Global Ransomware Surge Drives 212 New Extortion Claims as Manufacturing Leads Sector Targeting
الارتفاع العالمي لبرمجيات الفدية يدفع نحو تسجيل 212 مطالبة ابتزاز جديدة، وقطاع التصنيع يتصدر القطاعات المستهدفة
Forsan's weekly threat intelligence review tracks 212 new extortion claims from September 13 to September 20, 2026, dominated heavily by ransomware operations targeting manufacturing and technology.
تتتبع مراجعة استخبارات التهديدات الأسبوعية لشركة "فرسان" 212 مطالبة ابتزاز جديدة في الفترة من 13 إلى 20 سبتمبر 2026، والتي هيمنت عليها بشكل كبير عمليات برمجيات الفدية التي تستهدف قطاعي التصنيع والتكنولوجيا.
During the monitoring period from September 13 to September 20, 2026, our threat intelligence team tracked a total of 212 new extortion and cyber incident claims globally. The landscape continues to be overwhelmingly dominated by ransomware operations rather than disruptive attacks, with 210 claims attributed to ransomware groups compared to just 2 hacktivist or DDoS incidents. Organizations across all verticals must recognize that financially motivated encryption and data theft remain the primary vector of choice for modern cybercriminal enterprises.
Of the total volume recorded this week, 79 claims were classified as high or critical severity, underscoring the severe operational and data-exposure risks facing victims. Among geographic tags, 2 claims were explicitly tagged to the Middle East. While this specific regional count represents a small fraction of the global total, it serves as an important reminder that regional organizations remain within the operational scope of globally active threat groups and must maintain rigorous defensive postures.
An analysis of the threat actor landscape reveals active participation from several prominent extortion groups. The most active actor this week was thegentlemen with 31 claims, closely followed by qilin with 30 claims. Unattributed groups accounted for 20 claims, while N0n and akira each recorded 11 claims. The heavy concentration of activity among a handful of prolific syndicates indicates well-resourced operations with systematic approaches to target acquisition and victim shaming.
Looking at the sectoral distribution, the manufacturing sector bore the brunt of this week's activity with 32 claims, followed closely by technology with 24 claims and professional services with 20 claims. Rounding out the top five most-targeted sectors were healthcare with 12 claims and financial services with 11 claims. The heavy targeting of manufacturing and technology typically reflects the high cost of operational downtime in these industries, which extortionists leverage to pressure victims into paying demands.
On the vulnerability front, the most severe vulnerability highlighted this week was CVE-2026-90770, carrying a CVSS score of 8.8. High-severity flaws of this nature frequently serve as initial access vectors for automated exploitation or targeted intrusions before deployment of payloads. Security teams should prioritize vulnerability management and rapid patching to mitigate these entry points.
In light of these aggregated trends, Forsan advises organizations to review their defensive readiness, focusing particularly on robust data backup strategies, endpoint detection and response capabilities, and rapid patch management for high-severity vulnerabilities. Maintaining visibility across supply chains and critical infrastructure is essential to disrupting the initial access and lateral movement phases utilized by top-tier ransomware syndicates.
خلال فترة المراقبة من 13 إلى 20 سبتمبر 2026، تتبع فريق استخبارات التهديدات لدينا ما إجماليه 212 مطالبة جديدة للابتزاز والحوادث السيبرانية على مستوى العالم. ولا يزال المشهد يهيمن عليه بشكل ساحق عمليات برمجيات الفدية بدلاً من الهجمات التخريبية، حيث تُعزى 210 مطالبات إلى مجموعات برمجيات الفدية مقارنة بحادثين اثنين فقط لهجمات "هاكتيفيزم" (نشطاء السيبرانية) أو حجب الخدمة الموزعة (DDoS). ويجب على المؤسسات عبر جميع القطاعات إدراك أن التشفير بغرض تحقيق مكاسب مالية وسرقات البيانات يظل ناقل الاختيار الأساسي للمؤسسات الإجرامية السيبرانية الحديثة.
من إجمالي الحجم المسجل هذا الأسبوع، تم تصنيف 79 مطالبة على أنها ذات خطورة عالية أو حرجة، مما يؤكد المخاطر التشغيلية الخطيرة ومخاطر تعرض البيانات التي تواجهها الضحايا. ومن بين العلامات الجغرافية، تم تحديد مطالبتين صراحةً لمنطقة الشرق الأوسط. وفي حين أن هذا العدد الإقليمي المحدد يمثل جزءاً صغيراً من الإجمالي العالمي، إلا أنه بمثابة تذكير مهم بأن المؤسسات الإقليمية تظل ضمن النطاق التشغيلي لمجموعات التهديد النشطة عالمياً ويجب عليها الحفاظ على وضعيات دفاعية صارمة.
يكشف تحليل مشهد الجهات الفاعلة المهددة عن مشاركة نشطة من عدة مجموعات بارزة للابتزاز. وكانت الجهة الفاعلة الأكثر نشاطاً هذا الأسبوع هي "thegentlemen" بـ 31 مطالبة، تلتها عن قرب مجموعة "qilin" بـ 30 مطالبة. ومثلت المجموعات غير المنسوبة 20 مطالبة، بينما سجلت كل من "N0n" و"akira" 11 مطالبة. ويشير التركيز الكثيف للنشاط بين عدد قليل من النقابات الغزيرة الإنتاج إلى عمليات ذات موارد جيدة ونهج منهجية في استحواذ الأهداف والتشهير بالضحايا.
بالنظر إلى التوزيع القطاعي، تحمل قطاع التصنيع العبء الأكبر من نشاط هذا الأسبوع بـ 32 مطالبة، تلاه عن قرب قطاع التكنولوجيا بـ 24 مطالبة، ثم الخدمات المهنية بـ 20 مطالبة. واستكمالاً للقطاعات الخمسة الأكثر استهدافاً، جاء قطاع الرعاية الصحية بـ 12 مطالبة والخدمات المالية بـ 11 مطالبة. وعادةً ما يعكس الاستهداف المكثف للتصنيع والتكنولوجيا التكلفة العالية للتوقف التشغيلي في هذه الصناعات، والتي يستغلها المبتزون للضغط على الضحايا لدفع المطالب.
على صعيد الثغرات الأمنية، كانت الثغرة الأكثر خطورة التي تم تسليط الضوء عليها هذا الأسبوع هي (CVE-2026-90770)، والتي تحمل درجة على مقياس (CVSS) تبلغ 8.8. وغالباً ما تعمل العيوب عالية الخطورة من هذا النوع كناقلات وصول أولية للاستغلال الآلي أو عمليات الاختراق المستهدفة قبل نشر حمولات الاختراق. وينبغي على فرق الأمان إعطاء الأولوية لإدارة الثغرات الأمنية وترقيعها بسرعة للتخفيف من نقاط الدخول هذه.
في ضوء هذه الاتجاهات المجمعة، تنصح "فرسان" المؤسسات بمراجعة الجاهزية الدفاعية، مع التركيز بشكل خاص على استراتيجيات النسخ الاحتياطي القوية للبيانات، وقدرات اكتشاف النقاط الطرفية والاستجابة لها، وإدارة الترقيع السريع للثغرات عالية الخطورة. ويعد الحفاظ على الرؤية عبر سلاسل الإمداد والبنية التحتية الحيوية أمراً أساسياً تعطيل مراحل الوصول الأولية والحركة الجانبية التي تستخدمها عصابات برمجيات الفدية من الدرجة الأولى.