Research release · H1 2026

Six months of threat-source activity, made readable.

Explore 29,858 collected records across time, category, source network and metadata. Start with the signal, then open the method behind it.

Reading boundary: these are collected source observations. They are not a count of confirmed incidents, victims or attacks.

01

Start here

What changed across the half-year?

March produced the highest collected volume. The mix matters more than the headline total: six categories accounted for most records, and half of the records came from one source network.

Peak month6,148

March carried the most records

April then fell to 4,031, the lowest monthly count in the period.

Category mix57.5%

Three categories led the set

DDoS Attack, Data Breach and Ransomware together accounted for more than half of the records.

Metadata limit56.4%

Organization metadata was incomplete

Use organization-level findings as leads for review, not as a complete market count.

02

Volume over time

The monthly signal moved, but did not trend in one direction.

Focus each point to inspect the exact count. The chart uses the publication month stored with each collected record.

Collected records by monthLoading chart…
Monthly records

Use Tab or move across a point to inspect a month.

03

Interactive explorer

Move through the dataset without reading six tables.

Switch the dimension, search long lists and choose how many rows to compare. Every percentage uses the 29,858-record study total unless noted.

Top categoriesLoading…

Category labels describe the collected record. They do not confirm the underlying event.

Selected signalDDoS Attack
Records6,796
Share22.8%
Rank#1

Select any bar to hold its details here.

04

Source composition

One source network supplied half of the records.

The collection mix affects every comparison on this page. A larger slice can reflect source availability and collection coverage, not more real-world incidents.

Telegram · 50.0%14,931 collected records
50.0%Telegram
05

Confidence and limits

See which fields are complete before using the data.

Coverage varies by field. The consistency view compares values only where records could be matched across the collected and enriched sets.

Field coverageMetadata completeness
Matched fieldsCross-table consistency

Source network needs care. Its match rate was 69.4%, largely because the enriched set left the field blank on many records. Other shared fields matched above 99.5%.

06

Inspect the evidence

Open the details only when you need them.

The aggregate files contain counts and de-identified record snapshots. They do not include raw post bodies, organization lists or internal identifiers.

Three recordsDe-identified record snapshots

Loading record snapshots…

Seven stepsMethod and study limits

    Limits

    • Source availability and collection coverage change over time.
    • Labels can be incomplete, duplicated, misspelled or supplied by the original source.
    • The study does not deduplicate separate records that may describe one event.
    • Counts describe this dataset, not the whole threat landscape.

    Read the monitoring methodology and editorial policy.

    Reproducible filesDownloads and integrity checks
    CSV SHA-25639bc3edf967bb0493f7a974ed8099f6f4d2a6c4a4a77965757196759d017b035
    JSON SHA-256c0090084dca58fe163470757c320f02b1cb6353030537589a4e6d6eb46399fc3

    Check your own signal

    Move from aggregate patterns to one domain.

    Run a free lookup against the records currently available in the production index.

    Check a domain