Cyberattacks are becoming faster, quieter, and more persistent, as artificial intelligence cuts the time and effort needed to automate certain stages of an intrusion. NTT DATA’s Cyber Threat Intelligence Trends 2026 report places this combination, along with geopolitics and the professionalization of cybercrime, among the factors reshaping risk for companies and public administrations during 2026.
2026’s cyberthreats in 30 seconds
- NTT DATA warns of critical vulnerabilities being exploited in under 24 hours, with some cases capable of going from initial access to exfiltration in as little as 72 minutes.
- Ransomware showed up in 48% of the breaches analyzed and racked up 2,122 published victims in the first quarter.
- AI is already being used for reconnaissance, personalized phishing, deepfakes, and automated social engineering.
- Public administration ranks among the most exposed sectors.
The most significant shift isn’t necessarily the emergence of entirely new techniques. NTT DATA finds that attackers are combining known tools, automating them, and using them faster. That narrows the window between the discovery of a vulnerability, its exploitation, and the attacker’s lateral movement inside the compromised infrastructure.
There’s also a second problem: an intrusion no longer has to announce itself through a service outage or immediate system encryption. Staying hidden can be more profitable. An attacker can hunt for credentials, identify valuable assets, access cloud services, extract data, and prepare an extortion attempt before the organization even realizes what happened.
From Vulnerability to Exfiltration in Just 72 Minutes
One of the report’s most striking data points concerns shrinking attack timelines. NTT DATA notes that some critical vulnerabilities are starting to be exploited in under 24 hours, while certain intrusion cycles can move from initial access to data exfiltration in roughly 72 minutes.
For security teams, this changes an important part of the traditional rulebook. A patching policy that takes days to react can prove insufficient when a vulnerability is being actively exploited.
It also raises the importance of knowing which systems are exposed to the internet. Forgotten servers, outdated applications, admin interfaces, virtual private networks (VPNs), perimeter devices, or misconfigured cloud services can all become entry points.
Identity is another piece of the problem. If a cybercriminal obtains valid credentials, part of their activity can blend in with that of a legitimate user. That’s why identity monitoring, access controls, and phishing-resistant multi-factor authentication are becoming just as relevant as conventional patching.
Artificial intelligence can compress these cycles even further. According to NTT DATA, it’s already being used to automate reconnaissance, generate more personalized phishing campaigns, produce deepfakes, and scale up social engineering operations.
That doesn’t mean AI has replaced the human attacker. Its current effect is better understood as a multiplier: tasks that previously required more manual work can now be automated or carried out at greater scale.
Ransomware Is Changing: Stealing Before Encrypting
Ransomware still holds a prominent position, but how it operates has evolved. The report logs 2,122 published victims during the first quarter of 2026 and finds it was present in 48% of the breaches analyzed. The ten most active groups alone accounted for 71.1% of the victims counted.
Encryption remains a tool of pressure, but stealing data lets criminals keep the extortion leverage even when a company has backups capable of restoring its systems.
An organization can restore its servers and still face the threat of internal documents, business information, or personal data ending up published.
Add to that a growing use of legitimate services. Cloud infrastructure and software-as-a-service (SaaS) applications can be used to store data, maintain persistence, or make it harder to quickly tell certain communications apart from normal business traffic.
The criminal ecosystem has also fragmented. Shutting down large, centralized underground forums and marketplaces doesn’t necessarily bring an equivalent drop in activity. NTT DATA sees a shift toward specialized marketplaces, initial-access brokers, and private channels.
So-called initial access brokers are a particularly problematic piece of the puzzle. Their business is gaining access to an organization and then selling those compromised credentials or sessions to other criminals, who can use them for espionage, fraud, or ransomware.
Public Administration, Education, and Finance Among the Top Targets
The sector-level data shows where part of the activity NTT DATA detected is concentrated. Public administration and governments logged 3,343 incidents during the period analyzed.
Next come educational institutions, with 1,140; financial services, with 957; information technology, with 802; and telecommunications, with 614.
| Sector | Incidents recorded |
|---|---|
| Public administration and governments | 3,343 |
| Education | 1,140 |
| Financial services | 957 |
| Information technology | 802 |
| Telecommunications | 614 |
These sectors’ exposure has a technological explanation, but also a strategic one. Public administrations, telecom operators, financial institutions, and technology providers manage huge amounts of data and, in many cases, are part of services used by other organizations.
Compromising a provider can also open an indirect path to its customers. That’s why digital supply chains keep coming up as an area that requires close monitoring.
NTT DATA adds another element to the analysis: geopolitics. International conflicts, trade disputes, and technological fragmentation are making it harder to separate purely criminal operations from campaigns tied to state interests.
Attribution isn’t always straightforward either. Shared infrastructure, intermediaries, and publicly available tools make it easier to obscure the origin of certain operations.
The takeaway for companies is that complying with a security regulation doesn’t automatically mean being prepared to recover from an attack. Up-to-date inventories, early detection, segmentation, identity protection, verified backups, and recovery plans remain basic technical measures as the time available to react keeps shrinking.
Speed is likely to be one of the variables that most shapes defense in the coming years. If a vulnerability can start being exploited just hours after becoming public, and an intrusion can advance in minutes, the ability to detect anomalous behavior and respond quickly carries as much weight as the measures meant to prevent access in the first place. This continues a trend NTT DATA had already flagged in an earlier report: less noise, more persistence, and greater geopolitical tension.
Frequently Asked Questions
How long can a cyberattack currently take to steal data?
NTT DATA describes scenarios where the interval between initial access and exfiltration can shrink to roughly 72 minutes. That doesn’t mean every attack is this fast, but it shows how much some intrusion cycles are shortening.
How are cybercriminals using artificial intelligence?
The report identifies uses tied to automated reconnaissance, personalized phishing, deepfakes, social engineering, and the automation of certain offensive stages. AI mainly lets attackers increase the speed and scale of techniques that already existed.
Is ransomware still one of the top threats in 2026?
Yes. NTT DATA counts 2,122 published victims during the first quarter of 2026 and places ransomware in 48% of the breaches analyzed.
Which sectors suffer the most cyberattacks?
According to NTT DATA’s data, public administration and governments lead incidents for the period analyzed, followed by education, financial services, information technology, and telecommunications.

