Fortinet, Inc.

NASDAQ Global Select
Neutral 0

The Fortinet 2026 Global Threat Landscape Report Reveals a Surge in AI-Enabled Cybercrime, Contributing to a 389% Increase in Ransomware Victims Year-over-Year

πŸ“Š The 2026 Global Threat Landscape Report, released by Fortinet on April 30, 2026, reveals that AI-enabled cybercrime has driven a massive surge in attacks.

πŸ’° Ransomware victims globally skyrocketed to 7,831 confirmed cases in 2025 compared to roughly 1,600 in 2024.

πŸ€– This dramatic increase is attributed to crime service kits like WormGPT and FraudGPT enabling criminals to operate more efficiently.

⏱️ The time-to-exploit (TTE) for critical outbreaks has shrunk significantly from 4.76 days to just 24–48 hours due to AI acceleration.

🏭 Manufacturing, business services, and retail were the top three targeted sectors with over 1,200 victims in the manufacturing sector alone.

πŸ‡ΊπŸ‡Έ The United States was the primary geographic concentration of ransomware victims, accounting for 3,381 of the total cases.

☁️ Most cloud incidents stem from stolen or misused credentials rather than infrastructure exploitation due to identity sprawl.

πŸ€– Shadow agents and semi-autonomous criminal enterprises now reduce operator skill requirements while increasing workflow speed.

πŸ’» Brute force attempts decreased by 22% year-over-year as criminals use optimized techniques targeting better-selected credentials.

πŸ“‰ Despite fewer brute force attempts, global exploitation attempts increased by 25.49% due to intelligent targeting.

πŸ—ƒοΈ Stealer logs representing compromised systems now dominate dark web data activity at over 67%, surpassing leaked credentials.

πŸ” RedLine malware remains the most prevalent credential-stealer with nearly 1 million infections in 2025.

🌐 Fortinet's report highlights a shift toward AI-driven tools that compress the cyberattack life cycle and operate as integrated systems.

πŸ›‘οΈ Derek Manky, Chief Security Strategist at FortiGuard Labs, states defenders must industrialize cybersecurity operations to match threat velocity.

Bullish Signals
  • Fortinet, the global cybersecurity leader driving the convergence of networking and security, released the 2026 Global Threat Landscape Report derived exclusively from its proprietary FortiGuard Labs telemetry.
  • The report provides a comprehensive analysis across all tactics used in cyberattacks as outlined in the MITRE ATT&CK framework, offering deep visibility into the active threat landscape.
  • Fortinet is actively committed to disrupting cybercrime by collecting and sharing threat intelligence on a global scale to combat threats proactively.
  • FortiRecon adversary intelligence identified 7,831 confirmed ransomware victims globally in 2025, providing clear metrics that Fortinet's security platforms can detect and prevent against this specific threat vector.
  • Fortinet's leadership, including Chief Security Strategist Derek Manky, is emphasizing the evolution of cybersecurity operations into an industrialized defense model equipped with AI-enabled tools.
  • The report highlights the critical need for velocity in defense, reinforcing Fortinet's position as a provider of solutions that respond at the same speed as modern AI-accelerated threats.
  • FortiCNAPP intelligence is actively monitoring cloud exposure, identifying specific risks like stolen credentials to help clients secure their federated access models.
Risk Factors
  • The time-to-exploit for critical outbreaks has shrunk drastically from 4.76 days to just 24–48 hours as AI accelerates reconnaissance, weaponization, and execution.
  • Confirmed ransomware victims globally skyrocketed to 7,831 in the period covered, a 389% increase year-over-year from approximately 1,600 victims reported in 2025.
  • Availability of AI-enabled crime service kits such as WormGPT, FraudGPT, and BruteForceAI directly contributed to the massive surge in ransomware attacks targeting sectors like manufacturing (1,284 victims), business services (824), and retail (682).
  • Cloud exposure risks have intensified with stolen, exposed, or misused credentials identified as the origin of most confirmed cloud incidents, particularly in hospitals/physician clinics and retail establishments.
  • Threat actors are working more efficiently with fewer brute force attempts due to optimized AI techniques; while global brute force events dropped by 22% year-over-year, exploitation attempts increased by 25.49% YoY.
  • Data theft via infostealer malware has surged with a combined 500% increase in logs observed in 2025 and an additional 79% increase detected in 2026, shifting attacks toward comprehensive dataset theft.
  • Credential-stealer malware remains a lucrative upstream engine for exposure, with RedLine accounting for over half (50.80%) of stealer activity followed by Lumma (27.84%) and Vidar (13.19%).
  • Stealer logs now dominate dark web database activity at 67.12%, reducing attacker effort by bundling identity material with contextual artifacts for immediate replay.
  • Malicious hackers operate as semi-autonomous enterprises supported by shadow agents, access brokers, and botnet operators who provide AI-enabled offensive services on demand.
Full Analysis
Fortinet (NASDAQ: FTNT) released its 2026 Global Threat Landscape Report, driven by FortiGuard Labs telemetry from 2025, which details a dramatic escalation in AI-enabled cybercrime. The report indicates that malicious actors are transitioning from isolated campaigns to functioning as semi-autonomous enterprises supported by shadow agents and botnet operators. A primary consequence of this shift is a massive increase in ransomware attacks, with confirmed victims rising from approximately 1,600 in 2025 to 7,831 globally, representing a 389% year-over-year increase. This surge is attributed to the availability of AI-powered crime service kits such as WormGPT, FraudGPT, and new tools like BruteForceAI that automate reconnaissance and penetration testing. The velocity of attacks has also accelerated significantly; the time-to-exploit (TTE) for critical outbreaks has compressed from 4.76 days to just 24–48 hours due to AI accelerating weaponization and execution. Specific data points highlight that brute force attempts have decreased by 22% year-over-year as criminals use intelligence to optimize attacks against better-selected targets, yet global exploitation attempts have risen by 25.49%, totaling approximately 67.65 billion events in the reported period. Furthermore, there has been a distinct shift from stolen leaked credentials toward the theft of comprehensive datasets via infostealer malware like RedLine and Lumma, with stealer logs now dominating dark web database activity at 67.12%. Identity sprawl continues to define cloud exposure, where most confirmed incidents stem from stolen or misused credentials rather than infrastructure exploitation alone. Hospitals, physician clinics, retail, manufacturing, and business services are identified as top targets for these sophisticated threats. The report emphasizes that defenders must evolve cybersecurity operations into an industrialized defense capable of matching the velocity of modern, AI-driven threats to effectively disrupt these criminal ecosystems.