Executive Summary
Every 90 days, we review the latest cyber threat trends to identify what IT leaders should learn, where resilience gaps are widening, and what practical actions organisations should take next.ย
The first quarter of 2026 has been intense. The UK threat picture is not defined by one single malware family or one headline ransomware group.
Instead, it is being shaped by a broader rise in disruptive incidents, persistent phishing, growing supply-chain exposure, and more sophisticated abuse of identity, data and AI-enabled workflows. ย
The key trend in Q1 2026 is the accelerated exploitation of zero day and no dayย vulnerabilities within 24 hours. Most organisationsย can notย respond this quickly, but now need to. ย
The National Cyber Security Centre (NCSC) says it handledย 204 nationally significantย cyber attacksย in the 12 months to August 2025, up from 89 the year before,ย showing how quickly the operational pressure on UK organisations is rising.ย
Whilst automation is helping SOC teams (averageย 1stย line incident automation on average increased from 53% to 59%),ย benign and true positiveย triage toย resolution remained at an average ofย 154 minutes.ย ย
Key Cyber Threat Trendsย (last 90 days)ย
- Data theft is overtaking ransomware as the primary attack objectiveย ย
- AI-driven data exfiltration is becoming harder to detectย ย
- Attackers are increasingly targeting developers and third-party codeย ย
- Backup and recovery systems are now a primary targetย ย
- New phishing techniques likeย Clickfixย are rapidly emergingย ย
- Insider-led attacks are rising and taking longer to detectย ย
Data Theft Is Replacing Ransomware in 2026ย
Weโre seeing a clear move towards smaller, repeated data theft events. These may involve lower ransom demands, but they still create significant financial,ย regulatoryย and reputational risk.
These attacks donโt always trigger immediate disruption, which makes them harder to spot and easier to sustain over time.
The impact, however, is just as serious.
Data loss creates regulatory exposure, reputational damage and often leads to ongoing extortion. The difference is that it happens more quietly, and often for longer.
For IT leaders, itโs no longer enough to focus on preventing system disruption. You need visibility into how data is being accessed, used and potentially extracted.
Watch on-demand: You Paid the Ransom. Incident Response Teardown
The Rise of AI-Driven Data Exfiltration Attacksย
Dark settlements have become more complex andย frequent, butย so have the repeated events in these businesses seeking a faster resolution to exposures.ย
It is not the quantity but the content of the data which is being focused on and withย Shadow AI tools now widely prevalent.
Sensitive information is now being exposed through:
- prompts
- summaries
- analysis workflows
Visibility of these remains a key issue as traditionalย DLP detectionย techniques are less effective as these are not physical file changes or movements, rather through summarisation and analysis actions.ย ย
The NCSC warns that prompt injection and insecure AI integrations can give attackers paths into wider systems,ย while AIโs ability to summarise large volumes of information quickly can increase the efficiency and impact of data theft.ย
Action:ย Data Loss Preventionย remainsย difficult for many organisations to gain user and board support to progress beyondย initialย data classification and labelling.
Developer and Third-Party Risk Is Increasingย
Another consistent pattern is the growing risk across development environments and third-party relationships.
Organisations are shipping faster. Theyโre relying more on external developers, offshore teams, and AI-assisted coding tools. That speed brings efficiency, but also risk.
This is a longer term espionage tactic, where vibe coding, development expertise is being infused with DPRK capabilities in 3rd parties.ย These 3rdย parties areย off-shore, freelance, burst rapid application coding services.
Weโre seeing more cases where:
- third-party access isnโt fully controlled
- externally developed code isnโt properly validated
- trusted relationships are used as entry points
Organisational security and integrity validation of 3rdย party developed code has become more reliant on AI security tools inย thenย last 3 months and more issues areย remainingย undetected and evaded.ย ย
Action: Organisations need to rapidly improve development screening and verify the background checks on personnel, on shore andย off shore. They are working for your business so please verify.
Backup and Recovery Systems Are Being Targetedย
More recently, with so many organisations now adopting both immutable and tenant backups, adversarial entities are focusing on recovery denialย techniques.
Malicious entities are systematically targeting backup infrastructure, identity services, storageย containersย and MSP providers delivering these services.
The target is reducing the ability to recover a key service dependency quickly.ย ย
Clickfixย Is Emerging as a Common Attack Techniqueย
And the most common attack vector in the last 90 daysโฆ. is the Clickfixย technique.
Instead of asking users to click a link, they are prompted to:
- verify access
- join a meeting
- run a command to โfixโ an issue
We are observing more and more businesses fail to update key website services (usually a 3rdย party responsibility)ย and adversarial groups are using prompts to replicate on a phishing page, short term DNS hijacking for traffic redirection and asking users to executeย Powershellย to verify identity or legitimacy.
We’ve seen many fake CAPTCHAโsย but this has shifted to verification for meeting invitations and joining actions.ย ย
ย Attackย Vectors Last 90 Daysย
There is no change is the industry focus though in the last 90 days with Financial, Insurance, Business & Professional Services, Tech firms (MSP providers)ย and Healthcareย remainingย firmly the mostย frequentlyย researched and targeted.ย ย
They are also theย industriesย most rapidly adopting a wider spectrum of generative AI technologies.ย ย
- Exploitation combined with specifically targeted phishing email campaignsย remainย the predominantย initialย attack vectors. There was a significant increase in gaining access to an internal impersonated or compromise user account, to create mailbox forwarding rules to send phishing emails.ย ย
- The most common malicious attachment for Outlook application related malwareย isย financial documentsย using dynamic code execution capabilities in graphics and e-signature fields.ย ย
- The most common attack source isย Internal (52%)ย which alsoย observedย an increase in dwell time as well as attack evasion. Those organisations notย leveragingย user behavioural analysis are up toย 4 times slowerย in detection than those that do haveย UEBA activated.ย ย
AI tools are increasing the challenge of detecting IP and data theft across organisations.ย Research shows that 40% of knowledge workers admit to entering sensitive business information into public AI tools.ย
As many of these platformsย operateย under standard user privileges, they create new blind spots for security teams. As a result, insider risk controls need to become a much higher priority for businesses in 2026.ย
Learn more about AI-Driven risk here: The AI-Enabled Insider Threat – From Accidental Leaks to Intentional Knowledge Distillation
The Threat Has Changed. Has Your Strategy?ย
The key lesson from Q1 2026 is that cyber risk is broadening, not narrowing.
Ransomware still matters, but IT leaders should now plan for a wider range of outcomes: data theft, extortion, identity abuse, supplier compromise, destructive attacks on recovery systems and AI-enabled attack paths.
The organisations that respond fastest will be the ones that improve visibility across data, identity, third parties and recovery,ย not just endpoints.ย