CyberIntel ⬡ News
★ Saved ◆ Cyber Reads
← Back 🛡 Active Threats

Global cyberattacks rise in January 2026 as ransomware activity increases and GenAI-driven data exposure expands - Intelligent CIO

Intelligent CIO Archived Mar 16, 2026 ✓ Full text saved

Global cyberattacks rise in January 2026 as ransomware activity increases and GenAI-driven data exposure expands Intelligent CIO

Full text archived locally
✦ AI Summary · Claude Sonnet


    Global cyberattacks rise in January 2026 as ransomware activity increases and GenAI-driven data exposure expands Ben Leitch | 11 February, 2026 Check Point Research, the threat intelligence arm of Check Point Software Technologies Ltd, has released its Global Threat Intelligence insights for January 2026, revealing organisations worldwide faced an average of 2,090 cyberattacks per week. This represents a 3% increase from December and a 17% rise year-on-year, confirming continued escalation in global cyberpressure driven by intensified ransomware activity and widening exposure linked to the expanded use of Generative AI tools. Among the four African countries included in the January insights, Nigeria recorded the highest number of attacks at 4,701 per organisation per week, a 12% year-on-year increase, up from 4,622 in December 2025. Angola followed with 4,512 attacks per organisation per week, down 7% year-on-year. Kenya recorded 2,172 attacks per organisation per week, a decrease of 41% from the same period last year. South African organisations were attacked 2,145 times per week, up 36% year-on-year. Overall, Africa saw 2,864 attacks per organisation per week, down 6% year-on-year. These attacks focused on a broad spectrum of industries, with government, financial services and consumer goods and services the three most targeted sectors. Ian van Rensburg, Head Security Engineering Africa at Check Point Software Technologies, said: “January’s data shows that cyberattacks are not only increasing but becoming more refined and opportunistic.” The data highlights growing risks for African organisations pursuing Digital Transformation, particularly where cybersecurity hygiene does not keep pace with technology deployment. Unchecked Generative AI usage is creating new blind spots for organisations. “Prevention-first, real-time protection powered by AI is the only effective way to stop attacks before they cause operational or financial damage,” he said. GenAI adoption drives new data exposure risks while education remains the top target The rapid adoption of Generative AI tools across enterprises continues to introduce high-risk data leakage pathways. In January, one in every 30 GenAI prompts submitted from corporate networks posed a significant risk of sensitive data exposure, impacting 93% of organisations using Generative AI tools. An additional share of prompts contained potentially sensitive information including internal documents, personal identifiers, customer information and proprietary source code. Organisations used an average of 10 different GenAI tools per month, many likely unmanaged and operating outside formal governance structures, increasing the risk of accidental data spillover, ransomware infiltration and AI-powered cyberattacks. The education sector remained the most attacked globally, with institutions averaging 4,364 weekly attacks per organisation, up 12% year-on-year. Government entities followed with 2,759 weekly attacks, up 8% year-on-year. Telecommunications ranked third with 2,647 attacks per week, up 8% year-on-year, reflecting increased targeting of connectivity-driven infrastructure and 5G-enabled ecosystems. Regionally, Latin America recorded the highest attack volumes at 3,110 attacks per organisation per week, up 33% year-on-year. APAC followed with 3,087 attacks, up 7% year-on-year. Africa recorded 2,864 attacks, down 6% year-on-year, while Europe increased 18% and North America rose 19% year-on-year. Ransomware threat landscape activity rises 10% year-on-year Ransomware remained one of the most destructive threats in January, with 678 publicly reported incidents, marking a 10% increase compared with January 2025. North America accounted for 52% of reported cases, followed by Europe at 24%, confirming continued focus on high-value economic regions. The US represented 48% of global ransomware victims, followed by the UK at 5%, Canada and Germany at 4% each and Italy and Spain at 3% each. Across industries, business services was the most impacted sector at 33%, followed by consumer goods and services at 15% and industrial manufacturing at 11%. The leading ransomware groups in January were Qilin at 15%, LockBit at 12% and Akira at 9%, collectively responsible for a significant share of disclosed incidents.
    💬 Team Notes
    Article Info
    Source
    Intelligent CIO
    Category
    🛡 Active Threats
    Published
    Archived
    Mar 16, 2026
    Full Text
    ✓ Saved locally
    Open Original ↗