APAC Intelligence Insights Report, May 2026
← Research Hub

APAC Intelligence Insights Report, May 2026

Every major threat category climbed in May 2026. DDoS activity nearly doubled, compromised accounts topped 6.7 million, and Australia was again the region's most-targeted ransomware country. Group-IB's May 2026 APAC intelligence brief shows exactly where the threat landscape is heading.

Synopsis

May 2026 stood out as a month in which every major threat category rose at once: Ransomware climbed, compromised accounts and bank cards surged, and hacktivist DDoS activity nearly doubled — driven in large part by a single religiously motivated group. Australia remained the region’s most-targeted ransomware country, while critical infrastructure, government, and financial systems across APAC stayed under sustained pressure.

Every figure is drawn from Group-IB’s own Threat Intelligence collection and dark web monitoring. The report is built for defenders who need to know what changed this month, and why it matters.

Key Findings and Insights

Every major threat category rose in May 2026.Every major threat category rose in May 2026.

A rare month of across-the-board increases: Ransomware activity was up 11.57%, compromised accounts up 26.95%, DDoS and hacktivism up 96.67%, and compromised bank cards up sharply month-on-month.

Australia was again the region's most-targeted ransomware country.Australia was again the region's most-targeted ransomware country.

Australia recorded 25 ransomware activities in May — ahead of Thailand, Japan, and Singapore — the second consecutive month at the top of the regional list.

Hacktivist DDoS activity nearly doubled behind a single group.Hacktivist DDoS activity nearly doubled behind a single group.

APAC logged 118 DDoS and hacktivism incidents, with the religiously motivated Indonesian group BABAYO EROR SYSTEM responsible for over 37% of the regional total. Government and Military was the most-targeted sector.

Compromised accounts surpassed 6.7 million.Compromised accounts surpassed 6.7 million.

Group-IB recorded 6,767,371 compromised-account data leaks across APAC, led by information stealers such as RedLine Stealer, with India the hardest-hit country.

Compromised bank cards spiked.Compromised bank cards spiked.

Card leaks rose to 506,349 for the month, driven by a large single-actor dump, with Malaysia, Australia, and Thailand the most affected markets.

Ransomware stayed concentrated on supply-chain-heavy sectors.Ransomware stayed concentrated on supply-chain-heavy sectors.

The Gentlemen remained the most active group, followed by newcomer Lamashtu. Manufacturing was the top target at over 22% of incidents — pointing to continued supply-chain focus.

Initial access broker activity ticked up.Initial access broker activity ticked up.

APAC saw initial access broker events rise 26.67% month-on-month, spread across seven countries, with Vietnam, Indonesia, and India the most affected.

Global supply-chain and fraud campaigns intensified.Global supply-chain and fraud campaigns intensified.

May 2026 brought a major npm supply-chain attack affecting hundreds of packages, a reported GitHub repository breach, and large-scale fraud ecosystems targeting consumers around the 2026 FIFA World Cup and investors across Australia and the United States.

Who Must Read This Report

CISOs and security leaders across Asia-PacificCISOs and security leaders across Asia-Pacific

Who need a fast, evidence-based read on how the regional threat landscape is shifting month to month.

SOC and threat intelligence teamsSOC and threat intelligence teams

Tracking active ransomware groups, hacktivist actors, and the stealer malware families driving credential theft.

Fraud and financial-crime teamsFraud and financial-crime teams

At banks and fintechs monitoring compromised bank cards and the underground channels that distribute them.

Risk, compliance, and regulatory stakeholdersRisk, compliance, and regulatory stakeholders

Who need clarity on exposure across multiple APAC markets.

Incident response and IT teamsIncident response and IT teams

Defending developer pipelines, CI/CD environments, and operational technology from supply-chain and critical-infrastructure threats.

Government and critical infrastructure operatorsGovernment and critical infrastructure operators

Assessing the surge in hacktivist DDoS activity targeting the region.

See why every major threat category rose this month.

Download APAC Intelligence Insights — May 2026 for the full month-on-month breakdown of ransomware, fraud, hacktivism, and initial access activity, plus the adversary of the month — sourced from Group-IB’s Threat Intelligence.

Frequently asked questions

What is the APAC Intelligence Insights May 2026 report?

arrow_drop_down

APAC Intelligence Insights — May 2026 is Group-IB’s monthly threat intelligence brief on the Asia-Pacific cybersecurity landscape. It covers month-on-month changes in ransomware, DDoS and hacktivism, compromised accounts, compromised bank cards, and initial access brokers, alongside global trends and an adversary of the month.

Which country was most targeted by ransomware in APAC in May 2026?

arrow_drop_down

Australia was the most-targeted ransomware country in the Asia-Pacific region in May 2026, with 25 recorded activities, ahead of Thailand (18), Japan (16), and Singapore (16). This marked the second consecutive month with Australia at the top of the regional list.

Why did DDoS and hacktivism activity rise so sharply in May 2026?

arrow_drop_down

APAC DDoS and hacktivism activity rose 96.67% month-on-month to 118 incidents in May 2026, driven largely by the religiously motivated Indonesian hacktivist group BABAYO EROR SYSTEM. The group was responsible for 44 attacks — representing over 37% of the regional total — and shifted from basic defacements to coordinated, professional-grade DDoS campaigns, primarily against Government and Military targets.

How does Group-IB monthly threat intelligence differ from an annual threat report?

arrow_drop_down

Where an annual report captures long-term trends, Group-IB’s monthly APAC Intelligence Insights shows how the threat landscape is moving right now, with month-on-month percentage changes across each category. May 2026’s simultaneous rise across ransomware, accounts, cards, and DDoS is exactly the kind of shift monthly reporting surfaces while it is still actionable.

What are the first three steps to act on this month's intelligence?

arrow_drop_down
  • Prioritise credential hygiene and dark web monitoring, given more than 6.7 million compromised accounts and the dominance of information stealers such as RedLine Stealer.
  • Review ransomware readiness for supply-chain-exposed sectors, with Manufacturing again the most-targeted industry.
  • Stress-test DDoS resilience for government, education, and healthcare services, given the near-doubling of hacktivist activity.

Who was the adversary of the month in APAC for May 2026?

arrow_drop_down

Group-IB named BABAYO EROR SYSTEM as the APAC adversary of the month for May 2026. Active since September 2025 and attributed to Indonesia, the religiously motivated hacktivist group has operated across 48 countries, specialising in DDoS attacks, data leaks, and hacktivism against government, education, and healthcare targets.

Is the report free to download?

arrow_drop_down

Yes. APAC Intelligence Insights — May 2026 is available as a free download by completing the form on this page.