In Bitsight’s annual State of the Underground report we discuss cyber threat trends, key players, attack vectors, and why it all matters. The key theme from the 2026 State of the Underground is that cyber risk is changing as we know it. We are starting to see threat actors pivot alongside the changing threat landscape. We also explored how the threat landscape is reacting to the ever-growing changes brought on by AI.
The paradox: Declining numbers don't tell the whole story
Some numbers moved downward in 2025, including breaches, endpoint logs, compromised credentials, and credit card listings. But those declines should not be taken at face value. To understand the decline, you need to understand the current geopolitical climate and how it applies to the cyber threat landscape. The decline in these numbers reflects a shift toward hacktivism, AI, better security, and nation-state efforts. There’s a lot going on in the world right now, and threat actors are responding.
While financially motivated threat actors are still active, we also saw groups that are more politically or ideologically inclined ramping up their activity. Ransomware threat actors are shifting toward large blast-radius attacks to create more disruption, more pressure, and increase the likelihood of payment. Hacktivists and nation-state actors are focusing on critical infrastructure and key resources in alignment with their geopolitical, religious, or ideological views.
3 threat actor categories reshaping the landscape
Ransomware, hacktivism, and state-sponsored activity increased in 2025, and each represents a distinct threat model with different motivations and tactics.
Ransomware groups are financially motivated actors whose main goal is to steal and encrypt a victim’s data and demand a ransom in exchange for the decryption key. These ransomware groups are making a lot of money and have little motivation to halt their activity.
Hacktivists are groups of threat actors who target and hack victims based on the group's political, religious, or ideological views. These groups feel strongly about their position and are unlikely to stop because they feel justified in their targeting.
Nation State groups, or Advanced Persistent Threats (APTs), are groups of hackers that are sponsored and paid for by their government or related entities. For example, Charming Kitten out of Iran is reportedly sponsored by the IRGC. These groups are persistent because it is quite literally their job to target their adversaries. Furthermore, unlike ransomware threat actors, APTs are not going to post their exploits on the dark web. Similarly most nations are not going to actively report on their targeting or their attacks on their infrastructure, which can make breach numbers appear lower than they really are.