Back Asec.Ahnlab August 2026 Dark Web Threat Actor Trend Report
The August 2026 Dark Web Threat Actor Trend Report focuses on trends among threat actors—including hacktivists—active on the deep web and dark web. It is noted that the accuracy of some information could not be verified.
NoName057(16), BD Anonymous, and Dark Storm Team claimed responsibility for repeated DDoS attacks targeting websites of Japanese government agencies, local governments, and organizations in the transportation, finance, and shipbuilding sectors. A DDoS attack involves generating a massive volume of requests to disrupt service availability.
BD Anonymous also targeted museums, cultural foundations, and police-related portals, while Dark Storm Team similarly claimed responsibility for attacks on numerous websites, including those of Japanese government agencies and financial institutions.
A Norwegian public digital services agency was also a DDoS attack target.
In Japan, unauthorized access to hundreds of rental server accounts at major internet infrastructure and hosting service providers was confirmed, and it was further disclosed that the potential impact could extend to as many as several million accounts. A global insurance company based in Japan disclosed the possibility of a customer data breach due to the exploitation of a vulnerability in its file transfer solution. A Japanese IT services company is investigating an incident involving unauthorized access, and a major Japanese media outlet disclosed the possibility of information leaks due to account takeovers.
In the US, a global medical and pharmaceutical distribution company officially disclosed a cyber incident, and a global apparel manufacturing and distribution company stated that corporate information was leaked after employee devices were compromised by a social engineering attack. In the United Kingdom, a small-scale power plant was attacked by hackers linked to Iran, causing a disruption in operations that lasted several days. In Singapore, unauthorized access to customer order information was confirmed due to an authentication flaw in the order tracking system of a virtual asset wallet service provider, and a hardware wallet manufacturer disclosed a customer data breach resulting from a breach at a logistics company.
The real name of the LockBitSupp operator was identified as a specific individual, and claims were made that this person’s role differs from that of previously known key operators. This was reported as additional information regarding the operational structure of the ransomware group.
Rootor recruited initial access providers on a dark web forum, and on another forum, evidence emerged of recruitment efforts for specialists in penetrating corporate networks. The trading of initial access credentials and demand for penetration specialists continued to be observed on dark web forums.
Eclipse a Windows-compatible Ransomware-as-a-Service (RaaS) affiliate program, while Storm and Panzer also continued their efforts to recruit affiliates and specialized personnel.
Law enforcement agencies arrested two members of a supply chain attack threat group, and the US Department of Justice and the Federal Bureau of Investigation seized attack infrastructure used by a China-linked state- hacking group. Through an international cooperative operation, INTERPOL made a large-scale arrest of individuals linked to an organized crime network in West Africa, and the operator of a ransomware group was sentenced to a lengthy prison term.
In August 2026, claims of repeated DDoS attacks by hacktivists targeting Japan were observed simultaneously with actual breach incidents in Japan, the US, the United Kingdom, and Singapore. In particular, the breaches of major Japanese internet infrastructure and hosting service providers demonstrated that attacks on key digital service providers can lead to widespread ripple effects. Furthermore, the public naming of individuals linked to LockBitSupp, the recruitment of initial access brokers and penetration testing specialists, and the promotion of new RaaS partnership programs indicated that the division of labor within the ransomware landscape and data extortion ecosystem continues. At the same time, law enforcement agencies continued to achieve results, including the arrest of members of supply chain attack threat groups, the seizure of attack infrastructure belonging to China-linked state- hacking groups, the dismantling of organized crime networks through international cooperative investigations, and the imposition of significant prison sentences on ransomware group operators.
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
