Cyble APAC threat landscape report flags rising ransomware

The Cyble APAC threat landscape report for H1 2026 points to a growing cybersecurity challenge across the Asia-Pacific region, with India emerging as one of the most targeted countries for ransomware. The report recorded 77 distinct ransomware attacks against India between January and June 2026, placing it ninth globally and second among the most targeted APAC nations, behind Thailand.
The findings highlight a threat environment that goes beyond ransomware alone. Cyble Research and Intelligence Labs (CRIL) recorded 496 ransomware attacks, 19 data breach incidents and 20 initial access listings across APAC during the first half of 2026. The numbers point to a wider attack ecosystem where organisations face risks ranging from stolen access to data theft and disruption.
India cybersecurity threat report highlights ransomware pressure
India's position in the India cybersecurity threat report findings reflects the risks that come with its expanding digital and IT ecosystem. According to Cyble, the region's technology supply chains and digital transformation are attracting both financially motivated ransomware groups and state-sponsored threat actors.
The report notes that double extortion has become a common tactic, increasing pressure on organisations to protect not just systems and backups but also sensitive data before it is stolen and exposed.
APAC ransomware target rankings show industry risks
Manufacturing was the most targeted industry in APAC, recording more than 49 attacks. IT and ITES followed with 30 attacks, while BFSI recorded 22 attacks. Consumer goods, professional services, healthcare and construction also appeared among the most exploited sectors.
Three ransomware-as-a-service operators, The Gentlemen, Qilin and LockBit, accounted for more than 43% of ransomware attacks across APAC. The underground market also remains a concern, with retail and professional services making up half of all initial access sale listings in the region.
APAC cybersecurity surge includes state-backed threats
APAC also recorded the highest ratio of Advanced Persistent Threat profiles globally. Of 123 threat actor profiles tracked in the region, 54 were identified as nation-state APTs linked to China, North Korea and Pakistan. Groups including SideCopy, SharpPanda, Kimsuky and UNC3886 were reported as targeting government, defence and enterprise IT infrastructure.
Hacktivism added another layer of pressure, with more than 4,500 regional domains affected by campaigns that generated nearly 700 data leak posts across government, education and technology sectors.
India cyber attack statistics reveal wider risks
The broader global picture reinforces the scale of the challenge. Cyble recorded 3,836 ransomware attacks worldwide and 367 data breach incidents in H1 2026. Of 146 CVEs analysed, nearly 90% were rated critical or high severity, with network and edge appliances remaining key entry points for zero-day and N-day exploits.
For organisations across India and APAC, the report suggests that cybersecurity strategies need to address multiple stages of an attack, from initial access and network protection to data exfiltration. The rising APAC cybersecurity surge shows that ransomware is only one part of a wider threat landscape that increasingly combines financially motivated attacks, state-backed activity and hacktivism.
Read More:
SK Group and NVIDIA Sign USD 500B+ Mega-Deal to Build 2-Gigawatt AI Factory in Korea
Intel and Fortinet partnership targets stronger security chips
Why ESG is reshaping the future of manufacturing
Can India Build Its Own AI Stack Without Relying on Global Tech Giants?






