Understanding threat attribution in cybersecurity

The TrendAI framework offers a structured approach to threat attribution, emphasising evidence over labels.

  • Tuesday, 17th February 2026 Posted 2 months ago in by Sophie Milburn
As the cybersecurity industry navigates the complexities of threat actor identification, TrendAI, part of Trend Micro, has released a guide outlining how threat attribution should operate based on evidence, rather than relying on renaming or differences between vendors.

Variations in threat actor naming are often seen as discrepancies, but this perspective oversimplifies the underlying complexity. Different research teams may analyse distinct datasets, use different clustering methods, and reach varying confidence levels. Complete alignment across all entities is neither realistic nor necessary.

TrendAI's guide explains its approach to tracking activity using structured evidence rather than pre-existing labels. It introduces provisional SHADOW designations, which allow analysts to monitor emerging or overlapping activity without prematurely assigning firm attribution or overstating certainty.

The framework aims to clarify how attribution decisions are made within the industry, highlighting the reasons for differing naming practices and emphasising the importance of evidence over labels.

For business leaders, accurate attribution affects risk management and response planning. Overreliance on threat actor names alone can create a false sense of certainty, potentially affecting priorities and defensive measures.

When attribution decisions are reviewed by stakeholders such as boards, auditors, or regulators, labels on their own may not suffice. An evidence-based approach provides a foundation rooted in verifiable data, supporting clearer communication, justification, and adaptation as new information emerges.

AI trust fails to keep pace with rate of adoption

Posted 4 days ago by Phil Alsop
Two thirds of organisations (64 per cent) are actively using artificial intelligence across the UK, a 12 per cent increase from last year according...

AI adoption is accelerating identity sprawl

Posted 4 days ago by Phil Alsop
Keeper Security has released its latest global insight report, “Identity Security at Machine Speed.”

Surge in AI-enabled cybercrime

Posted 5 days ago by Phil Alsop
Fortinet leverages threat intelligence to disrupt global cybercrime, transforming awareness into actionable insights.
Study finds most organizations recognize the need for connected data, content, and workflows, but few have built the operational foundation required...
A third (35%) of European organisations cannot say whether they have been hit by an AI-powered cyberattack, according to the latest AI Pulse Poll...
Nearly half of European organisations spend up to €5 million a year on cloud – yet a quarter of capacity sits idle.

AI-Driven attacks reshape the MSP threat landscape

Posted 1 week ago by Phil Alsop
New research shows session hijacking surging 23%, ransomware up 190%, and non-human identities outnumbering users 25:1 as AI accelerates attacks...
Lenovo research highlights a growing AI execution gap as organizations struggle to control and operate AI across their environments.