India ranks second in APAC for ransomware attacks in H1 2026: Report
ADVERTISEMENT

India was the second most targeted country in the Asia-Pacific region for ransomware attacks in the first six months of 2026, according to a report by threat intelligence firm Cyble. This highlights the growing cybersecurity risks facing one of the world's fastest-growing digital economies
The Cyble Research and Intelligence Labs (CRIL) report found that India recorded 77 ransomware attacks between January and June, making it the ninth most targeted country globally. Within APAC, only Thailand, with 82 attacks, reported a higher number of ransomware victims.
Researchers tracked 496 ransomware attacks, 19 data breach incidents and 20 initial access sale listings across APAC during the period.
The report points to an increasingly sophisticated threat landscape, with state-backed hacking groups playing a prominent role. Of the 123 threat actor profiles tracked in APAC, 54—about 44%—were nation-state advanced persistent threat (APT) groups. These included China-, North Korea- and Pakistan-linked actors such as SideCopy, SharpPanda, Kimsuky and UNC3886, which have historically targeted government agencies, defence organisations and enterprise IT infrastructure.
Manufacturing was the most attacked industry in the region, recording more than 49 ransomware incidents. IT and IT-enabled services followed with 30 attacks, while the banking, financial services and insurance (BFSI) sector saw 22 attacks. Consumer goods, professional services, healthcare and construction also featured among the sectors most frequently targeted.
Ransomware and underground cybercrime on rise
Ransomware groups also continued to consolidate their grip on the region. The report found that The Gentlemen was the most active ransomware-as-a-service (RaaS) operator, accounting for 114 victims or 23% of all attacks in APAC. Qilin followed with 64 victims (13%), while LockBit was linked to 38 victims (7.7%). Together, the three groups were responsible for more than two-fifths of all ransomware attacks recorded in the region.
Beyond ransomware, underground cybercrime markets remained active. Retail and professional services accounted for half of all initial access sale listings in APAC, while hacktivist campaigns targeted more than 4,500 domains across the region and generated nearly 700 data leak posts involving government, education and technology organisations.
"India's rapid digital transformation and expanding IT supply chain make it an incredibly attractive target for both state-sponsored espionage groups and financially motivated ransomware networks," said Kaustubh Medhe, VP – Research and Threat Intelligence.
"In H1 2026, double extortion has become the default operating procedure. Organizations can no longer rely solely on backup restoration—protecting network edges, securing initial access brokers' targets, and stopping data exfiltration before it happens are critical to national digital resilience," he added.
Globally, the report recorded 3,836 ransomware attacks and 367 data breach incidents during the first half of the year. It also analysed 146 vulnerabilities, with nearly 90% classified as critical or high severity. According to Cyble, internet-facing network and edge appliances from vendors including Ivanti, Fortinet, Cisco, SolarWinds and Palo Alto Networks continued to be among the most common entry points exploited by attackers.