EVENTS
0
EVENTS/DAY
0
EVENTS
0
EVENTS/DAY
0

The first timeline of April 2026 brings an evolution in terms of methodology: from now on I will map the initial access techniques with the MITRE ATT&CK model. I also decided to merge the categories of Finance and Fintech in the sectors chart.

From an event perspective, the first half of April 2026 confirmed a sustained trend, despite not at the same level of the previous fortnight. In this timeline I collected 94 events (6.27 events/day) and a threat landscape driven by cyber crime (65% the same level of the previous timeline) and characterized by malware attacks with 41%, (nearly at the same level of the previous timeline when it was 40%).

This period was also characterized by a remarkable number of cyber espionage operations (18% vs 15%) of the previous timeline, again at number two, ahead of cyber warfare, which doubled its share to 6% from 3%) and hacktivism, down to 3% from 7%.

In terms of attack techniques, malware precedes once again account takeovers (down to 14% from 22% and ransomware (slightly  down to 8% from 9%, confirming the same positions of March as a whole.

In the first half of April, the exploitation of public-facing applications led the initial access techniques with 23%, even if a direct comparison with the previous timeline is not possible since, as I aforementioned, I changed the methodology. Phishing with spearphishing Links and with spearphishing attachments complete the podium respectively with 12% and 7%. If we aggregate the macro categories of phishing (T1566) and supply chain compromise (T11195), we have respectively 26 and 8 events, corresponding to 28% and 9%, meaning that the initial access was still dominated by spearphishing but also supply chain compromises played an important roles.

And in this timeline, targets belonging to the Information an Communication sector took the lead with 28%, up from 20%, overtaking targets in the Public Administration sector slightly up to 23%, from 22%, ahead of Finance and Insurance with 21% (as I mentioned before I merged the categories of Finance and Insurance and Fintech).

Besides these trends, this timeline in particular is rich of interesting events, such as additional mega breaches , so my final suggestion does not change: browse the timeline for the details of all the events collected in this fortnight.

As always bear in mind that the sample refers exclusively to the attacks included in my timelines, available from public sources such as blogs and news sites. Obviously the sample cannot be complete, but only aims to provide an high level overview of the threat landscape.

Please support my work, sharing the content, and of course connect on Linkedin, or even follow @paulsparrows on X (formerly Twitter), psparrows.bsky.social on Bluesky, or @ppasseri@Infosec.exchange on Mastodon for the latest updates.

BE NOTIFIED OF NEW BLOG POSTS: SUSCRIBE!


SUPPORT MY WORK, MAKE A DONATION!

MOST READ BLOG POSTS

POPULAR POSTS
  • Malicious Campaigns Using AI-generated Malware in 2026

    In this blog post I am collecting the campaigns that show evidence of being AI-generated, or make use of AI tools to increase their impact. As always I will continue to update the list as soon as new campaigns emerge.

  • Maga Breaches 2026 Front ImageMega Breaches in 2026

    Here’s a collection of the main mega breaches (that is data breaches with more than one million records compromised and possibly leaked) during 2026. The information is derived from the cyber attacks timelines that I published, normally, on a bi-weekly basis.

  • August 2026 Cyber Attacks Statistics

    August 2026 statistics report breaks down 218 confirmed cyber incidents by motivation, attack vector, initial access technique, and target sector. Financially motivated Cyber Crime drove more than 4 in 5 attacks, Malware remained the weapon of choice, and Information & Communication infrastructure bore the brunt ...

  • Q2 2026 Cyber Attacks Statistics

    Q2 2026 brought 578 recorded cyber incidents worldwide, with financially-motivated cyber crime accounting for over 71% of the total. Malware remained the attacker's weapon of choice, exploiting public-facing applications as the leading entry point. Information & Communication stood out as the hardest-hit sector.

  • August 2026 Cyber Attacks Statistics Infographic

    A one-page visual briefing on August 2026's global cyber attack landscape: 218 confirmed incidents, a rising four-in-five share driven by profit-motivated crime, and a back-to-back spike that delivered 34 attacks in just two days.

Download CSV

Leave a Reply

This site uses Akismet to reduce spam. Learn how your comment data is processed.