Trending

Threat Landscape:
January 2026

Ransomware Attacks Surge, Hitting the Supply Chain

January 2026 began where 2025 ended — with ransomware operating at record-breaking pace. Ransomware groups claimed 679 victims in January alone, continuing a surge that pushed activity more than 30% above the 2025 monthly average.

But volume wasn’t the only concern. Attackers increasingly targeted engineering environments, exfiltrating technical documentation, PCB layouts, CAD files, and internal blueprints, exposing organizations and their downstream partners to severe supply chain risk.

This report delivers a comprehensive breakdown of the threat activity that defined January 2026.

Annual-threat-report-2026

Key Highlights at a Glance

679

Ransomware victims in January 2026

2,018

Ransomware attacks in Q4 2025 (avg. 673/month)

30%

Increase over 2025 monthly
trend

Qilin led with 115 claimed attacks

CL0P resurged with new campaigns targeting multiple regions

ICS systems manipulated in energy, water, and industrial facilities

What You’ll Gain From This Report

  • Detailed breakdown of January’s most significant ransomware incidents
  • Sector and geographic attack analysis
  • Supply chain risk implications
  • Critical IT and OT vulnerability prioritization
  • Active threat groups and malware families
  • Defensive recommendations for resilience

Gain actionable threat intelligence to strengthen your defense posture against ransomware, supply chain compromise, and industrial system exploitation.

Stay ahead of evolving threat actors with real-time insights powered by Cyble.

Download the Full Report

Scroll to Top