
Get 24/7 incident response assistance from our global team
- APAC: +65 3159 4398
- EU & NA: +31 20 890 55 59
- MEA: +971 4 540 6400
- LATAM: +56 2 275 473 79
Get 24/7 incident response assistance from our global team
Please review the following rules before submitting your application:
1. Our main objective is to foster a community of like-minded individuals dedicated to combatting cybercrime and who have never engaged in Blackhat activities.
2. All applications must include research or a research draft. You can find content criteria in the blog. Please provide a link to your research or research draft using the form below.

Group-IB’s monthly threat intelligence report on the cybercriminal, hacktivist and nation-state activity targeting Asia-Pacific between 1 to 31 August 2026. This month’s edition documents 695 threat incidents: 583 data leaks, 190 ransomware events, and 118 hacktivism operations – all sourced entirely from Group-IB’s own intelligence collection.
Asia-Pacific is where the world’s fastest digital growth meets the world’s busiest threat actors.
In August 2026, Group-IB tracked 695 threat reports across the region. Data leaks increased, ransomware surged, and a state-sponsored zero-day campaign quietly ran through the software South Koreans are required to install for local banking services.
India bore the brunt with 182 incidents, followed by Indonesia, China, and Japan. Government and military stayed the most-targeted sector.
Every figure here comes from Group-IB’s own collection. It’s written for defenders who need to prioritise, not just observe.
Named groups. Named sectors. Hard numbers. All sourced from Group-IB Threat Intelligence.
Group-IB documented 695 threat reports across Asia-Pacific in August 2026: 583 data leaks, 190 ransomware events, and 118 hacktivism operations.
The Gentlemen was the most active, claiming 37 of the region’s ransomware leak events, followed by Krybit and Qilin. Total ransomware activity rose 26.7% month-on-month.
Operation Double Barrel was a state-sponsored campaign exploiting zero-day vulnerabilities in the financial-security software South Korean users must install for banking and institutional access, using watering-hole and spear-phishing lures across legitimate Korean websites to deploy backdoor malware.
India was most targeted, followed by Indonesia, China, and Japan.
Krybit is a ransomware and data-leak-extortion group first observed by Group-IB in April 2026. In August, it recorded a 230% month-on-month increase in events across eight APAC countries, with healthcare a signature target.
Yes. The August 2026 APAC Threat Landscape is a free download via the form on this page.