Press Release
Updated statement regarding LockBit claims
We have completed a thorough security investigation following yesterday’s tweets by LockBit claiming they had compromised Darktrace’s internal systems. We can confirm that there has been no compromise of our systems or any of our affiliate systems. Our service to our customers remains uninterrupted and is operating as normal and no further action is required.
Press Release
Statement regarding LockBit claims
Earlier this morning we became aware of tweets from LockBit, the cyber-criminal gang, claiming that they had compromised Darktrace’s internal security systems and had accessed our data. Our security teams have run a full review of our internal systems and can see no evidence of compromise. None of the LockBit social media posts link to any compromised Darktrace data. We will continue to monitor the situation extremely closely, but based on our current investigations we are confident that our systems remain secure and all customer data is fully protected.
プレスリリース
Darktrace Annual Threat Report Finds Identity Is Now Primary Target as Global Vulnerabilities Rise 20%
- Registered software vulnerabilities rose 20% in 2025, even as attackers increasingly shifted toward credential abuse over traditional exploitation
- 32 million phishing emails detected globally with a 28% increase in QR code-based attacks as email attacks continue to grow in sophistication
- Nearly 70% of incidents in the Americas begin with stolen or misused accounts, reflecting the global shift toward identity‑led intrusions.
- Azure the most targeted cloud provider as cloud compromises accelerate
Darktrace, a global leader in AI for cybersecurity, today announced the findings of its Annual Threat Report 2026, a comprehensive assessment of the global cyber threat landscape and the trends shaping cyber risk in 2026. Among its key findings, the report highlights a 20% year‑over‑year increase in publicly disclosed vulnerabilities, even as attackers increasingly bypass these weaknesses in favor of credential abuse and identity‑led intrusions.
The cyber threat environment in 2025 was defined by acceleration, convergence, and complexity. Adversaries are no longer relying solely on traditional exploits; they are adopting new technologies and techniques that allow them to move faster and operate with greater precision. This shift has enabled attackers to conduct more targeted, adaptive intrusions that are significantly harder for traditional defenses to detect.
Identity Is the New Perimeter
Identity‑driven compromise has now become the dominant path into organizations. Darktrace’s findings show that, across the Americas, nearly 70% of incidents in the region began with stolen or misused accounts, underscoring how cloud and SaaS adoption have shifted the frontline of cyber defense from the network to the user. As organizations increasingly rely on interconnected cloud services, attackers are targeting the identities that govern access to them, rather than the infrastructure itself.
The findings reinforce a shift that has been reflected in real world headlines across the past 12 months. High‑profile incidents at Jaguar Land Rover, Marks & Spencer, and Salesforce over the past year demonstrated how quickly attackers can move once they gain access to legitimate accounts. In each case, the breach did not begin with a sophisticated software exploit, but with compromised identity. Once inside, attackers used trusted accounts and existing permissions to operate in plain sight, accelerating impact while evading traditional security controls.
The trend is reinforced by attackers’ growing focus on stealing high‑value identities. More than 8.2 million phishing emails targeted VIPs in 2025, amounting to over a quarter of all phishing activity identified in that period, reflecting a deliberate effort to compromise privileged accounts that can unlock broader access across cloud and SaaS ecosystems.
Once inside, attackers use legitimate tools and permissions to disguise their attack as normal activity, making lateral movement fast and difficult to detect. Detecting and responding to identity abuse across these highly distributed environments has become one of the hardest problems in cybersecurity.
“Traditional perimeter defenses were built for a world where attackers had to break in,” said Nathaniel Jones, VP of Security and AI Strategy at Darktrace. “Today they simply log in. Stopping identity‑led intrusions requires the ability to recognize when legitimate accounts begin to behave in ways that do not align with normal activity, and that means moving beyond static controls toward security that understands context and intent.”
Cloud and SaaS Environments Are Driving Systemic Risk
Cloud compromise has become the main entry point for cyber-attacks on both sides of the Atlantic. In Europe, 58% of incidents began with compromised cloud accounts and email, overtaking traditional network breaches at 42%. In the Americas, attackers most often break in through SaaS applications and Microsoft 365 accounts, with many of these breaches escalating into double or even triple extortion campaigns.
With 94% of organizations worldwide now relying on cloud computing, the risk is widespread. Across cloud providers, Azure was the most targeted, drawing 43.5% of observed malware samples, compared with 33.2% for Google Cloud Platform (GCP) and 23.2% for Amazon Web Services (AWS). When measured by unique malicious IP addresses, Docker environments accounted for 54.3% of honeypot targeting, underscoring the growing appeal of containerized cloud infrastructure for large scale attacks.
Email Attacks Are Becoming More Sophisticated
Analysis of the 32 million phishing emails detected across Darktrace’s global fleet shows a clear trend: email attacks grew significantly more sophisticated in 2025, with AI‑assisted content, evasive payloads, and identity‑targeting techniques all increasing year-over-year.
Key indicators of this rising sophistication include:
- AI‑assisted phishing accelerating: Signs of AI usage increased year-over-year, with novel social engineering techniques rising from 32% to 38% and large‑text, long‑form messages increasing from 27% to 33%. These patterns reflect a shift toward more personalized, credible‑looking lures designed to evade traditional filters.
- QR‑code attacks on the rise: Darktrace detected a 28% increase in QR code-based phishing attacks from 940,000 in 2024 to over 1.2 million in 2025. Alongside growing volume, attackers introduced new forms of QR code phishing including ‘splishing’, in which a QR code is split into two distinct images, and QR code nesting, where a legitimate QR code is embedded with a malicious one, all designed to bypass link‑scanning tools and route victims through multi‑stage redirects.
- Fresh domains used at scale: More than 1.6 million phishing emails relied on newly created domains spun up specifically for malicious activity, reducing the effectiveness of reputation‑based defenses.
- DMARC evasion through legitimacy: 70% of phishing emails passed DMARC authentication, helping them appear legitimate to both users and automated controls.
“Phishing has become far more convincing and far more targeted,” Jones comments. “Attackers are using AI to craft messages that look authentic, exploit human trust, and slip past traditional email filters. Defenders need technology that can identify subtle signs of abnormality even when an email appears legitimate at first glance.”
Critical National Infrastructure Outlook
The convergence of geopolitical tensions and rapid digital transformation has made Critical National Infrastructure (CNI) a strategic target for state‑aligned and criminal actors. Darktrace observed three recurring trends shaping CNI risk in 2025:
- Disruption of national services: Cyber‑physical attacks linked to the Russia‑Ukraine conflict targeted Western and Ukrainian energy infrastructure, with downstream impacts on healthcare and other dependent sectors.
- Strategic access and pre‑positioning: Groups such as Salt Typhoon and Volt Typhoon expanded operations beyond espionage, infiltrating telecommunications and energy organizations to enable intelligence gathering and potential future disruption.
- Use of proxy and hybrid actors: State‑sponsored groups, particularly DPRK‑affiliated actors, blended financially motivated operations with strategic objectives. In 2025, Darktrace observed DPRK‑linked activity exploiting vulnerabilities and deploying trojanized malware in financial services environments to support broader intelligence efforts.
The Annual Threat Report 2026 shows that the threat landscape has entered a new phase. With credential abuse driving the majority of intrusions and attackers increasingly exploiting trusted accounts, cloud services, and interconnected SaaS environments, identity has become the most reliable path into an organization. AI is accelerating this trend by helping attackers scale targeted, credible‑looking activity that blends into normal behavior. As organizations continue to adopt cloud, SaaS, and AI‑driven technologies, security teams must evolve their approach to detecting and responding to abnormal behavior across highly distributed environments.
“The speed and scale of modern attacks demand continuous visibility into how users and systems behave. Identity has become the most reliable path for attackers, and cloud interconnectivity means a single compromised account can have far‑reaching consequences. Behavioral AI gives defenders the ability to detect small deviations early, before they develop into major incidents,” Jones concludes.
Additional Resources:
- Download the full Annual Threat Report and region-specific outlooks here and check out the Darktrace blog here for more insights behind the data.
- Register for the webinar, “Navigating the Threat Landscape: Insights from the Darktrace Annual Threat Report 2026” on March 11 for a deeper dive.
About the Darktrace Annual Threat Report 2026
The Darktrace Annual Threat Report is based on extensive analysis conducted across Darktrace’s global customer base. The findings draw on data collected throughout 2025, including behavioral anomalies, threat notifications, and real‑world case studies. Darktrace combines these insights with intelligence from national agencies and cyber intelligence partners, as well as open‑source, industry‑leading sources such as CERT advisories and dark‑web collection, to provide a comprehensive and accurate view of the threat landscape. Darktrace will also release a series of in‑depth, region‑specific reports offering tailored intelligence and contextual analysis.
About Darktrace
Darktrace is a global leader in AI for cybersecurity that keeps organizations ahead of the changing threat landscape every day. Founded in 2013, Darktrace provides the essential cybersecurity platform protecting organizations from unknown threats using its proprietary AI that learns from the unique patterns of life for each customer in real-time. The Darktrace ActiveAI Security Platform™ delivers a proactive approach to cyber resilience to secure the business across the entire digital estate – from network to cloud to email. It provides pre-emptive visibility into the customer’s security posture, transforms operations with a Cyber AI Analyst™, and detects and autonomously responds to threats in real-time. Breakthrough innovations from our R&D teams in Cambridge, UK, and The Hague, Netherlands have resulted in over 250 patent applications filed. Darktrace’s platform and services are supported by over 2,300 employees around the world who protect nearly 10,000 customers across all major industries globally.
Darktrace Annual Threat Report Finds Identity Is Now Primary Target as Global Vulnerabilities Rise 20%
cv
Darktrace named a Challenger in first Gartner® Magic Quadrant™ for Email Security Platforms · Evaluated on Completeness of Vision and Ability to Execute Darktrace, a global leader in AI for cybersecurity,today announces that Darktrace / EMAIL™, has been recognized in thefirst ever Gartner Magic Quadrant™ for Email Security Platforms (ESP) as a Challenger. Chris Kozup, Chief Marketing Officer, Darktrace, said of therecognition: “We are extremely proud to have been recognized in the first MagicQuadrant for ESP. We believe the factthat wehave seen such wide scale adoption is testament to the unique way in which wedevelop products to keep our customers safe from even the most sophisticated emailcompromises. We believe our placement reaffirms our dedication to deliveringexceptional customer service, and innovations that safeguard against the emailchallenges of today—and tomorrow.” Darktrace customers consistently acknowledge its exceptional customersupport, delivered by an award-winning[1]service team. Darktrace has the highest percentage of 5-star ratings with a 4.8rating on Gartner® Peer Insights™ out of 249 reviews as on[MW1] 19th December. We feel this unwavering commitment to customersatisfaction is evident in strong renewal rates and accelerated growth inDarktrace / EMAIL over the past few years, gaining almost 5,000 customers sinceits launch in 2019. Darktrace / EMAIL, one of the fastest-growing emailsecurity products on the market, is built on Darktrace’s unique Self-LearningAI, a multi-layered AI engine that leverages different types of AI includingNLP and behavioral analysis to detect threats, instead of traditional securitymeasures such as signatures and sandboxing. This approach enables Darktrace todetect and stop threats like business email compromise attacks and noveltechniques, including some 56% of which passed through customers’ other emailsecurity layers. This pioneering approach has enabled Darktrace to introduce industry-leadingcapabilities such as QR code analysis and automated incident investigations, alongsidedifferentiated functionality to help teams add new depth to their emailsecurity, including: Account take over and Lateral mail account compromise protection. Contributing yet another layer to the AI behavioural profile for each user, security teams can now spot early symptoms of account compromise or malicious insiders before a link or attachment payload is sent, and exfiltration occur Microsoft Teams security with advanced messaging analysis: Advancing beyond simple text analysis to behavioral and natural language content analysis that tracks context across both email and instant messaging to identify the approximately 38% of phishing, sophisticated social engineering and novel insider threats other solutions fail to capture · Drastically improveend user reporting with Cyber AI Analyst narratives: Real-time awareness training capabilities reduce falsepositives in phishing investigations by up to 60% by providing context specificanalysis of each received email to each employee as they interact with their mail.· MailboxSecurity Assistant to increase security team operational efficiency: All forms ofsecondary investigations can now automatically perform advanced behavioralbrowser analysis and stop malicious links within webpages, reducing manualeffort of security analysts to detecting phishing links, and allowing them to remediateup to 70% more malicious phishing links than before.· AI based,autonomous data loss prevention: to immediately protect organizations from misdirected emails,insider threats, and data loss—both classified and unclassified – using userbehavior and dynamic content analysis to determine sensitivity, removing administrativeoverhead from manual expressions and labeling.Marco Cavallo, IT Manager at Darktrace / EMAIL customer Arpa Industries comments:“During the POV, Darktrace / EMAIL showed how specific attacks weresurgically blocked. We realized that other tools wouldn’t have detected thesethreats.” Darktrace / EMAIL is part of Darktrace’s ActiveAI Security Platform™,offering network, cloud, endpoint, identity and operational technologyprotection from a single shared architecture, all built on Darktrace’s uniqueAI engine – providing a strong, integrated approach to threat prevention,detection and response across an organization’s entire digital footprint. Darktrace’s global presence supports a diverse and varied customer base,and adapts proactively to customer pain points of all kinds. Darktrace’sadaptability across all market segments, from SMBs to large enterprisessupports both first time email security buyers and mature email securitystacks. It is able to meet varied security needs with lower setuprequirements, includes capability for advanced depth in configuration and,particularly for mature organizations, can augment existing security providerswith additional protections. Download the fullMagic Quadrant for Email Security Platforms here Resources:· Read more onthe Darktrace Blog· Read more abouthow business email compromise attacks are evolving on The Inference Gartner disclaimersGartner, Magic Quadrant for EmailSecurity Platforms, Max Taggett, Nikul Patel, Franz Hinner, Deepak Mishra, 16December 2024 GARTNER is a registered trademarkand service mark of Gartner and Magic Quadrant and Peer Insights are aregistered trademark, of Gartner, Inc. and/or its affiliates in the U.S. andinternationally and are used herein with permission. All rights reserved.
Gartner Peer Insights content consists of the opinions of individual endusers based on their own experiences with the vendors listed on the platform,should not be construed as statements of fact, nor do they represent the viewsof Gartner or its affiliates. Gartner does not endorse any vendor, product orservice depicted in this content nor makes any warranties, expressed orimplied, with respect to this content, about its accuracy or completeness,including any warranties of merchantability or fitness for a particularpurpose. Gartner does not endorse any vendor,product or service depicted in its research publications and does not advisetechnology users to select only those vendors with the highest ratings or otherdesignation. Gartner research publications consist of the opinions of Gartner’sresearch organization and should not be construed as statements of fact.Gartner disclaims all warranties, expressed or implied, with respect to thisresearch, including any warranties of merchantability or fitness for aparticular purpose. About DarktraceDarktrace is a global leader in AI for cybersecurity that keepsorganizations ahead of the changing threat landscape every day. Founded in2013, Darktrace provides the essential cybersecurity platform protectingorganizations from unknown threats using its proprietary AI that learns fromthe unique patterns of life for each customer in real-time. The DarktraceActiveAI Security Platform™ delivers a proactive approach to cyber resiliencewith pre-emptive visibility into security posture, real-time threat detection,and autonomous response – securing the business across cloud, email,identities, operational technology, endpoints, and network. Breakthroughinnovations from our R&D teams in Cambridge, UK, and The Hague, Netherlandshave resulted in over 200 patent applications filed. Darktrace’s platform andservices are supported by over 2,400 employees around the world who protectnearly 10,000 customers across all major industries globally. To learn more,visit http://www.darktrace.com. ----
[1] Darktrace wins two Globeeawards for excellent customer service [PressRelease] [MW1]shouldthis be 'of'


