Rising threats: the 2026 Arctic Wolf security report

Arctic Wolf highlights a surge in data-theft extortions and remote access threats in its latest threat report.

Arctic Wolf's 2026 Threat Report highlights notable trends in the cybersecurity landscape. Data-theft-driven extortion and the increasing use of remote access tools emerged as key focus areas, reflecting evolving patterns in cyber threats.

In 2025, Arctic Wolf responded to numerous ransomware, business email compromise (BEC), and data-related incidents, which together accounted for 92% of all incident response cases. While ransomware remained the most common threat, data-only extortion incidents rose elevenfold, indicating a shift in tactics among cyber actors.

The report also found that 65% of non-BEC breaches involved the exploitation of remote access technologies, such as RDP, VPN, and RMM tools, demonstrating a preference among attackers for lower-friction entry points over complex technical exploits.

Key findings include:

  • Ransomware, BEC, and data incidents: These represented the majority of cases, with data-focused threats increasing from 2% to 22%.
  • Pre-ransomware activity: Accounted for 5% of cases, showing the value of early detection.
  • Ransom demands: Professional negotiations reduced demands by an average of 67%, with most organisations choosing not to pay.
  • Phishing: Responsible for 85% of BEC incidents, with AI making scams more convincing.
  • Exploited CVEs: All top-exploited vulnerabilities were from 2024 or earlier, highlighting the importance of patch management.
Ismael Valenzuela, Vice President of Threat Research & Intelligence at Arctic Wolf, notes that attackers increasingly focus on efficiency, prioritising stealth and subtle methods rather than high-complexity exploits.

Kerri Shafer-Page, Vice President of Incident Response, adds that early detection significantly affects outcomes, with timely identification helping organisations prevent more serious consequences.

These findings emphasise the importance of strong security measures, including visibility, identity protection, and controlled remote access, to mitigate emerging threats.
As pressure mounts, CFOs are rethinking financial reporting to enhance decision-making and performance.
Sectigo reveals multi-tenant partner platform, aiming for seamless, automated certificate management for channel partners.

CybaVerse rebrands to strengthen cyber operations

Posted 5 days ago by Sophie Milburn
CybaVerse pivots from consultancy-led defence to platform-driven operations with its rebrand, emphasising control over cyber security.

AI and Cybersecurity: the future of phishing defence

Posted 5 days ago by Sophie Milburn
2025 marked a turning point in cybersecurity, as AI transformed both phishing techniques and the tools used to combat them, ushering in a more...
Dr. Maria Maragkou joins Nu Quantum to lead business development and enhance partnerships, leveraging her blend of scientific and commercial...

MSPs embrace hybrid IT for lucrative returns

Posted 1 week ago by Sophie Milburn
New research reveals MSPs are capitalising on hybrid IT for cloud and security returns.
Boomi adds new features to its Enterprise Platform, including context-aware data activation and expanded SAP integration.
Datadog establishes a new UK data centre to aid organisations in regulated industries with local storage needs and upgraded security measures.