Image showing the Threat Matrix Report. It shows the cover and two pages inside the report.
Cyber threat insights

Threat Matrix Report · Spring 2026 Edition

Access CSIS’s Spring 2026 update on the cyber threat landscape, drawing on frontline incident response, MDR telemetry, and threat intelligence. This edition's clear theme: attackers are getting more effective by exploiting trust — legitimate services, everyday workflows, and human behaviour.

What's inside this edition

  • Real-world incident response: How CSIS responders shut down a months-long stealth extortion campaign and contained an Akira ransomware intrusion that exploited a VPN patch-gap window.

  • The shift to user-assisted compromise: Why "fix-it" social engineering like ClickFix and FileFix is bypassing automated defences — and how identity-driven intrusions by actors such as Scattered Spider (UNC3944) are turning IT support workflows into an entry point.

  • Supply-chain and malware trends: Inside the self-spreading Shai-Hulud npm worm, the fragmenting ransomware ecosystem, the resurgence of Lumma Stealer, and industrialised Android malware delivered through Google Play.

  • Hacktivism and geopolitics: Election-timed DDoS campaigns against Denmark and Greenland, China's expanding cyber-espionage, and intensifying Russian hybrid pressure across Europe — analysis from our SecAlliance intelligence team.

  • Key statistics: Curated statistics on phishing, business email compromise, identity weakness, and AI-driven risk from across the industry.

Watch the webinar 

In our on-demand webinar, CSIS cyber intelligence expert Stefan Tanase unpacks the Spring 2026 report findings — which threats are accelerating, which defences are working, and where organisations are still exposed (1 hr 2 min).

Watch the Spring 2026 webinar →

 

About Threat Matrix Reports 

CSIS's Threat Matrix Reports deliver detailed, real-world insights on the cyber threat landscape. Each report draws on proprietary data from our Managed Detection and Response work, Cyber Threat Intelligence feeds, and Emergency Incident Response teams — ensuring that the report’s findings are grounded in frontline experience.