
Get 24/7 incident response assistance from our global team
- APAC: +65 3159 4398
- EU & NA: +31 20 890 55 59
- MEA: +971 4 540 6400
- LATAM: +56 2 275 473 79
Get 24/7 incident response assistance from our global team
Please review the following rules before submitting your application:
1. Our main objective is to foster a community of like-minded individuals dedicated to combatting cybercrime and who have never engaged in Blackhat activities.
2. All applications must include research or a research draft. You can find content criteria in the blog. Please provide a link to your research or research draft using the form below.

April 2026 was a month of sharp contrasts. Ransomware activity and compromised bank cards both fell, yet compromised accounts more than doubled and hacktivist DDoS activity climbed. Australia was the single most-targeted ransomware country in the region, while critical infrastructure and government systems across APAC drew sustained hacktivist attention.
Every figure is drawn from Group-IB’s own Threat Intelligence collection and dark web monitoring. The report is built for defenders who need to know what changed this month, and why it matters.
Download APAC Intelligence Insights — April 2026 for the full month-on-month breakdown of ransomware, fraud, hacktivism, and initial access activity, plus the adversary of the month — sourced from Group-IB’s Threat Intelligence.
APAC Intelligence Insights — April 2026 is Group-IB’s monthly threat intelligence brief on the Asia-Pacific cybersecurity landscape. It covers month-on-month changes in ransomware, DDoS and hacktivism, compromised accounts, compromised bank cards, and initial access brokers, alongside global trends and an adversary of the month.
Australia was the most-targeted ransomware country in the Asia-Pacific region in April 2026, with 24 recorded activities, followed by Thailand with 18 and Indonesia with 12. This came despite overall APAC ransomware activity falling 26.67% month-on-month to 121 incidents.
Where an annual report captures long-term trends, Group-IB’s monthly APAC Intelligence Insights shows how the threat landscape is moving right now — with month-on-month percentage changes across each threat category. This lets security teams spot emerging shifts, such as April’s 143% surge in compromised accounts, while they are still actionable rather than historical.
Group-IB’s April data points to continued supply-chain targeting — Manufacturing was the most-hit ransomware sector — alongside rising credential theft driven by information stealers such as Redline Stealer, and sustained hacktivist pressure on government and critical infrastructure. Organisations should expect stolen credentials to feed follow-on intrusions across the region.
Group-IB named Coinbase Cartel as the APAC adversary of the month for April 2026. The group focuses on data exfiltration rather than encryption, conducted four APAC attacks in April, and has carried out 11 attacks in the region in 2026 as part of 104 attacks globally.
Yes. APAC Intelligence Insights — April 2026 is available as a free download by completing the form on this page.