AI Generated by Fortune India
India ranks second in APAC for ransomware attacks in H1 2026: ReportJuly 23, 2026, 18:00 IST
Loading AI Hub...
Disclaimer : Certain content on this page, including summaries, timelines, FAQs, glossaries, highlights, insights, and other supplementary informational features, maybe generated or assisted by artificial intelligence tools. While reasonable efforts are made to review and verify such content, AI generated output may occasionally contain errors, omissions or inconsistencies. Readers are advised to independently verify any information before relying upon them for professional, legal, financial, medical or other decisions. The publisher along with its affiliates and contributors do not warrant accuracy of AI-generated content and disclaim any liability, loss or damage arising from its use.

India ranks second in APAC for ransomware attacks in H1 2026: Report

/2 min read

ADVERTISEMENT

Surge in sophisticated ransomware and state-backed cyberattacks exposes vulnerabilities in India’s rapidly expanding digital economy
India ranks second in APAC for
 Credits: Shutterstock

India was the second most targeted country in the Asia-Pacific region for ransomware attacks in the first six months of 2026, according to a report by threat intelligence firm Cyble. This highlights the growing cybersecurity risks facing one of the world's fastest-growing digital economies

The Cyble Research and Intelligence Labs (CRIL) report found that India recorded 77 ransomware attacks between January and June, making it the ninth most targeted country globally. Within APAC, only Thailand, with 82 attacks, reported a higher number of ransomware victims.

Sign up for Fortune India's ad-free experience
Enjoy uninterrupted access to premium content and insights.

Researchers tracked 496 ransomware attacks, 19 data breach incidents and 20 initial access sale listings across APAC during the period.

The report points to an increasingly sophisticated threat landscape, with state-backed hacking groups playing a prominent role. Of the 123 threat actor profiles tracked in APAC, 54—about 44%—were nation-state advanced persistent threat (APT) groups. These included China-, North Korea- and Pakistan-linked actors such as SideCopy, SharpPanda, Kimsuky and UNC3886, which have historically targeted government agencies, defence organisations and enterprise IT infrastructure.

Manufacturing was the most attacked industry in the region, recording more than 49 ransomware incidents. IT and IT-enabled services followed with 30 attacks, while the banking, financial services and insurance (BFSI) sector saw 22 attacks. Consumer goods, professional services, healthcare and construction also featured among the sectors most frequently targeted.

Ransomware and underground cybercrime on rise

Ransomware groups also continued to consolidate their grip on the region. The report found that The Gentlemen was the most active ransomware-as-a-service (RaaS) operator, accounting for 114 victims or 23% of all attacks in APAC. Qilin followed with 64 victims (13%), while LockBit was linked to 38 victims (7.7%). Together, the three groups were responsible for more than two-fifths of all ransomware attacks recorded in the region.

Beyond ransomware, underground cybercrime markets remained active. Retail and professional services accounted for half of all initial access sale listings in APAC, while hacktivist campaigns targeted more than 4,500 domains across the region and generated nearly 700 data leak posts involving government, education and technology organisations.

"India's rapid digital transformation and expanding IT supply chain make it an incredibly attractive target for both state-sponsored espionage groups and financially motivated ransomware networks," said Kaustubh Medhe, VP – Research and Threat Intelligence.

"In H1 2026, double extortion has become the default operating procedure. Organizations can no longer rely solely on backup restoration—protecting network edges, securing initial access brokers' targets, and stopping data exfiltration before it happens are critical to national digital resilience," he added.

Globally, the report recorded 3,836 ransomware attacks and 367 data breach incidents during the first half of the year. It also analysed 146 vulnerabilities, with nearly 90% classified as critical or high severity. According to Cyble, internet-facing network and edge appliances from vendors including Ivanti, Fortinet, Cisco, SolarWinds and Palo Alto Networks continued to be among the most common entry points exploited by attackers.