Global Ransomware Surge Yields 212 New Claims with Manufacturing and Technology Most Targeted
Global Ransomware Surge Yields 212 New Claims with Manufacturing and Technology Most Targeted
Forsan's weekly threat intelligence review tracks 212 new claims from September 13 to September 20, 2026, dominated by extortion groups and significant activity in the manufacturing and technology sectors.
Forsan's weekly threat intelligence review tracks 212 new claims from September 13 to September 20, 2026, dominated by extortion groups and significant activity in the manufacturing and technology sectors.
During the reporting period from September 13 to September 20, 2026, our threat intelligence team tracked a total of 212 new claims across the global threat landscape. Of these total incidents, 79 were categorized as high or critical severity, reflecting sustained operational pressure from sophisticated cybercriminal syndicates against enterprise environments.
A sector-level breakdown of this week's data reveals a heavy concentration of attacks against industrial and digital infrastructure. Manufacturing led all verticals with 32 claims, followed closely by Technology with 24 claims, Professional Services with 20 claims, Healthcare with 12 claims, and Financial Services recording 11 claims. A heavy focus on manufacturing and technology typically indicates that threat actors are prioritizing sectors with proprietary intellectual property and low tolerance for operational downtime, which can increase extortion leverage.
The operational split between attack motivations heavily favored financial extortion over disruptive operations. Out of the 212 tracked claims, 210 were attributed to ransomware and extortion operations, while only 2 claims involved hacktivist or DDoS activity, demonstrating that financially motivated groups continue to dominate the cyber threat ecosystem.
Activity was led by several prominent threat actor groups during this cycle. The top actors by claim count this week included thegentlemen with 31 claims, qilin with 30 claims, Unattributed groups with 20 claims, N0n with 11 claims, and akira with 11 claims. Meanwhile, regional monitoring specifically captured 2 Middle East-tagged claims, highlighting a persistent baseline of interest in the region.
In addition to extortion pressures, organizations must maintain rigorous vulnerability management practices. The most severe vulnerability highlighted this week was CVE-2026-90770, carrying a CVSS score of 8.8. Forsan advises security teams to review their perimeter defenses, prioritize patching high-severity vulnerabilities, and ensure resilient offline backups are maintained to mitigate extortion risks.
During the reporting period from September 13 to September 20, 2026, our threat intelligence team tracked a total of 212 new claims across the global threat landscape. Of these total incidents, 79 were categorized as high or critical severity, reflecting sustained operational pressure from sophisticated cybercriminal syndicates against enterprise environments.
A sector-level breakdown of this week's data reveals a heavy concentration of attacks against industrial and digital infrastructure. Manufacturing led all verticals with 32 claims, followed closely by Technology with 24 claims, Professional Services with 20 claims, Healthcare with 12 claims, and Financial Services recording 11 claims. A heavy focus on manufacturing and technology typically indicates that threat actors are prioritizing sectors with proprietary intellectual property and low tolerance for operational downtime, which can increase extortion leverage.
The operational split between attack motivations heavily favored financial extortion over disruptive operations. Out of the 212 tracked claims, 210 were attributed to ransomware and extortion operations, while only 2 claims involved hacktivist or DDoS activity, demonstrating that financially motivated groups continue to dominate the cyber threat ecosystem.
Activity was led by several prominent threat actor groups during this cycle. The top actors by claim count this week included thegentlemen with 31 claims, qilin with 30 claims, Unattributed groups with 20 claims, N0n with 11 claims, and akira with 11 claims. Meanwhile, regional monitoring specifically captured 2 Middle East-tagged claims, highlighting a persistent baseline of interest in the region.
In addition to extortion pressures, organizations must maintain rigorous vulnerability management practices. The most severe vulnerability highlighted this week was CVE-2026-90770, carrying a CVSS score of 8.8. Forsan advises security teams to review their perimeter defenses, prioritize patching high-severity vulnerabilities, and ensure resilient offline backups are maintained to mitigate extortion risks.