ISEC7 Digital Workplace Blog

Arctic Wolf Threat Report 2026: Most attackers simply log in

Written by ISEC7 Editorial Team | Oct 6, 2026, 6:00:00 AM

The Arctic Wolf Threat Report 2026 doesn't describe a new attack technique. It shows how well the old ones still work: two out of three incidents it analyses started with a login over VPN, RDP or a remote management tool.

The report, explained live. Arctic Wolf and ISEC7 walk through the findings in 45 minutes on 15 October and 5 November 2026, both at 11:00 Berlin time. The sessions are held in German.

Attackers aren't breaking in. They're logging in.

Arctic Wolf built its Threat Report 2026 on twelve months of incident response work, from 1 November 2024 to 1 November 2025, plus telemetry from its own platform and leak site data from its partner ecrime.ch.

The headline finding is already in the foreword: attackers bypass controls by logging in, not breaking in. In 65% of incidents other than business email compromise (BEC), abused external remote access was the way in. That means RDP, VPNs and remote monitoring and management tools, the same tools organisations deploy so their people can work securely from anywhere. Often, logging in to an unprotected service is all it takes.

Exploited vulnerabilities, by contrast, matter less than they used to. They account for 11% of those cases, down from 29% in the previous report. Arctic Wolf's reading: attackers would rather take the easy door than invest in exploit development.

Old flaws, stolen credentials

Every one of the ten vulnerabilities seen most often in these cases dates from 2024 or earlier. Most of them sit on edge devices: firewalls, VPN gateways and remote access products. According to the report, the exploited flaws were known vulnerabilities with patches available, not zero-days.

That's the encouraging part. Closing the vulnerabilities known to be exploited makes an organisation a much harder target. The less comfortable part follows straight after: once a flaw has been exposed, patching isn't enough. Arctic Wolf advises rotating passwords and keys and reviewing access logs afterwards. Otherwise the attacker simply comes back later and logs in with the credentials they already took.

How little time that leaves is spelled out by Kerri Shafer-Page, VP of Incident Response at Arctic Wolf. In multiple investigations, attackers reached domain-level control within minutes, which leaves little room for manual intervention.

When the IT team is the target

One chapter speaks directly to admins and developers, because attackers go looking for them where they work. In one campaign, trojanised versions of PuTTY and WinSCP delivered a backdoor. They sat on fake domains promoted through sponsored search ads. In another, self-replicating malware compromised more than 180 npm packages and harvested credentials and cloud tokens.

The logic is simple. Take over an admin's account or device and you are already past the perimeter and the endpoint controls. For 2026, Arctic Wolf expects attackers to try getting malicious links into the AI summaries search engines now show.

Email fraud, meanwhile, still starts the old way. 85% of BEC cases with a confirmed root cause began with a phishing email, up from 74% in the previous report.

Extortion without encryption

Ransomware is still the most common reason for an IR engagement at 44% of cases, with BEC at 26%. The category that grew is data incidents, where attackers only steal data and threaten to publish it. Their share rose from 2% to 22%.

Arctic Wolf sees this as a response to better recovery. Organisations that can restore quickly after encryption are less likely to pay, so some groups have stopped encrypting at all. A good backup does nothing against the threat of leaked customer or HR data.

Ransom demands show a second effect. For the first time in the report's history, the median initial demand fell, by 20% to USD 414,000. Arctic Wolf suspects an attempt to get paid more often. In 77% of ransomware cases, the victim chose not to pay. Where a ransom was paid, negotiation brought it down by an average of 67% from the initial demand.

There is progress, too. In 5% of cases, a ransomware attack was detected and contained before the payload ran.

Manufacturing first, Germany near the top

By the number of victims posted on leak sites, manufacturing is by far the most targeted sector, with construction second. Manufacturing also leads Arctic Wolf's own ransomware IR cases. Both sectors are hit hard by downtime, which is exactly what the groups count on. By country, the United States leads, followed by Canada and Germany, and Germany's share grew year over year.

What 2026 adds

The report closes with five predictions. Two of them land directly on IT teams. AI becomes an everyday tool for attackers rather than an experiment, down to malicious code generated on the fly so that no two samples share a signature. And social engineers increasingly manipulate voice and video in real time, for instance to pose as an executive on the phone. Arctic Wolf doesn't expect this in the bulk of cases, but expects attackers to keep refining the approach.

What the report doesn't tell you

The figures describe the incidents Arctic Wolf was called in to handle. Most of those engagements come through cyber insurers and privacy law firms, so they skew towards incidents serious enough to become insurance claims. Attacks stopped early often never need an IR engagement, so they are under-represented. Arctic Wolf itself notes that its numbers may differ from broader market experience.

So the report doesn't tell you how likely your organisation is to be attacked. It tells you how the expensive attacks start, which is the more useful thing to know when deciding what to fix first. Mobile devices are not covered.

What to check now

The report closes with twelve recommendations. Five of them map directly onto its findings:

  1. Count your remote access. Which VPN endpoints, RDP services and remote management tools can be reached from the internet? Switch off what nobody needs.
  2. Audit VPN accounts. Review users regularly and remove inactive accounts and third-party access.
  3. Use phishing-resistant MFA. Arctic Wolf points to hardware tokens based on WebAuthn.
  4. Patch known exploited vulnerabilities first, for example using CISA's KEV catalog. Then rotate the credentials on the affected systems.
  5. Centralise and analyse logs. If attackers can reach domain control in minutes, someone needs to see the alert at night and at the weekend.

Want to go through these five points for your environment? Our team will look at where your remote access, patch levels and monitoring stand today. Request a conversation or email sales@isec7.com

How ISEC7 works with Arctic Wolf

ISEC7 is an Arctic Wolf partner. In Managed Detection and Response, Arctic Wolf's Security Operations Center in Frankfurt monitors your systems around the clock, identifies incidents and reports them. ISEC7 integrates your mobility infrastructure and remediates the vulnerabilities that come to light.

To keep track of patch levels, there is ISEC7 SPHERE. It monitors connected systems, shows their patch status and known CVEs, and warns before certificates expire, so you can see where one of the flaws from the report is still open.

The report as a webcast: two dates

Terence Canaday of Arctic Wolf presents the key findings in a 45-minute webcast with ISEC7, followed by a conversation about what a Security Operations Center with a German-speaking team takes on around the clock. Both sessions cover the same content, are free to attend and are held in German:

If you'd rather talk it through in English, contact our team.

Get the full report

Arctic Wolf offers the full report, with every chart, the list of the ten most common vulnerabilities and all twelve recommendations, as a download: Request the Arctic Wolf 2026 Threat Report

Frequently asked questions

What is the Arctic Wolf Threat Report 2026 based on?
Twelve months of incident response by Arctic Wolf's team, from 1 November 2024 to 1 November 2025, supplemented by platform telemetry and leak site data from ecrime.ch.

What is the most common way in, according to the report?
Abused external remote access via RDP, VPN and remote management tools. It accounts for 65% of non-BEC cases.

Is patching known vulnerabilities enough?
No. A patch closes the flaw, not the access an attacker may already have gained. Arctic Wolf advises rotating credentials and reviewing access logs after any known exposure.

Sources