> ## Content Index
> Fetch the complete content index at: https://www.cybersecstats.com/llms.txt
> Use this file to discover other available public pages before exploring further.

# CyberSecStats #72 - Biggest target of the year, security tool woes, and cloud problems
- URL: https://www.cybersecstats.com/cybersecstats-72-biggest-target-of-the-year-security-tool-woes-and-cloud-problems/
- Published: 2026-08-18T19:36:27.000Z
- Updated: 2026-09-01T16:08:25.000Z
- Author: Laura M

Hello,

Laura from CyberSecStats here.

Another light week for reports, only 7 published. We’re assuming vendors are taking a breather after Black Hat?

But as always, the data we did get is often among the most interesting. This week, we pulled new stats on how cloud security risks differ by provider, plus a lot of industry-specific reports, particularly on manufacturing, both global and UK.

There's also data here that should make anyone marketing to the manufacturing sector stop and rethink their approach.

As always, thank you for subscribing.

Thank you also to this week's sponsor ANY.RUN. 

Partner - ANY.RUN 

[![CTA Image](https://storage.ghost.io/c/c0/17/c01762e7-1ff7-42b5-be72-9498adb5e3f5/content/images/2026/08/Screenshot-2026-08-17-at-20.52.48.png)](https://any.run/cybersecurity-blog/lazarus-group-it-workers-investigation-part-two/?utm%5Fsource=cybercats&utm%5Fmedium=newsletter&utm%5Fcampaign=lazarus&utm%5Fcontent=blog&utm%5Fterm=170826) 

****What happens when you knowingly hire DPRK IT workers? These researchers found out**

Researchers built a fake DeFi startup and hired three suspected Famous Chollima developers, giving them weeks of access to monitored virtual desktops. Learn what DPRK IT workers actually do once they are inside your company.

[Read the full technical breakdown ](https://any.run/cybersecurity-blog/lazarus-group-it-workers-investigation-part-two/?utm%5Fsource=cybercats&utm%5Fmedium=newsletter&utm%5Fcampaign=lazarus&utm%5Fcontent=blog&utm%5Fterm=170826) 

## This Week's Cybersecurity Eye-Openers

Three stats that made me pause this week. 

### 1\. Professional services is the biggest target of the year

SonicWall found that professional services (law firms, accountants, consultants) generated 3 billion IPS events in the first half of 2026\. That's the largest absolute attack volume of any industry they track. Professional services also recorded 69.9 million ransomware hits in the same period, more than any other vertical.

### 2\. Manufacturing getting hit, but not sold on solutions

In the UK, 30% of manufacturers experienced a cyber incident in the past year. Supplier attacks led to delivery delays, reduced capacity, and material shortages, while disruptive incidents caused production downtime and pushed up operating costs.

The answer might NOT be more security tools. At least, not the ones currently being offered.

More than one in five manufacturers (22.7%) say available cybersecurity solutions aren't relevant to their business, while 18.2% say providers don't sufficiently understand how manufacturing operations work.

### 3\. Every single CISO says AI has expanded their attack surface

More security tool woes? NetFoundry surveyed CISOs and CTOs and got 100% agreement that AI is expanding their organization's attack surface, but only 15% are very confident their current security solutions can protect their AI deployments. 

## Cloud Security

### 2026 Cloud Security Index (Intruder)

How misconfigurations differ across AWS, Azure, and Google Cloud. 

**Each cloud has its own problems:**

- More than two-thirds of organizations operate multi-cloud environments.
- 83% of AWS accounts have IAM policies that allow privilege escalation.
- 75% of Google Cloud accounts are missing OS Login controls.

**Read the full report** [**here**](https://www.intruder.io/blog/cloud-security-index?ref=cybersecstats.com)**.**

## DDoS

### Cloudflare DDoS Threat Report H1 2026 (Cloudflare)

Cloudflare's mid-year DDoS report. 

**Small, fast attacks are the norm:**

- 96.62% of network-layer DDoS attacks remained under 500 Mbps in the first half of 2026.
- 90.60% of network-layer DDoS attacks ended in under 10 minutes.
- Brazil was the top DDoS source country in H1 2026 at 14.9%, overtaking the United States at 13.4%.

**Read the full report** [**here**](https://blog.cloudflare.com/ddos-threat-report-2026-h1/?ref=cybersecstats.com)**.**

## Enterprise Perspective

### 2026 State of Secure AI Access (NetFoundry)

A survey of CISOs and CTOs about how AI is changing their security posture. 

**100% agreement on the AI problem:**

- 100% of CISOs and CTOs at enterprises say AI is expanding their organization's attack surface.
- 15% are very confident their current security solutions adequately protect their AI deployments.
- 58% have experienced security events due to lack of machine identity oversight.

**Read the full report** [**here**](https://info.netfoundry.io/lp-survey-august-2026?ref=cybersecstats.com)**.**

## Consumer Scams

### Love/hate relationship: The AI affair (Malwarebytes)

Young people are particularly susceptible to AI scams.

**Biggest scam victims:**

- 70% of young adults ages 18 to 22 experienced an AI-related scam in the past year, compared to 50% of the general population.
- 19% of young adults have been a victim of a deepfake or virtual kidnapping scam, compared to 8% of the general population.
- 14% of young adults have been a victim of an impersonation scam, compared to 10% of the general population.

**Read the full report** [**here**](https://www.malwarebytes.com/blog/ai/2026/08/love-hate-relationship-the-ai-affair-young-people-love-ai-but-its-breaking-their-trust?ref=cybersecstats.com)**.**

## Industry-Specific

### 2026 Professional Services Protect Brief (SonicWall)

Professional services are being targeted far more than any other industry, at least according to SonicWall.

**The scale of it:**

- 3 billion IPS events in the first half of 2026, the largest absolute attack volume of any industry tracked.
- 69.9 million ransomware hits in the first half of 2026, more than any other vertical.
- Ten active ransomware families operated simultaneously against the professional services sector, including Filecoder (19.1 million hits across 113 organizations), Gandcrab (11.9 million) and Ryuk (10.5 million).

**Read the full report** [**here**](https://www.sonicwall.com/blog/objection-overruled-professional-services-has-a-bigger-target-on-its-back-than-anyone-realizes?ref=cybersecstats.com)**.**

### Industrial Ransomware Analysis for Q2 2026 (Dragos)

Who's getting hit by ransomware in the industrial sector (and by whom).

**More attacks, (mostly) the same victim:** 

- 1,140 ransomware incidents affected industrial organizations worldwide in Q2 2026, a 12% increase over the 1,020 incidents recorded in Q1.
- Manufacturing was the most affected sector with 747 incidents (65%) across all subsectors.
- The US was the country most impacted, with 431 incidents (38% of all incidents).

**Read the full report** [**here**](https://www.dragos.com/blog/dragos-industrial-ransomware-analysis-q2-2026?ref=cybersecstats.com)**.**

## Regional Spotlight

### Cyber Security In Manufacturing (Make UK)

A UK-specific look at how cyber incidents are disrupting manufacturers, and how few have a tested plan for when it happens.

**Struggling with cyber risk:** 

- 30% of manufacturers experienced a cyber incident in the past year, either directly or through their supply chain.
- More than one in five manufacturers (22.7%) believe available cybersecurity solutions are not relevant to their business, while 18.2% report that providers lack a sufficient understanding of manufacturing operations.
- Firewalls are the most widely adopted measure (92%) among manufacturers, followed by malware protection (80%), secure configuration (67%) and access controls (61%).

**Read the full report** [**here**](https://www.makeuk.org/insights/reports/cyber-security-manufacturing?ref=cybersecstats.com)**.**

[Smile, You’re on Camera! Part 2: Lazarus IT Workers ExposedSee what happened after suspected Lazarus-linked IT workers were hired, from forged identities and AI tools to remote access and supporting infrastructure.![](https://storage.ghost.io/c/c0/17/c01762e7-1ff7-42b5-be72-9498adb5e3f5/content/images/icon/android-chrome-192x192-4f7c5ef7-aab4-47e4-b635-b8957ef1eb5c.png)ANY.RUN's Cybersecurity BlogMauro Eldritch and Heiner García Pérez![](https://storage.ghost.io/c/c0/17/c01762e7-1ff7-42b5-be72-9498adb5e3f5/content/images/thumbnail/Hiring-Lazarus-APT-Remote-Workers_smm-00b43b3f-f783-4914-8935-57d91c9e2cee.png)](https://any.run/cybersecurity-blog/lazarus-group-it-workers-investigation-part-two/?utm%5Fsource=cybercats&utm%5Fmedium=newsletter&utm%5Fcampaign=lazarus&utm%5Fcontent=blog&utm%5Fterm=170826)