India Second Most Ransomware-targeted APAC Nation in H1 2026: Report
India ranks among top 10 ransomware targets globally as APAC records 496 ransomware attacks in H1 2026: Cyble.
India ranks at the ninth position among the most ransomware-targeted countries, according to the latest report by Cyble Research and Intelligence Labs (CRIL).
The Global Threat Landscape Report H1 2026 covers 77 ransomware attacks during the first six months of 2026. With 82 attacks. Thailand stood at the top in the APAC region.
Key India & APAC Highlights (H1 2026)
- India among top ransomware targets: Ranked 9th globally with 77 ransomware attacks, second only to Thailand (82 attacks) in APAC.
- APAC threat landscape: CRIL recorded 496 ransomware attacks, 19 data breach incidents, and 20 initial access listings across APAC between January and June 2026.
- Highest state APT exposure: APAC recorded the highest proportion of Advanced Persistent Threat (APT) groups globally. Of 123 threat actor profiles, 54 (44 percent) were nation-state actors linked to China, North Korea, and Pakistan.
- Most targeted industries:
- Manufacturing – 49+ attacks
- IT & ITES – 30 attacks
- BFSI – 22 attacks
- Consumer Goods, Professional Services, Healthcare, and Construction were also among the most targeted sectors.
- Ransomware groups: The Gentlemen (114 victims), Qilin (64 victims), and LockBit (38 victims) accounted for over 43 percent of ransomware attacks across APAC.
- Retail and Professional Services accounted for 50 percent of all initial access sale listings in APAC.
- More than 4,500 regional domains were targeted, resulting in nearly 700 data leak posts across government, education, and technology sectors.
Global Highlights (H1 2026)
While APAC faced severe targeted pressure, Cyble’s H1 2026 global metrics show the sheer scale of the threat landscape:
- Global ransomware: 3,836 ransomware attacks recorded worldwide.
- Global data breaches: 367 data breach incidents, with the BFSI sector the most affected.
- Critical vulnerabilities: Of 146 CVEs analyzed, nearly 90 percent were rated critical or high severity. Network and edge appliances, including Ivanti, Fortinet, Cisco, SolarWinds, and Palo Alto Networks, remained major attack vectors.
Kaustubh Medhe, VP – Research and Threat Intelligence, said, “India’s rapid digital transformation and expanding IT supply chain make it an incredibly attractive target for both state-sponsored espionage groups and financially motivated ransomware networks. In H1 2026, double extortion has become the default operating procedure. Organizations can no longer rely solely on backup restoration protecting network edges, securing initial access brokers’ targets, and stopping data exfiltration before it happens are critical to national digital resilience.”
India ranks at the ninth position among the most ransomware-targeted countries, according to the latest report by Cyble Research and Intelligence Labs (CRIL).
The Global Threat Landscape Report H1 2026 covers 77 ransomware attacks during the first six months of 2026. With 82 attacks. Thailand stood at the top in the APAC region.
Key India & APAC Highlights (H1 2026)
- India among top ransomware targets: Ranked 9th globally with 77 ransomware attacks, second only to Thailand (82 attacks) in APAC.
- APAC threat landscape: CRIL recorded 496 ransomware attacks, 19 data breach incidents, and 20 initial access listings across APAC between January and June 2026.
- Highest state APT exposure: APAC recorded the highest proportion of Advanced Persistent Threat (APT) groups globally. Of 123 threat actor profiles, 54 (44 percent) were nation-state actors linked to China, North Korea, and Pakistan.
- Most targeted industries:
- Manufacturing – 49+ attacks
- IT & ITES – 30 attacks
- BFSI – 22 attacks
- Consumer Goods, Professional Services, Healthcare, and Construction were also among the most targeted sectors.
- Ransomware groups: The Gentlemen (114 victims), Qilin (64 victims), and LockBit (38 victims) accounted for over 43 percent of ransomware attacks across APAC.
- Retail and Professional Services accounted for 50 percent of all initial access sale listings in APAC.
- More than 4,500 regional domains were targeted, resulting in nearly 700 data leak posts across government, education, and technology sectors.
Global Highlights (H1 2026)
While APAC faced severe targeted pressure, Cyble’s H1 2026 global metrics show the sheer scale of the threat landscape:
- Global ransomware: 3,836 ransomware attacks recorded worldwide.
- Global data breaches: 367 data breach incidents, with the BFSI sector the most affected.
- Critical vulnerabilities: Of 146 CVEs analyzed, nearly 90 percent were rated critical or high severity. Network and edge appliances, including Ivanti, Fortinet, Cisco, SolarWinds, and Palo Alto Networks, remained major attack vectors.
Kaustubh Medhe, VP – Research and Threat Intelligence, said, “India’s rapid digital transformation and expanding IT supply chain make it an incredibly attractive target for both state-sponsored espionage groups and financially motivated ransomware networks. In H1 2026, double extortion has become the default operating procedure. Organizations can no longer rely solely on backup restoration protecting network edges, securing initial access brokers’ targets, and stopping data exfiltration before it happens are critical to national digital resilience.”