SK shieldus says on the 21st it publishes its KARA ransomware trend report analyzing global ransomware attack trends and major cases in the first half of 2026. /Courtesy of SK shieldus

SK shieldus said on the 21st that it published the KARA ransomware trend report analyzing global ransomware attack trends and major cases in the first half of 2026.

According to the report, the total number of ransomware victims worldwide in the first half of this year was 4,744. Second-quarter damage increased about 48% from a year earlier.

SK shieldus analyzed that the main intrusion route of recent ransomware attacks is shifting from the malware itself to exploiting corporations' security vulnerabilities or stolen account credentials. Attackers were found to be abusing essential infrastructure for corporate operations—such as virtual private networks (VPNs), business platforms, and management systems—to secure initial access and then spread the damage.

In particular, in the first half, attacks targeting common platforms and infrastructure occurred in succession. The Qilin ransomware group exploited VPN vulnerabilities to harm a global automaker and a U.K. medical testing service corporation. Groups including ShinyHunters and Clop reportedly attempted large-scale compromises by targeting business platforms and management systems used by many organizations.

As VPNs, software as a service (SaaS), business platforms, and management systems commonly used by multiple corporations have emerged as prime targets, "common infrastructure attacks," in which a single vulnerability or account compromise leads to damage across multiple corporations, are spreading.

The report emphasized the importance of managing internet-exposed systems and accounts in responding to ransomware. In Korea as well, attacks targeting multiple corporations simultaneously through managed service providers (MSPs) have been identified.

In response, SK shieldus said it is necessary to inspect externally exposed assets through attack surface management (ASM) and to establish a real-time detection and response framework based on MDR. It said continuous inspections, rapid security patches, and application of multi-factor authentication (MFA) are essential for assets connected to the internet, such as VPNs, firewalls, servers, and remote access systems.

SK shieldus continuously inspects externally exposed assets and vulnerabilities through its ASM service, and based on its MDR service, security experts monitor threats 24 hours a day and support everything from detection and analysis to response. It also supports early identification of anomalies that appear during ransomware attacks—such as privilege escalation, credential theft, and data exfiltration attempts—or, in the event of an incident, forensic analysis and the establishment of recurrence prevention measures.

Kim Byeong-mu, head of the cyber business division (vice president) at SK shieldus, said, "Recent ransomware attacks are appearing in a form that targets common infrastructure shared by multiple organizations rather than individual corporations," adding, "Because a single vulnerability or account compromise can lead to cascading damage, corporations should proactively inspect their externally exposed asset and account management systems and strengthen real-time detection and response capabilities to secure cyber resilience."

※ This article has been translated by AI. Share your feedback here.