- Last modified: April 27, 2026
Top Motivations - April H1 2026
No Data Found
Top Attack Techniques - April H1 2025
No Data Found
Top Initial Access Techniques - April H1 2026
No Data Found
Top Targeted Sectors - April H1 2026
No Data Found
The first timeline of April 2026 brings an evolution in terms of methodology: from now on I will map the initial access techniques with the MITRE ATT&CK model. I also decided to merge the categories of Finance and Fintech in the sectors chart.
From an event perspective, the first half of April 2026 confirmed a sustained trend, despite not at the same level of the previous fortnight. In this timeline I collected 94 events (6.27 events/day) and a threat landscape driven by cyber crime (65% the same level of the previous timeline) and characterized by malware attacks with 41%, (nearly at the same level of the previous timeline when it was 40%).
This period was also characterized by a remarkable number of cyber espionage operations (18% vs 15%) of the previous timeline, again at number two, ahead of cyber warfare, which doubled its share to 6% from 3%) and hacktivism, down to 3% from 7%.
In terms of attack techniques, malware precedes once again account takeovers (down to 14% from 22% and ransomware (slightly down to 8% from 9%, confirming the same positions of March as a whole.
In the first half of April, the exploitation of public-facing applications led the initial access techniques with 23%, even if a direct comparison with the previous timeline is not possible since, as I aforementioned, I changed the methodology. Phishing with spearphishing Links and with spearphishing attachments complete the podium respectively with 12% and 7%. If we aggregate the macro categories of phishing (T1566) and supply chain compromise (T11195), we have respectively 26 and 8 events, corresponding to 28% and 9%, meaning that the initial access was still dominated by spearphishing but also supply chain compromises played an important roles.
And in this timeline, targets belonging to the Information an Communication sector took the lead with 28%, up from 20%, overtaking targets in the Public Administration sector slightly up to 23%, from 22%, ahead of Finance and Insurance with 21% (as I mentioned before I merged the categories of Finance and Insurance and Fintech).
Besides these trends, this timeline in particular is rich of interesting events, such as additional mega breaches , so my final suggestion does not change: browse the timeline for the details of all the events collected in this fortnight.

16-31 March 2026 Cyber Attacks Timeline
The second half of March 2026 has been very active from an infosec standpoint, with 124 events and a threat landscape dominated by malware. As always,
As always bear in mind that the sample refers exclusively to the attacks included in my timelines, available from public sources such as blogs and news sites. Obviously the sample cannot be complete, but only aims to provide an high level overview of the threat landscape.
Please support my work, sharing the content, and of course connect on Linkedin, or even follow @paulsparrows on X (formerly Twitter), psparrows.bsky.social on Bluesky, or @ppasseri@Infosec.exchange on Mastodon for the latest updates.
BE NOTIFIED OF NEW BLOG POSTS: SUSCRIBE!
SUPPORT MY WORK, MAKE A DONATION!
MOST READ BLOG POSTS

1-15 March 2026 Cyber Attacks Timeline
In the first half of March 2026 I collected 95 events (6.34 events/day) with a threat landscape dominated by malware once ahead of account takeovers and
Malicious Campaigns Using AI-generated Malware in 2026In this blog post I am collecting the campaigns that show evidence of being AI-generated, or make use of AI tools to increase their impact. As always I will continue to update the list as soon as new campaigns emerge.
Mega Breaches in 2026Here’s a collection of the main mega breaches (that is data breaches with more than one million records compromised and possibly leaked) during 2026. The information is derived from the cyber attacks timelines that I published, normally, on a bi-weekly basis.
August 2026 Cyber Attacks StatisticsAugust 2026 statistics report breaks down 218 confirmed cyber incidents by motivation, attack vector, initial access technique, and target sector. Financially motivated Cyber Crime drove more than 4 in 5 attacks, Malware remained the weapon of choice, and Information & Communication infrastructure bore the brunt ...
Q2 2026 Cyber Attacks StatisticsQ2 2026 brought 578 recorded cyber incidents worldwide, with financially-motivated cyber crime accounting for over 71% of the total. Malware remained the attacker's weapon of choice, exploiting public-facing applications as the leading entry point. Information & Communication stood out as the hardest-hit sector.
August 2026 Cyber Attacks Statistics InfographicA one-page visual briefing on August 2026's global cyber attack landscape: 218 confirmed incidents, a rising four-in-five share driven by profit-motivated crime, and a back-to-back spike that delivered 34 attacks in just two days.
Share:
- Share on LinkedIn (Opens in new window) LinkedIn
- Share on X (Opens in new window) X
- Share on Bluesky (Opens in new window) Bluesky
- Share on Mastodon (Opens in new window) Mastodon
- Share on Facebook (Opens in new window) Facebook
- Share on WhatsApp (Opens in new window) WhatsApp
- Email a link to a friend (Opens in new window) Email
- Share on Reddit (Opens in new window) Reddit
- Share on Tumblr (Opens in new window) Tumblr
- Share on Telegram (Opens in new window) Telegram
- Share on Pinterest (Opens in new window) Pinterest
- Share on Threads (Opens in new window) Threads