AdverseMonitor house promotionSearch the live index before an exposure becomes an incidentCheck a domain →
← All threat advisories

Threat intelligence

Dark Web, AI and Ransomware: Trends Security Teams Should Watch

AdverseMonitor Team12 min read
Original visual analysis for this threat advisory
AdverseMonitor original analysis visual, created for this advisory.

Executive summary

Risk context: verify
  • This article tracks eight threat trends and the observable signals a security team can use to test each one against its own environment. A trend is a claim to measure, not an observed event.
  • The trends cover attacker use of AI, fragmented criminal channels, extortion, supply chains, identity systems, quantum preparation, regulation, and staffing.
  • Where the AdverseMonitor H1 2026 threat data study supports or contradicts a trend, the section says so. That study covers 29,858 collected source records from January through June 2026 and counts observations, not confirmed incidents.
Eight trends
Treat each trend as a claim to measure against observed incidents, first-party data, and published evidence

This article tracks eight threat trends and the observable signals a security team can use to test each one. Earlier versions of this piece were written as year-bound forecasts. The trends have outlived the calendar, so this version drops the dates and keeps the reasoning, the signals to watch, and a check against first-party data where one exists.

The trends cover attacker use of AI, fragmented criminal channels, extortion, supply chains, identity systems, quantum preparation, regulation, and staffing. Where the AdverseMonitor H1 2026 threat data study supports or contradicts a trend, the section says so. That study covers 29,858 collected source records from January through June 2026. It counts observations, not confirmed incidents, and its mix reflects collection coverage as much as attacker behaviour.

Trend 1: AI-Assisted Attacks Become Ordinary Tooling

Attackers already use automation and generated content. The useful measure for a defender is where a model changes attack volume, variation, or targeting, rather than whether a given campaign was AI-driven. Most campaigns leave no reliable marker of model use, so the question rarely has a clean answer.

Where Models Change the Work

  • Vulnerability discovery: Models help scan code and infrastructure and triage the results, which shortens the gap between a public disclosure and the first exploitation attempts
  • Personalised phishing: Language models draft context-aware messages in any language, so spelling and grammar stop working as filters
  • Adaptive tooling: Generated variants of scripts and loaders reduce the value of static signatures
  • Synthetic voice and video: Generated media used in impersonation attempts against help desks and finance staff

Signals to Watch

Track phishing volume per targeted user, the share of lures written in the recipient's own language, and the time from a public advisory to the first exploitation attempt against your perimeter. A rise in variation with no visible rise in operator skill is the clearest sign of model assistance.

The H1 2026 study does not record whether a post or lure was produced with model assistance, so it neither supports nor contradicts this trend. A model does not reduce breach impact by itself either. Measure the controls, data, analyst decisions, and response changes around it.

What This Means for Organizations

Rule-based tools can miss variations they were not written to match. Test model-based detection against the same attack set before adding it to a response path, and keep a human review step in front of any automated block.

Trend 2: Criminal Channels Fragment Across Messaging Platforms

Law enforcement actions against large marketplaces push sellers toward smaller forums, direct messages, and replacement sites. The degree of fragmentation is measurable rather than certain, and the answer depends on which sources a collector can actually see.

Key Shifts

  • Messaging platforms as markets: Telegram channels and groups used for initial access sales, leak announcements, and DDoS claims
  • Smaller, specialized markets: Niche marketplaces focusing on specific data types, industries, or regions
  • Direct seller-buyer relationships: Criminals using encrypted messaging for transactions, bypassing markets entirely
  • Regional platforms: Language-specific communities serving local cybercriminal groups

What the H1 2026 Data Shows

The AdverseMonitor H1 2026 threat data study supports this trend for the sources it covers. Telegram supplied 14,931 of the 29,858 collected records (50.0%), the open web 9,830 (32.9%), and Tor sites 5,096 (17.1%). Discord contributed one record. Read the split as a statement about where public claims are posted and where collection reaches, not as a census of the criminal economy.

Monitoring Implications

Monitoring only traditional dark web forums can miss records posted on public messaging channels or regional platforms. Buyers should verify which sources a provider collects instead of assuming channel-wide coverage.

Signals to Watch

Track the share of records naming your organization by source network over successive months, and log the first-seen source for each new listing. A rising share from messaging channels or regional forums, or listings that appear there before any leak site, shows the fragmentation reaching your own exposure.

Trend 3: Extortion Moves Beyond Encryption

Encryption remains common, but the pressure applied to victims increasingly comes from stolen data rather than downtime. Groups publish victim names before any negotiation starts, and some skip encryption entirely.

Extortion Tactics

  • Data destruction threats: Threatening to permanently delete data rather than only encrypt it
  • Customer notification: Directly contacting victims' customers about a breach
  • Regulatory pressure: Threatening to report the victim to a privacy or securities regulator
  • Timed disclosure: Releasing claims to coincide with earnings or deals at publicly traded companies
  • Supply chain leverage: Attacking vendors to pressure their customers

What the H1 2026 Data Shows

In the H1 2026 study, records labelled Ransomware numbered 4,502 (15.1% of the set). Records labelled Data Breach (5,882) and Data Leak (3,420) together came to 9,302, roughly twice the ransomware count. Labels describe the collected post, not a confirmed intrusion, and separate posts can describe one event. Even so, the mix is consistent with extortion that leads with data rather than encryption.

Payment reports vary by dataset and reporting period. Track the source, sample, and methodology before using a payment trend in planning.

Signals to Watch

Count leak-site listings that name your organization, your suppliers, or your customers, and record the time between a listing and any contact from the group. Both numbers come straight from monitoring and need no payment data.

Trend 4: Supply Chain Attacks Remain a Multiplier

The SolarWinds and MOVEit incidents show how one supplier can affect many customers. Track dependency abuse, vendor access, and managed-service incidents to assess whether this vector is expanding for your own supplier base.

High-Risk Areas

  • Open source dependencies: Compromised npm, PyPI, and Maven packages
  • MSP/MSSP targeting: Attacking managed service providers to reach their clients
  • CI/CD pipeline poisoning: Injecting malicious code during build processes
  • Hardware implants: Nation-state actors compromising manufacturing supply chains

What the H1 2026 Data Shows

The study does not classify supply-chain incidents as a category, so it cannot confirm growth. It does show 846 records carrying the Information Technology (IT) Services industry label and 239 carrying Software Development, sectors whose customers inherit the exposure. Industry metadata was populated on 57.7% of records, so treat these counts as leads for third-party review, not as a supply-chain total.

What Organizations Should Do

Maintain a software bill of materials (SBOM), set vendor security requirements in contracts, and monitor for records that name your suppliers as well as your own domains.

Trend 5: Identity Is the Primary Attack Surface

As network perimeters dissolve and organizations adopt zero-trust designs, attackers move to identity systems. A valid session is cheaper than an exploit and harder to distinguish from normal use.

Identity-Focused Threats

  • Credential marketplace growth: Dark web markets and channels specializing in enterprise credentials
  • MFA bypass techniques: Adversary-in-the-middle attacks, MFA fatigue, and SIM swapping
  • Identity provider targeting: Attacks on Okta, Entra ID, and other identity providers
  • Session token theft: Post-authentication token harvesting and replay

What the H1 2026 Data Shows

Records labelled Initial Access, the category that covers offers of credentials, VPN access, and similar footholds, numbered 3,526 in the H1 2026 study (11.8% of the set). Combo List (35) and Logs (4) labels were rare in this collection, which says more about where stealer output is traded than about its volume. Use the initial access figure as the observable share and check identity logs for the rest.

Identity logs and confirmed account-takeover cases show how credentials contribute to incidents in your environment.

Signals to Watch

Count MFA prompts declined per user, impossible-travel sign-ins, and new OAuth grants to unknown applications. A rise in any of them without a matching rise in phishing reports points to session theft rather than fresh phishing.

Trend 6: Quantum Preparation Becomes a Planning Item

Practical quantum attacks on current public-key cryptography remain years away, and the migration will take years as well. The work now is to inventory what depends on long-lived confidentiality and start the swap where it costs least.

The "Harvest Now, Decrypt Later" Threat

Some adversaries may collect encrypted data for later decryption. Organizations that hold long-lived secrets, including government, healthcare, and financial data, can begin by inventorying cryptographic dependencies.

Preparation Steps

  • Inventory all cryptographic dependencies
  • Identify data with long-term confidentiality requirements
  • Begin testing NIST-approved post-quantum algorithms
  • Develop migration roadmaps

The H1 2026 study has no view on this trend. It collects threat records, not cryptographic inventories. The signals live in your own systems: the share of external TLS endpoints and VPN tunnels that support a post-quantum key exchange, and the list of data stores whose confidentiality requirement outlasts the migration.

Trend 7: Regulatory Pressure Keeps Rising

Cybersecurity regulation continues to expand, creating new reporting duties and liability exposure. The specific rules differ by jurisdiction, but the direction is consistent: shorter reporting windows and more personal accountability for the people who sign off on security.

Key Regulatory Developments

  • Securities incident reporting: Four-business-day disclosure requirements for material incidents at US-listed companies
  • EU NIS2 Directive: Expanded scope and stricter requirements for essential and important entities
  • State privacy laws: California, Colorado, Virginia, and others creating patchwork requirements
  • Board accountability: Increasing personal liability for executives and board members

Impact on Organizations

Security teams will spend more time on compliance documentation and incident reporting. Organizations without a documented program face larger penalties and more reputational damage when a reportable incident lands. The H1 2026 study adds one relevant reading: Government Administration was the most common industry label (2,941 records), followed by Education (1,200). Public bodies that fall under expanded reporting rules are also the ones most often named in collected claims, so reporting duties and monitoring findings will overlap.

Signals to Watch

Count the jurisdictions whose reporting duties apply to you and review the list each quarter. Record the number of incidents per quarter that reached a materiality or notification decision, and the time from detection to that decision. A growing jurisdiction count with a shrinking decision window shows the pressure landing on your own process.

Trend 8: AI Changes Security Work, but Senior Roles Remain

Security teams remain short of experienced staff, and AI is beginning to change what that shortage means in practice.

What's Shifting

  • AI assistance: Analysts can use models to draft queries or summarize records, subject to review
  • Automation of routine tasks: SOAR platforms handling more alerts without human intervention
  • Skill requirements changing: Teams need staff who can test model output and recognize unsafe recommendations

Senior practitioners still design controls, lead incident response, and make risk decisions. Staffing data will show whether automation changes demand for those roles. Signals to watch inside a team: the share of tier-one alerts closed without an analyst touching them, the error rate a reviewer finds when sampling model-drafted queries, and time-to-hire for senior incident-response roles. The H1 2026 study has nothing to say about staffing.

Turning Trends Into Measures

Turn each trend into an observable measure: confirmed attack technique, source shift, identity event, supplier incident, regulatory change, or staffing outcome. Set a baseline before you claim a direction. The H1 2026 study is a useful reminder here: monthly collected volume peaked at 6,148 in March and fell to 4,031 in April, and the series did not move in one direction across six months. A single month proves little.

Immediate Priorities

  1. Expand threat intelligence coverage beyond traditional dark web forums
  2. Test model-based detection against your own attack set before relying on it
  3. Strengthen identity security with phishing-resistant MFA
  4. Audit supply chain security including software dependencies
  5. Develop incident response playbooks for data-led extortion

Stay Ahead of Emerging Threats

AdverseMonitor tracks publicly posted cyber-incident claims: ransomware and extortion leak-site posts, data-breach and data-leak listings, DDoS, defacement and initial-access offers, drawn from sources including Telegram channels, Tor sites and the open web, and raises a dashboard alert when your organisation, domain, industry or country is named.

Check a Domain

Related Reading

SHARE / SEARCHXLinkedInFacebook