
Get 24/7 incident response assistance from our global team
- APAC: +65 3159 4398
- EU & NA: +31 20 890 55 59
- MEA: +971 4 540 6400
- LATAM: +56 2 275 473 79
Get 24/7 incident response assistance from our global team
Please review the following rules before submitting your application:
1. Our main objective is to foster a community of like-minded individuals dedicated to combatting cybercrime and who have never engaged in Blackhat activities.
2. All applications must include research or a research draft. You can find content criteria in the blog. Please provide a link to your research or research draft using the form below.

May 2026 stood out as a month in which every major threat category rose at once: Ransomware climbed, compromised accounts and bank cards surged, and hacktivist DDoS activity nearly doubled — driven in large part by a single religiously motivated group. Australia remained the region’s most-targeted ransomware country, while critical infrastructure, government, and financial systems across APAC stayed under sustained pressure.
Every figure is drawn from Group-IB’s own Threat Intelligence collection and dark web monitoring. The report is built for defenders who need to know what changed this month, and why it matters.
Download APAC Intelligence Insights — May 2026 for the full month-on-month breakdown of ransomware, fraud, hacktivism, and initial access activity, plus the adversary of the month — sourced from Group-IB’s Threat Intelligence.
APAC Intelligence Insights — May 2026 is Group-IB’s monthly threat intelligence brief on the Asia-Pacific cybersecurity landscape. It covers month-on-month changes in ransomware, DDoS and hacktivism, compromised accounts, compromised bank cards, and initial access brokers, alongside global trends and an adversary of the month.
Australia was the most-targeted ransomware country in the Asia-Pacific region in May 2026, with 25 recorded activities, ahead of Thailand (18), Japan (16), and Singapore (16). This marked the second consecutive month with Australia at the top of the regional list.
APAC DDoS and hacktivism activity rose 96.67% month-on-month to 118 incidents in May 2026, driven largely by the religiously motivated Indonesian hacktivist group BABAYO EROR SYSTEM. The group was responsible for 44 attacks — representing over 37% of the regional total — and shifted from basic defacements to coordinated, professional-grade DDoS campaigns, primarily against Government and Military targets.
Where an annual report captures long-term trends, Group-IB’s monthly APAC Intelligence Insights shows how the threat landscape is moving right now, with month-on-month percentage changes across each category. May 2026’s simultaneous rise across ransomware, accounts, cards, and DDoS is exactly the kind of shift monthly reporting surfaces while it is still actionable.
Group-IB named BABAYO EROR SYSTEM as the APAC adversary of the month for May 2026. Active since September 2025 and attributed to Indonesia, the religiously motivated hacktivist group has operated across 48 countries, specialising in DDoS attacks, data leaks, and hacktivism against government, education, and healthcare targets.
Yes. APAC Intelligence Insights — May 2026 is available as a free download by completing the form on this page.