- Last modified: May 8, 2026
Top Motivations - April H2 2026
No Data Found
Top Attack Techniques - April H2 2026
No Data Found
Top Initial Access Techniques - April H2 2026
No Data Found
Top Targeted Sectors - April H2 2026
No Data Found
In the second timeline of April 2026 I collected 108 events, corresponding to an average of 7.2 events per day, a number that confirms a growing trend, driven by the increasing number of supply chain attacks, compared to the previous timeline, where I collected 94 events (6.27 events/day).
Once again, the threat landscape is dominated by cyber crime (67%, nearly the same level of the previous timeline when it was 65%) and characterized by malware attacks with 34%, down from 41% of the previous timeline.
And also in this timeline, cyber espionage operations played an important role, confirming their growth (25% vs 18%), once again ahead of cyber warfare, stable to 5% from 6%) and hacktivism, which confirmed its tiny 3%. Apparently the geopolitical tensions that characterize this period are showing a modest impact so far.
In terms of attack techniques, the first two techniques confirmed their leadership in the chart, with malware preceding again account takeovers (up to 20% from 14%). This fortnight, the third place is taken by the generic exploitation of vulnerabilities (10%) meaning that in these case it was not possible to determine exactly which technique was used to carry on the attack.
And similarly to the previous timeline, in the second half of April, the technique T1190 – exploitation of public-facing applications leads the initial access with 25%, very close to 23%. Phishing continues to characterize the initial access as well, with generic phishing (T1566) at number two with 17% and spearphishing attachments (T1566.001) at number three with 10%.
Even in this fortnight if we aggregate the parent categories we have 37 events for phishing (corresponding to 32%) and 12 events for supply chain compromises (corresponding to 10%). In turn the exploitation of vulnerabilities, phishing and supply chain compromises dominate the initial access.
And finally, even in this timeline, targets belonging to the Information an Communication sector were hit the most with 34%, a consequence of the growth of supply chain attacks, once again ahead of targets in the Public Administration, stable at 23%, and Finance and Insurance down to 13% from 21%.
Besides these trends, this timeline in particular is rich of interesting events, such as additional mega breaches , so my final suggestion does not change: browse the timeline for the details of all the events collected in this fortnight.

1-15 April 2026 Cyber Attacks Timeline
The first timeline of April 2026 brings an evolution in terms of methodology: from now on I will map the initial access techniques with the MITRE
As always bear in mind that the sample refers exclusively to the attacks included in my timelines, available from public sources such as blogs and news sites. Obviously the sample cannot be complete, but only aims to provide an high level overview of the threat landscape.
Please support my work, sharing the content, and of course connect on Linkedin, or even follow @paulsparrows on X (formerly Twitter), psparrows.bsky.social on Bluesky, or @ppasseri@Infosec.exchange on Mastodon for the latest updates.
BE NOTIFIED OF NEW BLOG POSTS: SUSCRIBE!
SUPPORT MY WORK, MAKE A DONATION!
MOST READ BLOG POSTS

Q1 2026 Cyber Attack Statistics
I aggregated the statistics created from the cyber attacks timelines published in the first quarter of 2026. In this period, I collected a total of 528
POPULAR POSTS
Mega Breaches in 2026Here’s a collection of the main mega breaches (that is data breaches with more than one million records compromised and possibly leaked) during 2026. The information is derived from the cyber attacks timelines that I published, normally, on a bi-weekly basis.
Malicious Campaigns Using AI-generated Malware in 2026In this blog post I am collecting the campaigns that show evidence of being AI-generated, or make use of AI tools to increase their impact. As always I will continue to update the list as soon as new campaigns emerge.
1-15 July 2021 Cyber Attacks TimelineThe first cyber attacks timeline of July is finally out. In this fortnight I have collected 101 events, a number in line with the previous one (102), confirming...
August 2026 Cyber Attacks StatisticsAugust 2026 statistics report breaks down 218 confirmed cyber incidents by motivation, attack vector, initial access technique, and target sector. Financially motivated Cyber Crime drove more than 4 in 5 attacks, Malware remained the weapon of choice, and Information & Communication infrastructure bore the brunt ...
2018: A Year of Cyber AttacksFinally I can summarize all the events and statistics collected in 2018, quite a complicated year from an infosec perspective. For those of you that keep asking...
Share:
- Share on LinkedIn (Opens in new window) LinkedIn
- Share on X (Opens in new window) X
- Share on Bluesky (Opens in new window) Bluesky
- Share on Mastodon (Opens in new window) Mastodon
- Share on Facebook (Opens in new window) Facebook
- Share on WhatsApp (Opens in new window) WhatsApp
- Email a link to a friend (Opens in new window) Email
- Share on Reddit (Opens in new window) Reddit
- Share on Tumblr (Opens in new window) Tumblr
- Share on Telegram (Opens in new window) Telegram
- Share on Pinterest (Opens in new window) Pinterest
- Share on Threads (Opens in new window) Threads