Cybersecurity Threat Report — October 2026

August was 2026's worst ransomware month, more gangs now steal data without encrypting it, and attackers exploited Citrix, Check Point, SonicWall and ScreenConnect gear in September. This edition covers the threats, the patches that can't wait and an eight-step plan for businesses with 10–250 employees.

Published by NetSys Group engineers · October 2026 edition · Updated October 4, 2026

Bottom line

Threat level: Elevated. Ransomware hit a 2026 high in August, and attackers exploited edge devices that small offices run in September. Most of the fixes cost little.

If you do only three things

  1. Patch the edge this week. Citrix NetScaler, Check Point gateways and Spark firewalls, SonicWall SMA 1000, Fortinet FortiOS and ConnectWise ScreenConnect all have exploited flaws.
  2. Audit vendor access. List every app, plug-in and API key that can reach your data, and remove what you don't use.
  3. Verify payments by phone. Confirm any bank-detail change on a number you already have on file.

Ransomware and extortion

964 victims were claimed on leak sites in August, up 19% on July and the highest month of 2026 (Breachsense, Sep 2026). Qilin led with 157 claims, followed by The Gentlemen with 127. More crews now steal data instead of encrypting it: Coveware found only 15% of victims paid when data was stolen but not encrypted (Q2 2026), and Coalition reports data-theft ransomware claims cost more than twice as much.

AI threats and wire fraud

KnowBe4 reports 86% of phishing is now AI-driven, with reverse-proxy Microsoft 365 login theft up 139% in six months. CrowdStrike says phone-based intrusions doubled. Business email compromise cost $3.04B in 2025 (FBI IC3), and 61% of these attacks now pose as a trusted vendor (Abnormal AI, 2026). IBM's 2026 study found shadow-AI incidents at 43% of breached firms, up from 20%.

Breaches to learn from

  • Brevo: a leaked key let attackers plant fake "verify you're human" pop-ups on 100,000+ websites.
  • BigCommerce: stolen app logins injected scripts into online stores.
  • ShipMonk: a vendor said it had deleted customer data but hadn't; 67,000 more people were exposed.
  • Fake IT help-desk calls tricked staff into giving up Microsoft 365 logins.

Patches that can't wait

ProductFlawAdded to CISA KEV
Citrix NetScaler ADC / GatewayCVE-2026-88771 / 88772Sep 27
Check Point Gateway & SparkCVE-2026-85102Sep 22
ConnectWise ScreenConnectCVE-2026-84869Sep 11
Fortinet FortiOSCVE-2025-25249Sep 9
Microsoft WindowsCVE-2026-81963Sep 8
SonicWall SMA 1000CVE-2026-83548Sep 2

What changed

Paid Windows 10 security updates for business PCs reach the end of year one on Oct 13. CMMC Phase 2 is paused. The CIRCIA incident-reporting rule is still pending. Delaware's privacy law now applies from 10,000 consumers. Cyber insurance rates fell for a 12th straight quarter (Marsh, Q2 2026).

Your 8-step action plan

  1. Patch internet-facing gear this week.
  2. Use phishing-resistant MFA everywhere.
  3. Verify every payment change by phone.
  4. Review third-party apps and API keys.
  5. Approve one AI tool for staff.
  6. Alert on large data transfers.
  7. Keep offline, tested backups.
  8. Settle the Windows 10 plan.

The designed PDF edition, with charts, is free. One short form on the main report page unlocks this edition and every other one. Get the PDF

Beyond the report

Discuss the security controls behind the headlines.

Share the systems, data and risks your business needs to protect. A NetSys engineer can discuss monitoring, identity protection, backups and incident response within an agreed scope.

Explore Cybersecurity Services 845-203-3914