NTT DATA has released the latest edition of its Cyber Threat Intelligence Report, covering the first half of 2026. The report reveals that the global cyber threat landscape is undergoing a structural transformation. According to the findings, threat actors are increasingly prioritizing low-profile, long-term intrusions designed to maximize economic, strategic, and reputational impact. Rather than seeking immediate disruption, attackers are focusing on persistence, stealth, and the ability to maintain long-term influence within compromised environments.
The report highlights that cyberspace has become a strategic domain where economic, political, and security conflicts increasingly converge. Geopolitical tensions, technological fragmentation, and shifting international alliances are having a growing impact on digital infrastructures, supply chains, and critical sectors. This evolution makes attribution more difficult, complicates international cooperation, and increases risk exposure for governments, critical industries, and private organizations. At the same time, cyberspace has become a common arena for indirect confrontation, where pressure and disruption can be exerted without escalating into open military conflict.
This trend is further intensified by the growing adoption of artificial intelligence as a strategic force multiplier. Its integration into cyber espionage, disinformation campaigns, and offensive automation lowers barriers to entry, accelerates attack cycles, and expands the reach of hybrid operations carried out by both nation-state actors and sophisticated cybercriminal organizations.
Meanwhile, the cybercriminal ecosystem has undergone significant fragmentation. The disruption of major underground forums and centralized marketplaces has not reduced illicit activity—it has redistributed it toward specialized markets, initial access brokers, and more private communication channels, making threat monitoring and early intelligence gathering increasingly difficult.
At the same time, ransomware and data extortion models have reached a high level of operational maturity. Campaigns increasingly combine automation, targeted theft of sensitive information, staged public pressure, and reputational exploitation. The report also highlights the growing use of “silent” techniques, with increased abuse of legitimate cloud and SaaS services to establish persistence and move laterally while leaving minimal traces.
From an industry perspective, the sectors most affected during the first half of the year were public administration and government (3,343 incidents), education (1,140), financial services (957), information technology (802), and telecommunications (614). Overall, the estimated global economic impact of cybercrime now stands at approximately US$10.5 trillion annually.
Although legal and regulatory frameworks continue to strengthen, international law enforcement operations are becoming more effective, and organizations are progressively improving their defensive capabilities, the report concludes that malicious actors continue to adapt faster than these advances. This highlights a persistent gap between regulatory compliance and true operational resilience.
“We are witnessing a paradigm shift: cyberattacks are no longer aimed solely at causing disruption; they are increasingly designed to influence long-term decisions, business processes, and strategic direction. Effective risk management now requires a comprehensive approach focused on contextual detection, resilience, and strategic anticipation of persistent and highly adaptive threats,” said María Pilar Torres Bruna, Head of Cybersecurity at NTT DATA Iberia, International Organisations, LATAM, and Consulting in Benelux and France.
As cyber threats become increasingly persistent and sophisticated, NTT DATA's report underscores the need to move beyond regulatory compliance. Anticipating risks, understanding the broader context, and positioning cybersecurity as a strategic business function will be essential to building genuine, sustainable digital resilience.