encryption
  • Defending against this shift means treating initial access, exfiltration, and exposure reduction as equally urgent
What actually happened in Q2 2026? 

Data leak sites, where ransomware groups publish victims who refuse to pay, logged 2,139 victims in Q2, essentially flat against Q1 and up 33% year over year. The ecosystem is holding at the elevated baseline it settled into through 2025. 

What shifted is who’s doing the attacking. In Q1, the top 10 groups controlled 71% of victims across just 71 active groups, a tight, top heavy market. By Q2, that eased to 57.6%, and active groups climbed to 93, the highest on record. Cl0p, whose Oracle E-Business Suite campaign drove much of Q1’s numbers, nearly vanished, and a wider mid tier filled the gap. Qilin held the top spot for a fourth straight quarter with 279 victims, narrowly ahead of The Gentlemen, which grew 62% and outpaced Qilin in June. 

Figure 1 – Total Number of Reported Ransomware Victims in data leakage websites, per month
(June 2024 – June 2026)

Figure 2 – Top-10 share and active group count, Q2 2026

What did the leaked Gentlemen chat logs actually reveal? 

A leak of The Gentlemen’s own backend and chat history, giving researchers a rare inside view of a top tier operation. The core team was just nine people, running a 90/10 split with a broader affiliate base that carried out most of the intrusion work, the highest cut advertised in the market. 

The detail worth remembering: the group’s admin, Zeta88, built the operation’s ransomware management panel in about three days using AI coding assistants, with a candid admission that the tools still require someone who understands the code well enough to guide and correct it. That’s genuine evidence AI is speeding up how ransomware tooling gets built, though its use here was about writing software faster, not running operations or picking targets. The bigger signal: the barriers to building a serious ransomware business have narrowed enough that one experienced operator can reach the top tier in months. 

Figure 3 – The Gentlemen monthly victim trajectory, Sep 2025 – Jun 2026

Why does data theft matter more than encryption right now? 

Payment rates have fallen for six straight years, from 85% in 2019 to roughly 23% today, largely because backups have gotten better at neutralizing encryption. Backups don’t help against data theft, though. If files are already stolen and about to be published, restoring systems doesn’t stop the leak, which is why operators are leaning into exfiltration first extortion. Total dollars paid haven’t followed payment rates down: on chain payments still exceeded $820 million in 2025. 

Law enforcement spent the quarter chasing shared infrastructure rather than individual groups, dismantling a laundering platform, sanctioning exchanges tied to ransomware actors, and taking down a malware signing service and major infostealer networks. None of that shows up as a drop in Q2’s victim count, and seized infrastructure tends to get rebuilt elsewhere, but raising the cost of laundering, signing, and credential harvesting adds friction that compounds over time. 

What should defenders actually prioritize? 

A few things fall out of the quarter’s data. Initial access remains the fight that matters most: The Gentlemen’s own pipeline ran on VPN scanning, brute forcing, and brokered credentials, the same route used across most of the ecosystem, so phishing and exposed remote access deserve defense in proportion to how often they’re the opening move. Exfiltration detection now deserves the same weight backup and recovery has traditionally received, and remediation speed matters more too, since the gap between disclosure and exploitation is now measured in hours. Defenses still running on a human review cycle are working against AI assisted tooling that no longer waits for one. 

How does Check Point address what this Ransomware quarter found? 

Most of what this report documents starts with a person, usually through phishing or stolen credentials feeding the same pipeline The Gentlemen relied on. Workspace Security protects users across email, browsers, SaaS applications, and endpoints, using AI driven detection to stop ransomware delivery before execution and limit lateral movement and exfiltration after a compromise. 

Hybrid Mesh Network Security applies consistent, AI driven controls at every connectivity point, from firewalls that block malicious files before they reach devices to CASB scanning that catches malware entering through SaaS platforms like OneDrive and Slack, a route access brokers increasingly favor. If a compromise happens anyway, Zero Trust access through SASE Private Access limits the blast radius so ransomware can only reach what the compromised user was authorized to touch. 

Exposure Management answers the harder question of which vulnerabilities ransomware groups can actually reach and use, not just which ones exist. Check Point’s 2026 Exposure Gap Report found vulnerabilities now make up 42.6% of critical exposures, more than double the year before, and that they can realistically be closed in under an hour, with utilities sector organizations using the platform resolving 30% of theirs within that window. 

AI Security addresses the same tooling ransomware groups are learning to use. ThreatCloud AI keeps protection moving on the same accelerated timeline as AI assisted exploitation, AI Agent Security governs the agent permissions that let an admin like Zeta88 build tooling in days, AI Red Teaming tests an organization’s own AI applications before deployment, and Workforce AI Security stops credentials and data from leaking through the AI tools employees already use. 

July 2026 Cyber Threats Surge: Ransomware Attacks Double Year over Year as GenAI Data Exposure Widens Says Check Point

Posted in Commentary with tags on August 13, 2026 by itnerd

July’s cyber threat landscape was shaped by pressure across multiple fronts. Global cyber attacks continued to rise, ransomware activity broke from the more stable pattern seen earlier in the year, and GenAI exposure became a clearer operational risk as employees used more tools and generated more prompts across the enterprise.

Cyber Attacks Keep Climbing

The global attack curve continued upward in July. Organizations faced an average of 2,336 weekly cyber attacks, up 3% from June and 16% from July 2025. While the monthly rise was more moderate than June’s rebound, the broader trend remains clear: average weekly attacks per organization have increased by 13.7% since May, signaling sustained pressure rather than a temporary spike.

Education Remains the Top Target

Education remained the most targeted sector, averaging 4,848 weekly attacks per organization, up 14% year over year. Government ranked second with 3,044 weekly attacks, up 11%, followed by Telecommunications at 2,927, up 6%. Energy and Utilities moved into fourth place with 2,759 weekly attacks, up 20%, while Hospitality, Travel and Recreation entered the top five with 2,614 attacks, up 28%, possibly reflecting higher exposure during the summer travel period.

Latin America Leads in Volume as Europe Sees a Sharp Rise

Regionally, Latin America continued to face the highest attack volume, with 3,561 weekly attacks per organization on average, up 19% from July 2025. APAC followed with 3,316 weekly attacks, while Africa ranked third despite a 5% year-over-year decline. Europe stood out for its growth rate, with attacks up 18% year over year, while North America rose 9%.

GenAI Risk Moves from Theory to Daily Business Reality

GenAI risk is becoming a daily business issue. The main concern is not only how AI tools are used, but what employees enter into them, from customer records and internal documents to infrastructure, legal, financial, or HR information. July’s data shows how quickly that exposure can scale:

  • 1 in every 36 prompts from enterprise networks carried a high risk of sensitive data leakage
  • 88% of regular GenAI-using organizations were affected by high-risk prompt activity
  • 22% of prompts contained potentially sensitive information.
  • Organizations used an average of 8 GenAI tools, while the average user generated 95 prompts during the month

This makes GenAI both a governance and security issue, especially as adoption moves faster than policies, training, and controls. Exposure was highest in Latin America and North America, while Europe and APAC were slightly below the global average. By industry, Business Services and Healthcare and Medical recorded the highest risk, followed by Information Technology and Government.

The type of information being exposed is also important. Personal data remained the most common sensitive category, appearing in 70% of organizations. Financial Data and Network and IT Infrastructure followed at 68% each, while Legal and Regulatory content appeared in 63% and Employee and HR data in 62%. The issue is not limited to one team, use case, or document type. It cuts across the core information organizations rely on every day.

Email Remains a Key Entry Point for Cyber Risk

Despite growing focus on newer attack surfaces, email remained a high-volume risk channel in July. One in every 128 emails, or 0.78%, was classified as phishing, while another 20% fell into unwanted or risky categories such as graymail, spam, and suspicious messages, adding to the daily burden security teams need to filter and investigate.

Africa recorded the highest phishing rate, with one in every 106 emails classified as phishing, followed by North America at one in every 117. Beyond the regional differences, the trend reinforces email’s role as a common starting point for broader attack chains, from credential theft and malware delivery to business email compromise. In July, that escalation was most visible in ransomware activity.

Ransomware Breaks the Pattern

* This ransomware data draws from ransomware “shame sites” operated by double-extortion groups, which publicly disclose victim information. While these sources have inherent biases, they provide valuable insight into the ransomware landscape.

The clearest shift in July came from ransomware. Reported attacks reached 964, up 87% from July 2025 and 49% from June. This marked a decisive break from the first half of 2026, when monthly ransomware activity averaged around 672 incidents.

The increase was broad, touching multiple regions and industries, but Business Services remained the most affected sector, accounting for almost one third of reported victims.

North America remained the most affected region, accounting for 45% of reported ransomware incidents. Europe followed at 28%, while APAC accounted for 17%.

At country level, the United States continued to dominate the victim count with 39.4% of reported attacks, followed by Germany, Canada, the United Kingdom, and Italy.

The Gentlemen and Qilin Lead as the Ransomware Landscape Shifts

The Gentlemen and Qilin were the most prevalent ransomware groups in July, each responsible for 14% of published attacks. DeadLock climbed to the top three, with 10% and 97 reported victims.

  • The Gentlemen: A fast-growing Ransomware-as-a-Service operation launched in mid-2025. The group combines ransomware operations with initial access brokering, helping it scale quickly in a short period of time.
  • Qilin: An established Ransomware-as-a-Service group with victim disclosures dating back to 2022. Its mature affiliate model and renewed recruitment activity have helped it increase victim listings and regain momentum.
  • DeadLock: A group first observed in July 2025. It has gained attention for using blockchain-based techniques to rotate command-and-control proxy addresses, alongside the use of legitimate remote management tools.

What July Tells Us

July’s threat landscape was defined by accumulation rather than a single dominant risk. Global attacks kept rising, ransomware accelerated sharply, and GenAI exposure became more visible as part of routine business activity. For security teams, the message is clear: prevention cannot be limited to one layer or one threat category. Organizations need coordinated protection across network, cloud, endpoint, email, and AI usage, supported by the visibility to understand where sensitive data and attacker activity are moving next.

Check Point Revolutionizes the Firewall Market: New AI Network Firewall Closes the Network’s AI Blind Spot — Everywhere 

Posted in Commentary with tags on July 30, 2026 by itnerd

Check Point Software Technologies Ltd. (NASDAQ: CHKP), a pioneer and global leader of cyber security solutions, today announced the Check Point AI Network Firewall, delivered as part of Check Point firewall software release R82.20. AI has introduced a new class of network traffic — prompts, autonomous agent actions, and sensitive business context — that traditional firewalls were never designed to see or secure. The AI Network Firewall closes that gap from the Check Point firewall organizations already run, delivered through Check Point’s AI Defense Plane with no new infrastructure and no rearchitecting. 

The exposure is already universal. Check Point Research’s AI Security Report 2026 found that between 87% and 93% of organizations experience at least one high-risk generative-AI interaction every month and the share of prompts carrying sensitive corporate, personal, or regulated data doubled in a year to one in every 25 interactions. Organizations are adopting AI faster than they can govern it, and the activity that needs governing is already moving across the network. 

Turning existing firewalls into immediate AI protection 

Unlike alternatives that require a separate virtual firewall deployed alongside existing infrastructure, Check Point delivers this protection directly from the physical or virtual firewalls customers already operate and scales across branches, data centers, cloud, and multi-cloud environments. For Check Point firewall customers, the AI Network Firewall turns existing firewall investments into immediate AI protection across three domains: 

  • Employee AI use: Discover AI apps, agents, and tools in use — both shadow and sanctioned — gain visibility into how AI is being used and prompt use-cases and intents, govern access to safe and sanctioned tools, and stop sensitive data from leaving the network based on the prompt’s use case. Check Point Research found organizations now run an average of ten AI applications per month, many outside any formal process 
  • AI Tools (MCP): Discover Model Context Protocol (MCP) communication, gain full visibility into servers and used tools, and enforce policies to control access across every interaction. Check Point Research found security weaknesses in 40% of 10,000 MCP servers reviewed 
  • AI Application and LLM: Prevent prompt injection and adversarial inputs, blocking malicious prompts before they reach the LLM. This happens inline, with no application changes required. Check Point Research identified 15,300 indirect-injection payloads planted in public web pages, roughly 70% of them hidden in parts of the page no human ever sees 

Part of the AI Defense Plane: one architecture across the enterprise 

The AI Network Firewall becomes part of Check Point’s AI Defense Plane, a unified control plane for discovering, governing, and protecting AI across the network, endpoints, cloud, applications, and APIs. Together, the AI Defense Plane delivers: 

  • Discovery, governance, and protection for AI across web, desktop, coding assistants, and AI agents 
  • Local AI agent discovery and control 
  • SaaS AI agent discovery and control 
  • Runtime protection and governance for AI applications 
  • Risk detection and guardrails to protect homegrown and deployed AI 

Additional enforcement points across the AI Defense Plane span standalone API for self-managed applications, endpoint for employees, containerized firewall for AI data centers, and WAF – giving organizations consistent AI security across public and private clouds, branch offices, remote users, and data centers. 

Unified, agentic management across a hybrid, multi-vendor environment 

Following the recent announcement of its agentic network security orchestration platform, Check Point is also extending central policy management to Check Point SASE and SD-WAN, with dynamic, always-accurate zero-trust policy enforcement across IT, OT, and micro-segmentation tools including Illumio and others: 

  • One console manages on-premises firewalls, cloud firewalls, AWS native firewalls, SD-WAN, and SASE with consistent policy and a unified audit trail across every environment 
  • SD-WAN connectivity and security policy are managed together, ending the operational split that forces teams to juggle separate tools 
  • Open-platform integrations keep firewall rules current as the environment changes, without manual reconciliation  

Check Point AI Network Firewall is available now. Learn more here

Check Point zero-day highlights identity control shortfalls

Posted in Commentary with tags on July 27, 2026 by itnerd

With Check Point warning that attackers are actively exploiting the critical SmartConsole authentication bypass flaw (CVE-2026-16232) to obtain full administrative privileges, this is another reminder that security infrastructure itself has become a prime target. 

The vulnerability has already been exploited in the wild, prompting emergency patch guidance and inclusion in CISA’s Known Exploited Vulnerabilities catalog which can be found here..

Bojan Simic, CEO and co-founder, HYPR had this to say:

“Authentication bypass flaws like this happen when systems treat the token as the proof of identity instead of verifying what actually produced it. If an attacker can trick the application into issuing a token without a legitimate authentication event, that token becomes nothing more than a bearer credential. Whoever possesses it gets access, regardless of how it was obtained.

Passkeys fundamentally change that model. The private key never leaves the user’s device, so there is no shared secret, password hash, or reusable credential traveling across the network for an attacker to steal, replay, or manipulate into creating a valid session. By eliminating passwords and other static credentials, phishing-resistant authentication dramatically reduces the attack surface these flaws depend on.

However, authentication can’t stop at verifying the device. Organizations also need to verify the person behind it, particularly when granting privileged access or stepping up an administrative session. Device-bound cryptography establishes trust in the device; identity verification at high-risk moments establishes trust in the human. You need both to close the gap between someone possessing the right device and someone actually authorized to use it.”

It’s once again time to patch all the things. But this time the urgency is clear. Though it would make life a whole lot easer if flaws like this didn’t exist.

Guest Post: What Is Brand Phishing and Why Does It Work?

Posted in Commentary with tags on July 23, 2026 by itnerd

Brand phishing is when a scammer impersonates a trusted, well known company, through email, a fake website, or both, in order to steal login credentials, payment details, or personal information. It works because trust is transferable. If a message looks like it came from a brand you already use and rely on, your guard drops. You’re not evaluating a stranger’s request. You’re responding to what feels like routine correspondence from a company you already have a relationship with. That single psychological shortcut is the entire business model behind brand phishing.

Which Brand Was Impersonated Most in Q2 2026?

Microsoft, by a wide margin. In Q2 2026, Microsoft remained the most impersonated brand in phishing attacks, accounting for 23% of all brand impersonation attempts, nearly double the next closest brand. Here’s how the full top ten broke down.

Together, the top five brand names cover more than half of all brand phishing activity this quarter. That concentration is worth sitting with. Scammers aren’t spreading their efforts across thousands of brands. They’re focused on a small set of names that nearly everyone recognizes and uses daily, since that recognition is what makes the con work in the first place.

Why Did ChatGPT Suddenly Join the Top Ten?

For the first time, the ChatGPT appeared among the ten most impersonated brands tracked in this report. It’s a strong signal of where attacker attention is heading next. As AI tools move from novelty to daily habit for millions of people managing subscriptions, payments, and work tasks through them, they become just as attractive a target as any bank or tech giant. One example from June involved a fake ChatGPT Plus billing email, built to look exactly like an OpenAI payment failure notice, that led to a page designed to harvest full credit card details. Expect AI platforms to keep climbing this list in future quarters.

Which Industries Get Targeted Most?

Technology led as the most impersonated sector overall, with Social Networks and Banking close behind. This lines up neatly with the brand rankings above. The industries under the most pressure are the ones handling our identities, our professional relationships, and our money, which also happen to be the accounts most people would be quickest to protect if only they knew an attack was happening.

What Do Real Phishing Attempts Actually Look Like?

The following sample of documented cases from this quarter demonstrate just how varied these schemes can be.

ChatGPT. A fake subscription failure email led to a payment page built to steal credit card details, using an official looking OpenAI subject line and branding.

Michael Kors. A registered lookalike site replicated the entire shopping experience, browsing, cart, and checkout, all designed to capture payment information under the guise of a real purchase.

UNIQLO. A fake regional storefront appeared for a market UNIQLO doesn’t officially operate in. The giveaway was that its social media icons didn’t actually connect to UNIQLO’s real accounts.

Apple. A fake iCloud login page, presented in Russian, used Apple’s real logo and branding. The sign in button itself didn’t work, suggesting the page was still being tested before a fuller campaign.

PayPal. A near identical login page carried a noticeably distorted PayPal logo, a likely sign it had been produced with an AI image tool rather than lifted from PayPal’s actual assets.

Microsoft. A fake support page pushed an urgent Office security update. Clicking through didn’t install anything from Microsoft. It delivered a disguised executable file, the first step of a malware infection.

What Gives Phishing Attempts Away?

A few patterns showed up across nearly every case.

A sense of urgency is doing the work. Payment failures, security alerts, and required updates all push you to act before you stop to think, which is exactly the point.

Small visual flaws are common. A distorted logo, a button that doesn’t respond, icons that lead nowhere. None of these are obvious at a glance, but a more thorough review tends to reveal them.

Domains rarely match the real brand exactly. A slightly off spelling, an unusual extension, or a domain that has no business hosting that brand’s content is a strong signal on its own.

AI-generated assets are starting to leave their own fingerprints. As logos and pages get faked with AI tools, subtle distortions and inconsistencies are becoming one of the more reliable ways to spot a fake.

The Check Point AI Security Report 2026 Is Out

Posted in Commentary with tags on July 14, 2026 by itnerd

For years, the cyber security industry tracked AI as a force multiplier: something that made existing attack techniques faster, cheaper, and more accessible. That framing was accurate. But the Annual AI Security Report 2026 from Check Point Research documents a transition that goes further. AI has crossed from assistant to operator. Where it once helped attackers prepare, it now runs the operation.

Key observed findings

  • AI has crossed from development aid to live attack operator. It now does the hands-on work inside live intrusions, from China-nexus espionage campaigns to a criminal breach of multiple Mexican government agencies and has spread from nation states to ordinary cyber criminals.
  • AI now builds deployment-ready malware and attack suites. Its involvement is often invisible in the finished artifact: one developer used an AI environment to produce VoidLink, an 88,000-line command-and-control offensive framework, in under a week.
  • Attackers prefer commercial models, and now abuse them by exploiting the agentic architecture, not just single prompts. Most actors favor jailbroken mainstream models over self-hosted ones, and the durable bypass is now a planted configuration file an agent loads and trusts across sessions.
  • An AI-enabled criminal tooling market has matured. Phishing-as-a-service kits now embed a language model with the jailbreak built in, and conversational AI voice-agent services run vishing and one-time-passcode theft at scale.
  • Virtual Identity is no longer a reliable trust anchor. Voice, face, documents, and live video are now cheap to forge convincingly and are widely used in attacks taking multi-channel social engineering to a new level of integration.
  • AI itself is an expanding attack surface. Models cannot always separate data from instructions and content they process might influence the model’s behavior; the surrounding stack adds ordinary software vulnerabilities and supply-chain risk, all in a rapidly evolving ecosystem where security practices not always mature.
  • Indirect prompt injection is on the rise. Detections of longer malicious payloads increased sharply, rising roughly fivefold between March and May 2026 and approaching 1% of observed prompts in May. Longer payloads are more typical of content-borne and agentic attack paths, this pattern suggests that indirect prompt injection is becoming more operationally relevant.
  • Enterprise data leakage through GenAI is persistent and growing risk. High-risk prompts doubled from 2% to 4% during the last year, while organizations used an average of 10 AI applications each month, many without official approval.
  • Data exposure risks are not evenly distributed across the verticals. Sector-level analysis reveals that AI-related data exposure risks are not evenly distributed across the verticals, and correlate both with AI usage patterns and security maturity. Business Services recorded the highest rate of high-risk GenAI prompts at 5.91%, meaning nearly one in every 17 AI interactions carried a significant risk of sensitive data exposure.

To read the full findings, access the AI Security Report 2026 from Check Point Research here. 

A New Ransomware Leader Emerges as June 2026 Attack Volumes Climb Worldwide

Posted in Commentary with tags on July 9, 2026 by itnerd

Check Point’s June 2026 Monthly Cyber Threat Statistics reveal a significant increase in global cyberattacks, with organizations experiencing an average of 2,270 weekly cyberattacks, up 17% year-over-year and 10% month-over-month. The report also highlights a 33% increase in ransomware activity, with The Gentlemen emerging as the most active ransomware group, alongside continued concerns around GenAI-related data leakage risks, as 1 in every 26 GenAI prompts carried a high risk of exposing sensitive information.

Key takeaways
  • Weekly cyber-attacks per organization reached 2,270 in June 2026, up 10% from May and 17% higher than June 2025
  • Education, Government, and Telecommunications again sat at the top of the industry list, with Education and Telecommunications posting double-digit gains while Government rose 5% year over year
  • Most regions grew year over year, led by Latin America at a 27% increase, while Africa was the exception with a 9% decline
  • GenAI exposure held roughly steady, though Healthcare and Telecommunications emerged as the industries carrying the most risk from unsafe prompts
  • Ransomware attacks reached 646 for the month, a 33% jump from June 2025, and The Gentlemen overtook Qilin as the most active group
A Global Rebound That Reaches Every Region

June reversed the brief calm of May. Organizations faced an average of 2,270 weekly cyber attacks, a 10% rise from the previous month and a 17% increase compared with June last year. What makes this month notable is not just the size of the jump but its reach. Rather than one region or sector absorbing the bulk of the growth, the increase showed up almost everywhere at once, suggesting attackers spread their effort wider rather than concentrating it.

Which Industries Faced the Most Attacks?

Education remained the most targeted sector, with organizations facing an average of 4,816 weekly attacks, a 16% climb from June 2025. Open campus networks, constant device turnover, and thin security budgets keep making schools and universities an easy draw for attackers. Government followed at 2,836 weekly attacks, up 5%, and Telecommunications came in close behind at 2,835, a 13% rise. Together these three sectors continue to absorb a disproportionate share of global attack volume, a pattern that has held steady across recent months even as the specific numbers shift.

Figure 1: Global average weekly cyber-attacks per industry, June 2026 vs June 2025

Which Regions Saw the Sharpest Increase?

Latin America held its position as the most attacked region, with organizations reporting 3,501 weekly attacks on average, a 27% increase over June 2025. APAC followed at 3,060, a smaller 5% rise, while Africa posted 3,008 weekly attacks, down 9% from a year earlier, its only decline among the five regions tracked. Europe and North America both saw sharp jumps, up 22% and 14% respectively, pushing every region into growth except Africa.

Figure 2: Weekly cyber-attacks per organization by region, June 2026

GenAI Exposure: Where the Risk Concentrates

GenAI exposure has become one of the clearest examples of how everyday business behavior can create security risk. In this context, the risk is not about attackers using AI or flaws in the models themselves. It is about what employees place into prompts: customer records, internal documents, infrastructure details, legal material, financial data, or HR information that may be copied into public or unmanaged GenAI tools.

The June data highlights three main signals:

  • High-risk prompts are common: 1 in every 26 GenAI prompts from enterprise networks carried a high risk of sensitive data leakage, equal to a global exposure rate of 3.9%
  • The risk is widespread: 85% of organizations that regularly use GenAI tools were affected by high-risk prompt activity
  • Sensitive information is frequently present: A further 27% of prompts contained potentially sensitive information
  • Adoption is broadening: Each organization used an average of 7 different GenAI tools over the past month, while the average user generated 78 prompts

That level of activity suggests GenAI is no longer a side experiment in many workplaces. It is becoming part of daily workflows, often faster than data protection policies, user training, and technical controls can adapt.

The highest-risk regions and industries stood out clearly against the 3.9% global benchmark. Looking at where this risk lands, Latin America stood out as the highest risk region at 5.2%, well above the global rate. Europe matched the global average of 3.9%, while North America and APAC came in slightly under it, at 3.6% and 3.5%. By industry, Healthcare and Medical carried the heaviest exposure at 5.7%, followed by Telecommunications and Business Services, both at 5.1%, and Information Technology at 4.1%.

Figure 3: High risk prompts per region, June 2026

Personal data made up the largest share of sensitive content flowing through these prompts, appearing in 80% of organizations, followed by network and infrastructure details at 62%, legal and regulatory material at 61%, financial data at 60%, and employee records at 57%. Taken together, these figures point to a workforce that treats GenAI tools as a general-purpose assistant, feeding them exactly the kind of material that governance policies are meant to protect.

Figure 4: The types of data flowing through AI prompts

This shows that GenAI exposure is not limited to one department or one type of task. It cuts across personal, technical, legal, financial, and workforce-related data, making prompt-level visibility and governance increasingly important as enterprise GenAI use continues to grow.

Figure 5: High risk prompts by industry, June 2026

Ransomware Keeps Climbing, With Business Services in the Crosshairs

* This ransomware data draws from ransomware “shame sites” operated by double-extortion groups, which publicly disclose victim information. While these sources have inherent biases, they provide valuable insight into the ransomware landscape.

Ransomware attacks totaled 646 in June, a 33% increase over the same month in 2025. Business Services remained the most affected industry, responsible for 31% of reported victims, followed by Consumer Goods and Services at 16% and Industrial Manufacturing at 14%. Two trends stand out over the past three months. Consumer Goods and Services has climbed steadily, from 14% of victims in April to 15% in May and 16% in June, and Government has moved even faster, rising from 4.0% to 4.3% to 5.4% across the same stretch.

Figure 6: Percentage of ransomware victims by industry, June 2026

Figure 7: Share of global ransomware victims by industry, April – June 2026

North America accounted for 44% of reported ransomware incidents, with APAC at 23% and Europe at 22%. APAC saw the sharpest shift of any region, its share of global victims rising from 16.8% in April to 22.6% in June, a jump of over a third in just two months.

Figure 8: Ransomware victims by region, June 2026

A New Name at the Top of the Ransomware Leaderboard

The Gentlemen was the most prevalent ransomware group in the past month, responsible for 17% of the published attacks, overtaking Qilin, which accounted for 11%. LockBit also recorded a significant increase, rising from 1% of published attacks in the previous month to 7%, making it the third most prevalent ransomware group.

  • The Gentlemen: The Gentlemen is a fast growing Ransomware-as-a-Service operation founded in mid-2025 by a Russian-speaking operator (Hastalamuerte) who previously worked as an affiliate across Qilin, Embargo, LockBit, Medusa, and BlackLock before launching his own platform after a dispute with Qilin. The group openly recruits affiliates in various forums and uniquely functions as both a RaaS provider and an Initial Access Broker, offering affiliates self-service access to approximately 14,000 pre-exploited FortiGate devices (CVE-2024-55591). With over 320 DLS-claimed victims and an estimated 1,570+ actual compromises revealed through Check Point Research’s analysis, The Gentlemen has established itself as a top-7 global ransomware threat in under a year. The group’s cross-platform lockers target Windows, Linux, and ESXi (C-based), and their latest May 2026 operator communication announces a shift from blunt-force BYOVD-based EDR killing to surgical userland evasion techniques. The group’s geographic targeting is notably atypical, with the US representing only 12% of victims (vs 50% ecosystem average), reflecting a device-driven victim selection model shaped by the FortiGate stockpile rather than deliberate geographic preference.
  • Qilin: Qilin is one of the most established RaaS groups, with a consistent track record of victim disclosures dating back to 2022. Originally operating under the name “Agenda,” the group rebranded as “Qilin” by September 2022, introducing a Rust-based encryptor and expanding its RaaS infrastructure. It provides affiliates with a full-featured toolkit via a dedicated administrative panel, including an encryptor, negotiation infrastructure, and support services. Following RansomHub’s retirement, Qilin intensified its affiliate recruitment efforts and, since March 2025, has significantly increased the volume of victim listings on its data leak site (DLS).
  • LockBit: LockBit is a ransomware-as-a-service (RaaS), that was first launched in September 2019 and was updated and improved in June 2021. LockBit targets large enterprises and government entities from various countries and does not target individuals in Russia or the Commonwealth of Independent States. LockBit shares details of their victims on a Tor-hosted leak site along with the countdown to the date and time at which stolen data will be published unless the ransom payment is received. LockBbit is considered to be the fastest ransomware in terms of encryption speed.
Frequently Asked Questions About June 2026’s Cyber Threat Landscape
  • Why did cyber attacks increase across nearly every region in June? The growth was broad rather than concentrated in one place, which points to attackers expanding their targeting rather than focusing on a single weak point. Latin America and Europe saw the steepest year over year gains, while Africa was the only region to post a decline.
  • Which industries face the highest GenAI data leakage risk? Healthcare and Medical carried the highest risk at 5.7% of prompts, followed by Telecommunications and Business Services at 5.1% each, and Information Technology at 4.1%. All four sat above the global average of 3.9%.
  • Why did The Gentlemen overtake Qilin as the top ransomware group? The Gentlemen built rapid scale through self-service access to a large pool of pre-exploited devices and an aggressive affiliate recruitment model, letting it grow into a leading threat within about a year of launching. In June it accounted for 17% of published attacks against Qilin’s 11%.
  • Is ransomware activity still concentrated in North America? Yes, though less so than before. North America still accounts for 44% of reported victims, but APAC’s share grew sharply, from 16.8% in April to 22.6% in June, making it the fastest growing region for ransomware activity.
  • Reading June Correctly: The headline number tells a straightforward story: attacks are up, broadly and consistently, across regions that had shown mixed signals in prior months. The more useful story sits underneath it. Ransomware is not just growing, it is reorganizing at the leadership level, with a group that barely existed a year ago now setting the pace. GenAI risk has not spiked, but it has settled into a steady baseline that most organizations still have not built the right controls around. None of this points to a single fix. It points to the same conclusion every month like this one does, that a prevention first strategy across network, cloud, endpoint, and user activity is the only approach built to keep up with a landscape that keeps shifting shape.

Guest Post – Under Pressure: Insights from the 2026 Exposure Gap Report

Posted in Commentary with tags on July 6, 2026 by itnerd

Risk is concentrating. The 2026 Exposure Gap Report shows vulnerabilities claiming a larger share of critical exposure, and that shift has real implications for how security teams prioritize their response.

Two findings are central to this change. Vulnerabilities now represent a much larger share of critical exposure, and only a small percentage of vulnerability alerts are validated as exploitable. Together, these findings show why prioritization depends on context, validation, and a clear understanding of which exposures require action.

Exposure Is Shifting Toward Vulnerabilities

Vulnerabilities now account for 42.6% of critical exposure, up from 18.7% in 2025. This increase shows that weaknesses across systems and applications are playing a larger role in how critical exposure develops across connected environments.

A higher volume of vulnerability findings does not mean a higher volume of real risk. Security teams need to know which exposures matter in their specific environment so they can focus remediation where it counts.

Only a Small Portion Is Exploitable

Only 7.8% of vulnerability alerts are validated as exploitable and classified as Critical or High. This finding shows that the actionable portion of vulnerability exposure is much smaller than the full alert volume suggests.

A vulnerability becomes Critical or High when exploitability is viewed alongside context. The affected assets, business criticality, existing security controls, and evidence of active exploitation by threat actors all shape the level of risk. Looking at these factors together gives security teams a more accurate view of which exposures require immediate attention.

Exploitability validation helps teams narrow large volumes of findings into a focused set of priorities. When teams know which exposures can be used in practice, they can make faster decisions, plan remediation more effectively, and reduce the operational noise that slows response.

Having trouble determining which exposures can be used in an attack? Get a free Agentic Exposure Validation (AEV) scan to identify actionable exposure and filter out findings that already have security protections in place.

The Structure Beneath the Volume

The report points to a clear gap between what is detected and what requires action. Vulnerability findings may appear broad at scale, yet the validated risk pool is much smaller than the overall dataset.

This distinction shapes how teams operate. When workflows are guided by validated exposure, teams can move with greater focus and avoid spending time on findings that do not change risk in practice.

Closing the Exposure Gap

Closing the exposure gap starts with better filtering and more consistent validation. Security teams need to understand which exposures are present, which can be exploited, and which should be addressed first.

Teams that make these distinctions clearly can respond faster and prioritize with more confidence. As vulnerability driven exposure continues to rise, progress depends on moving from broad detection to focused action.

The 2026 Exposure Gap Report covers exposure composition by industry, remediation benchmarks, and what separates teams closing critical exposures in under an hour from those still working through the backlog.

You can download it here

Check Point to Embed OpenAI Frontier Cyber Capabilities into Check Point Security Products 

Posted in Commentary with tags on June 23, 2026 by itnerd

Check Point today announced the use of OpenAI’s frontier cyber capabilities into its customer-facing defenses. Through the OpenAI Daybreak Cyber Partner Program, open to only a select group of security vendors, Check Point can embed OpenAI models directly into the products, workflows, and managed services its customers rely on. 

It marks a meaningful shift, from using these models internally to embedding them directly inside the defenses that protect customers, carrying the safety controls, abuse-prevention standards, and scoped outputs that enterprise security demands. The aim is to sharpen threat prevention, faster remediation, and stronger security operations, delivered through the products and services customers already rely on. 

The threat landscape is being shaped by AI. Threat actors are using it to move faster, craft more convincing attacks, and find weaknesses at scale. Defenders need equivalent or stronger capabilities, delivered safely and within clear boundaries. The quality of the models powering defensive workflows has become a strategic variable, not a technical detail. 

Through this expanded partnership, Check Point is identifying the defensive security workflows and solutions where OpenAI’s trusted access for cyber models, paired with the right safeguards, can deliver measurable customer value.  

Check Point and OpenAI are working together to help define the standards for using trusted access frontier AI responsibly in security, building protections against misuse and the controls to catch and stop it. The rollout is deliberately gradual: it begins with carefully controlled defensive uses and widens only as those protections prove themselves. This disciplined approach reflects how Check Point brings AI into its platform across the board, with the rigor and responsibility enterprise security demands. 

Check Point and Illumio Expand Partnership to Deliver Protection and Resilience Against Frontier AI-Powered Attacks

Posted in Commentary with tags on June 16, 2026 by itnerd

Check Point and Illumio Inc., the breach containment company, today announced an expanded strategic partnership to help organizations defend against a new category of threat: frontier AI models capable of autonomously executing full-scale attacks at machine speed.

Frontier AI models are changing the nature of cyber attacks. Adversaries can now compress the entire attack lifecycle — discovery, exploitation, and lateral movement — into a single, automated sequence with little or no human involvement. The window between initial access and catastrophic breach is collapsing. For security teams already stretched thin, the critical question is no longer, “can we stop the attack at the door?” It’s “if something gets in, can we find it and stop it from spreading before the damage is done?”

This expanded partnership is built to answer both questions. Check Point delivers the industry’s best security for the perimeter, data center, and networks — with the best real-time threat prevention against unknown attacks and the most comprehensive Zero Trust security available. Illumio addresses what happens inside the network: visibility into how workloads communicate, exposure of attack paths, and microsegmentation controls that protect critical assets and contain breaches before they cascade into disasters. Together, the two companies deliver protection and resilience as a unified capability. Customers can now procure Illumio directly through Check Point, simplifying vendor consolidation and accelerating deployment.

Building on the 2025 integration with Illumio Insights, which helped security teams connect Check Point threat intelligence with workload visibility to detect lateral movement risk, the expanded partnership now adds deep integration with Illumio Segmentation. Security teams can align Check Point firewall policy with Illumio’s workload model across hybrid and multi-cloud environments, reducing unnecessary connectivity and making it significantly harder for attackers to move undetected through the network once inside.

The result is a more complete security architecture for the AI era. Check Point’s prevention-first enforcement stops threats at key network boundaries. Illumio Insights surfaces suspicious movement and attack paths across hybrid environments. And Illumio Segmentation, now more tightly aligned with Check Point firewall policy, limits how far any threat can travel once inside. For security teams managing more systems, more connectivity, and more change than ever before, this combination means faster detection, smarter decisions, and incidents contained before they become disasters.

The expanded integration is available now for joint Check Point and Illumio customers. Additional details, including technical integration guidance, are available in the Check Point and Illumio white paper.