The full briefing is available via Download PDF above. What follows is the same analysis, in web form.
Most threat actor writing is either a taxonomy with no numbers or a list of scary group names with no structure. This briefing is neither. It sets out the four categories that matter, shows where the boundaries between them have stopped holding, and puts the 2026 measurements against each one. Every figure is attributed to Mandiant’s M-Trends 2026, the CrowdStrike 2026 Global Threat Report, the ENISA Threat Landscape, the Swiss NCSC semi-annual report 2026/I or Europol.
The short version: attribution matters less than tempo. You are unlikely to know who is in your network while it matters, and the measured window between initial access and lateral movement is now well under an hour.
Why the same group has four different names
Before any of the numbers make sense, the naming problem has to be dealt with, because it is the single most common reason threat intelligence gets misread inside an organisation.
Each major vendor runs its own taxonomy, derived from its own telemetry:
| Vendor | Convention | Example |
|---|---|---|
| Microsoft | Weather — Blizzard (Russia), Typhoon (China), Sandstorm (Iran), Sleet (North Korea), Tempest (financially motivated) | Midnight Blizzard |
| CrowdStrike | Animals — Bear (Russia), Panda (China), Kitten (Iran), Chollima (North Korea), Spider (criminal) | COZY BEAR |
| Mandiant / Google | APT<n> for graduated groups, UNC<n> for uncategorised clusters | APT29, UNC2452 |
| Palo Alto Unit 42 | Constellations | Muddled Libra |
All four names in the first three rows refer to the same Russian state-nexus group. Similarly, the criminal group most people call Scattered Spider is Octo Tempest to Microsoft and Muddled Libra to Unit 42.
In June 2025 Microsoft and CrowdStrike published a joint mapping, later joined by Mandiant and Unit 42, deconflicting more than 80 adversaries. It is deliberately not a single naming standard — each vendor keeps its own system — but it is a usable translation table, published as JSON in Microsoft’s MSTIC repository.
Two practical consequences. First, counting “how many groups attacked us” across two vendor feeds without deconfliction will overstate the answer. Second, a group name is a cluster of observed activity, not a legal identification of an organisation. Treat it as a behaviour label, and you will use it correctly.
The four categories, and where they stop holding
| Category | Motivation | What success looks like to them | Typical dwell |
|---|---|---|---|
| State-nexus espionage | Intelligence | Remaining undiscovered for years | 122 days median |
| Cybercriminal | Money | Fast monetisation, encryption or extortion | Minutes to days |
| Hacktivist | Attention | Visible disruption, screenshots, claims | Transient |
| Insider and fraudulent worker | Money or access | Being paid a salary while collecting | 122 days median |
The categories still describe motivations well. What has broken down is the assumption that each category owns a distinct toolset — the finding ENISA calls convergence.
State-nexus groups now use criminal tooling and infrastructure. ENISA documents North Korea’s Kimsuky using the ClickFix technique, Andariel operating as an apparent affiliate of Play ransomware, Moonstone Sleet deploying Qilin, and China-nexus Mustang Panda leveraging RA ransomware. APT29 and Sandworm have been observed on commercial residential proxy networks, sharing hosting with criminals, and deploying commodity infostealers.
The traffic runs the other way too. The criminal group FIN6 adopted fabricated LinkedIn personas and job-application lures — a playbook borrowed directly from North Korea.
The Swiss NCSC makes the same point about the software supply chain: open-source package manipulation spans financially motivated groups and state actors alike, naming TeamPCP on one side and Lazarus Group and APT29 on the other.
What this means for defence. You cannot infer an actor’s category from their tooling, and you should not size your response to a guess about who it is. A commodity infostealer is no longer evidence of a commodity adversary.
Tempo is the finding that should change your plans
This is where the 2026 data is genuinely different from previous years.
| Measurement | 2026 figure | Prior | Source |
|---|---|---|---|
| Average eCrime breakout time | 29 minutes | 48 min (2024) | CrowdStrike |
| Fastest breakout on record | 27 seconds | — | CrowdStrike |
| Access broker hand-off to a second group | 22 seconds | >8 hours (2022) | Mandiant |
| Detections involving no malware | 82% | — | CrowdStrike |
| Increase in AI-enabled adversary activity | 89% | — | CrowdStrike |
Breakout time is the interval between initial access and lateral movement onto a second system. At 29 minutes on average, an alert that waits in a tier-one queue has already been overtaken. In one CrowdStrike-observed intrusion, exfiltration began four minutes after initial access.
The 22-second figure deserves separate attention. Mandiant found a growing division of labour in which one group obtains access and hands it to another for follow-on operations — present in 9% of 2025 investigations, up from 4% in 2022. The hand-off no longer routes through a forum sale, so the delay that used to give defenders a window has gone.
Dwell time went the wrong way, for an instructive reason
Global median dwell time rose to 14 days from 11. That looks like defensive failure, and mostly is not.
- Internally detected intrusions improved, from 10 days to 9
- Externally notified intrusions doubled, from 11 days to 25
- Espionage and North Korean IT worker cases sat at 122 days, some beyond a year
The mix changed rather than the competence. Long-dwell espionage increasingly persists on edge devices — VPNs, firewalls and boundary appliances that lack standard telemetry. The average got worse because a category most programmes are not instrumented for got bigger.
How they actually get in
For the sixth consecutive year, Mandiant found exploitation of internet-facing systems the leading initial infection vector.
| Initial infection vector | 2025 | 2024 |
|---|---|---|
| Exploits | 32% | Leading vector |
| Voice phishing | 11% | — |
| Email phishing | 6% | 14% |
Two shifts matter here. Email phishing more than halved, while voice phishing rose to second place. Attackers moved to interactive, rapport-building social engineering against help desks and IT support, because it is far more resilient to automated technical controls than a message that can be filtered.
The Swiss NCSC observed exactly this pattern domestically: attackers contacting victims over Microsoft Teams while posing as IT helpdesk staff, and using a pending security update as a pretext to deliver malware.
On the exploitation side, the target is increasingly the edge. CrowdStrike found 40% of vulnerabilities exploited by China-nexus actors targeted edge devices. The NCSC describes inadequately protected edge devices as a key gateway into Swiss networks and as raw material for wider attack infrastructure.
The Static Tundra case in the NCSC report is worth reading in full, because the failures are ordinary rather than exotic. A Russian state-nexus actor reached operational technology through unpatched end-of-life network devices where remote access was exposed directly to the internet without MFA, passwords were reused across devices, and some equipment still carried factory default credentials. The attackers then corrupted firmware, deleted operating system files and deployed wiper malware.
What the Swiss data actually shows
Switzerland has an unusually good public dataset since mandatory reporting for critical infrastructure began on 1 April 2025. The NCSC’s report for the first half of 2026 recorded 27,128 voluntary reports — down from 35,727 in the first half of 2025 — and 200 mandatory notifications.
The mandatory reports are the more useful signal, because they come from critical infrastructure operators rather than the public:
| Reported attack type | Share of 200 mandatory reports |
|---|---|
| Unauthorised access (hacking) | ~26% |
| Theft of login credentials | 13.5% |
| DDoS | 12.7% |
| Data leaks | 12.7% |
| Ransomware and extortion | ~8% |
Public administration (19.4%) and IT and telecommunications (18.6%) reported the most. Note how modest the ransomware share is against how much attention it receives — and note that the largest category, unauthorised access, largely means compromised email accounts used to run further phishing and fraud.
Ransomware in Switzerland is flat in volume and fragmenting in structure. The NCSC recorded 79 incidents, identical to the previous half-year. Underneath that stable number, the number of active ransomware families rose from 21 to 29, and Akira — still the most documented group in the country — saw its share fall from around 35% to 19%.
Two other Swiss findings are worth carrying into a risk assessment:
- No targeted cyber sabotage against Swiss critical infrastructure has been observed to date, but the NCSC is explicit that this depends on geopolitics, and that Swiss infrastructure could become a proxy target because of its interconnection with neighbouring states.
- Some victim listings are false. Several Swiss organisations named on leak sites during the period turned out not to be victims at all. Treat a leak-site listing as a claim to verify, not a fact.
Law enforcement is working, which is part of why the ecosystem fragmented
2026 saw sustained action against shared criminal infrastructure rather than individual gangs.
Operation Saffron (19–20 May 2026) dismantled First VPN, described by Europol as the most widely used anonymity service in the cybercrime underground and present in almost every major investigation it had supported. A four-and-a-half-year investigation led by France and the Netherlands across 27 countries seized 33 servers, arrested the administrator, and — the important part — recovered the user database, identifying 506 users and feeding 21 other investigations.
The AudiA6 takedown (10 June 2026) hit the cash-out layer instead, dismantling a laundering service that had processed more than €336 million between 2022 and 2025 and was linked to more than 15 ransomware investigations.
This pressure is real, and it has a second-order effect visible in the Swiss numbers. When affiliates are displaced — the NCSC cites the leak of the group The Gentlemen’s own data in early May — they move to other groups. Enforcement success shows up as fragmentation, not as fewer attacks. Twenty-nine ransomware families are harder to track than 21, even when the incident count is unchanged.
What should you do in the next ninety days?
The tempo data points at a specific, unglamorous conclusion: you cannot out-respond a 29-minute breakout, so the leverage sits before the intrusion.
Days 0–30 — Reduce what is reachable. Enumerate internet-facing systems, and treat VPNs, firewalls and boundary appliances as the priority rather than the afterthought — they are simultaneously the leading exploitation target and the place long-dwell espionage hides. Verify MFA on every remote access path, check for reused and default credentials on network and OT equipment, and confirm end-of-life devices are actually gone.
Days 31–60 — Instrument the gap. Edge devices lack standard telemetry, which is precisely why dwell time on them is measured in months. Establish what logging those devices can produce and where it goes. Separately, rehearse the help desk: define an out-of-band verification step for password and MFA resets, because voice phishing is now the second most common way in and it targets that workflow specifically.
Days 61–90 — Rebase the plan on tempo. Re-examine any response process whose assumptions predate a 29-minute breakout time. Decide in advance what gets contained automatically rather than after triage. Deconflict your threat intelligence feeds against the joint vendor mapping so you are not double-counting adversaries, and drop any control whose value depends on knowing the attacker’s identity early.
Five questions for the next board meeting
- Which internet-facing devices could an attacker reach today, and when did we last verify that list rather than consult it?
- Do our VPNs, firewalls and other edge appliances produce logs we actually collect — and if not, how would we ever detect a 122-day intrusion?
- What happens when someone calls our help desk claiming to be an executive locked out of their account?
- If a leak site named us tomorrow, who confirms whether it is true, and how long does that take?
- Our incident response plan assumes how long between initial access and lateral movement — and is that number still 29 minutes or better?
The pattern across all of this year’s data is that identity of the attacker matters less than the state of your exposure. Breakout time, hand-off time and edge-device dwell time all describe the same problem from different angles: the attacker’s speed is now a property of the ecosystem, while your reachable surface is one of the few things still under your control.
That is the work Panop is built for — knowing what you expose, which of it is reachable, and which findings an attacker could actually use. See attack surface discovery, autonomous penetration testing, risk prioritisation and third-party risk, or book a demo.
Sources
Figures are reproduced as published by the cited source and were current at the edition date. Threat intelligence figures are vendor telemetry, not census data: different vendors measure different populations, and the absolute numbers should be read as direction and magnitude rather than precision.
- Mandiant / Google Cloud — M-Trends 2026
- CrowdStrike — 2026 Global Threat Report
- ENISA — Threat Landscape
- Swiss National Cyber Security Centre — Semi-annual report 2026/I
- Microsoft — Strategic collaboration on threat actor naming and the MSTIC actor mapping
- Europol — European Cybercrime Centre
- Computer Weekly — Operation Saffron and the First VPN takedown
- BleepingComputer — AudiA6 crypto-laundering takedown