STOCK TITAN

The Fortinet 2026 Global Threat Landscape Report Reveals a Surge in AI-Enabled Cybercrime, Contributing to a 389% Increase in Ransomware Victims Year-over-Year

(Moderate)
(Negative)
Tags
AI

Fortinet (NASDAQ: FTNT) released the 2026 Global Threat Landscape Report (Apr 30, 2026). FortiGuard Labs telemetry identified 7,831 confirmed ransomware victims in 2025 (a 389% YoY increase), TTE compressing to 24–48 hours, ~67.65 billion brute force events, and a 25.49% rise in exploitation attempts.

The report highlights AI-enabled offensive tooling, credential‑stealer dominance, and Fortinet’s role in law‑enforcement takedowns and new defender programs.

Loading...
Loading translation...

Positive

  • Fortinet telemetry identified 7,831 ransomware victims in 2025 (data-driven visibility)
  • Supported law-enforcement takedowns including Operation Red Card 2.0
  • Launched Cybercrime Bounty program to crowdsource threat leads
  • Provides FortiGuard Outbreak Alerts and advisory services for incident response

Negative

  • Ransomware victims rose 389% YoY to 7,831
  • Time-to-exploit compressed to 24–48 hours
  • Approximately 67.65 billion brute force events recorded in 2025
  • Global exploitation attempts increased by 25.49%

News Market Reaction – FTNT

-2.09%
-2.09% Session close to close

In the Apr 30 session, FTNT declined 2.09%, reflecting a moderate negative market reaction.

Data tracked by StockTitan Argus on the day of publication.

Market Context

This announcement spotlights Fortinet’s FortiGuard Labs data on accelerating AI-enabled cybercrime, ...
Analysis

This announcement spotlights Fortinet’s FortiGuard Labs data on accelerating AI-enabled cybercrime, including shrinking time-to-exploit windows and a 389% surge in ransomware victims to 7,831. It reinforces Fortinet’s role in global threat intelligence, complementing prior AI-focused platform and data center initiatives. Investors may watch how these trends translate into demand for Fortinet’s AI-driven security products and services and whether future updates continue to show rising attack complexity.

Key Figures

Time-to-exploit window: 24–48 hours Prior time-to-exploit: 4.76 days Ransomware victims 2025: 7,831 victims +5 more
8 metrics
Time-to-exploit window 24–48 hours Critical outbreak TTE in latest report
Prior time-to-exploit 4.76 days TTE from earlier Fortinet reports
Ransomware victims 2025 7,831 victims FortiRecon-confirmed global ransomware victims
Prior ransomware victims ≈1,600 victims Victims in 2025 Global Threat Landscape Report
Ransomware increase 389% YoY Year-over-year growth in identified ransomware victims
Brute force events 67.65 billion Global brute force events recorded by FortiGate IPS
Daily brute force attempts 185 million per day Average daily brute force activity
Stealer logs share 67.12% Share of dark web database datasets from stealer logs

Previous AI Reports

5 past events · Latest: Mar 10 (Positive)
Same Type Pattern 5 events
Date Event Sentiment 24h Move Catalyst
Mar 10 AI platform launch Positive +0.5% Release of FortiOS 8.0 expanding AI-driven security and SASE capabilities.
Mar 10 AI SecOps enhancements Positive +0.5% Advances in unified SOC platform with agentic AI and expanded endpoint security.
Dec 17 AI data center solution Positive -3.8% Joint Secure AI Data Center solution with Arista Networks for AI workloads.
Dec 16 NVIDIA AI integration Positive +1.2% Integration of FortiGate VM with NVIDIA BlueField-3 DPUs for AI security.
Nov 05 Secure AI framework Positive +0.9% Launch of Secure AI Data Center solution to protect AI models and infrastructure.

24h Move is the share-price change in the day after each event; other market factors may also have contributed.

Pattern Detected

AI-themed announcements have typically produced modest, mixed price reactions, with one notable negative outlier among otherwise small positive moves.

Recent Company History

Over the past several months, Fortinet has issued multiple AI-focused updates. On Nov 05, 2025, it launched the Secure AI Data Center solution, followed by joint AI data center and NVIDIA integration announcements in Dec 2025. In Mar 2026, Fortinet introduced FortiOS 8.0 and advanced its security operations platform with agentic AI capabilities. These events generated mostly small price moves around -3.75% to 1.17%, suggesting incremental rather than dramatic market reactions to AI news.

Key Terms

mitre att&ck framework, agentic ai, time-to-exploit, tte, +4 more
8 terms
mitre att&ck framework technical
"all tactics used in cyberattacks, as outlined in the MITRE ATT&CK framework."
A structured, publicly documented knowledge base of common cyberattack behaviors and defensive measures that helps organizations describe, explore and respond to intrusions. Think of it as a playbook and map combined—listing typical attacker moves and where they happen—so security teams can test defenses and prioritize fixes. Investors care because companies that follow this framework tend to identify risks faster, reduce breach impact, and provide clearer security reporting, which affects value and liability.
agentic ai technical
"malicious actors are beginning to leverage agentic AI to execute more sophisticated attacks"
Agentic AI refers to computer systems that can make their own decisions and take actions without needing someone to tell them what to do each time. It's like giving a robot a degree of independence to solve problems or achieve goals on its own, which matters because it could change how we work and interact with technology in everyday life.
time-to-exploit technical
"Velocity defines risk as time-to-exploit (TTE) shrinks"
Time-to-exploit is the interval between when a software or system vulnerability becomes known (through discovery or public disclosure) and when attackers begin using that weakness in real-world attacks. For investors, a short time-to-exploit means higher near-term risk of operational disruption, legal exposure, or unexpected costs for companies that rely on the affected technology—like a factory suddenly losing power after a safety flaw is exposed—while a longer interval gives firms more time to patch and reduce damage.
tte technical
"FortiGuard Intelligence shows that TTE as 24–48 hours for critical outbreaks"
Time-to-event (TTE) measures how long it takes for a specific outcome to occur, such as disease progression, hospitalization, or death, in a clinical study. Investors care because TTE shows how quickly a drug or treatment produces meaningful results versus alternatives, similar to timing how long different cars take to reach the same speed; faster or delayed outcomes can affect a drug’s market potential, regulatory prospects, and future revenue.
fortigate ips technical
"FortiGate IPS telemetry recorded a 22% decrease in brute force attempts YoY"
FortiGate IPS is a network security feature built into FortiGate firewall appliances that detects and blocks cyberattacks by scanning traffic for known attack patterns and suspicious behavior. Think of it as a security guard that inspects incoming packages and stops harmful ones before they enter a building; for businesses it reduces breach risk, downtime and cleanup costs. Investors watch adoption and effectiveness because strong IPS demand supports recurring security revenue and lowers client cybersecurity risk, which can affect a vendor’s growth and valuation.
dark web technical
"FortiRecon dark web signals captured AI-enabled offensive tooling advertised as services"
The dark web is a hidden part of the internet that standard search engines and browsers don’t show, accessible only with special software and settings that mask users’ identities. For investors, it matters because stolen customer data, leaked corporate documents or illegal marketplaces found there can lead to regulatory fines, cleanup costs, loss of customer trust and sudden drops in a company’s stock value—like a hidden back alley that can damage a storefront’s reputation and finances.
botnet operators technical
"supported by shadow agents, access brokers, and botnet operators who provide services on demand"
Botnet operators are individuals or groups who secretly control large collections of compromised computers and devices, using them like a fleet of remote-controlled machines to launch cyberattacks, spread malware, steal data, send spam, or mine cryptocurrency. They matter to investors because such attacks can disrupt operations, trigger data breaches and regulatory fines, damage reputation and sales, and force costly cleanup—risks that can quickly reduce a company’s value and stock price.
credential-stealer malware technical
"logs available from systems compromised by infostealer malware. In 2026, FortiRecon intelligence found"
Software designed to secretly capture usernames, passwords, and other authentication data from computers or phones so attackers can impersonate users. Like a digital pickpocket that steals keys to online accounts, it can lead to direct financial theft, unauthorized trades or access to sensitive corporate systems; for investors this raises the risk of material losses, regulatory penalties, and reputational damage that can quickly affect a company’s value.

AI-generated analysis. How Rhea-AI works. Not financial advice.

See more from StockTitan in Google Search and AI answers. Adds StockTitan as a preferred source · opens Google
Add on Google

Fortinet leverages threat intelligence to disrupt global cybercrime, transforming awareness into actionable insights

SUNNYVALE, Calif., April 30, 2026 (GLOBE NEWSWIRE) --

Fortinet® (NASDAQ: FTNT), the global cybersecurity leader driving the convergence of networking and security, today released the 2026 Global Threat Landscape Report from FortiGuard Labs. Derived exclusively from FortiGuard Labs telemetry, the latest annual report is a snapshot of the active threat landscape and trends from 2025, including a comprehensive analysis across all tactics used in cyberattacks, as outlined in the MITRE ATT&CK framework. The data reveals that cybercrime no longer functions as a series of isolated campaigns—it operates as a system, with malicious hackers operating across an end-to-end life cycle and compressing the attack life cycle with shadow agents.

“Cybercrime is one of the world’s most pervasive and costly threats, and our latest Global Threat Landscape Report reveals how malicious actors are beginning to leverage agentic AI to execute more sophisticated attacks,” said Derek Manky, Chief Security Strategist and Global VP of Threat Intelligence, Fortinet FortiGuard Labs. “As cybercriminals increasingly use AI to bolster their tactics, cyber defenders must evolve cybersecurity operations into an industrialized defense and adopt AI-enabled tools that respond at the same velocity as modern threats.”

Attack Techniques and Targeted Sectors in Today’s Threat Landscape

Modern cybercrime crosses borders and sectors, and even traditional definitions of crime itself. As attacks grow more sophisticated and interconnected, key findings from the latest FortiGuard Labs Global Threat Landscape Report reveal:

  • Velocity defines risk as time-to-exploit (TTE) shrinks: As AI accelerates reconnaissance, weaponization, and execution, FortiGuard Intelligence shows that TTE as 24–48 hours for critical outbreaks, a sharp increase from earlier reports that revealed a TTE of 4.76 days. Real-world incidents reflect how minutes can define outcomes: Active exploitation attempts were made within hours of the React2Shell vulnerability public disclosure.
  • Ransomware victims skyrocket: FortiRecon adversary intelligence identified 7,831 confirmed ransomware victims globally, skyrocketing from approximately 1,600 identified victims in the Fortinet 2025 Global Threat Landscape Report. Availability of crime service kits like WormGPT, FraudGPT, and BruteForceAI contributed to this 389% increase year-over-year (YoY). The top three targeted sectors include manufacturing (1,284), business services (824), and retail (682). Geographic concentration includes the U.S. (3,381), Canada (374), and Germany (291).
  • Identity sprawl defines cloud exposure: FortiCNAPP intelligence confirms that throughout 2025, most confirmed cloud incidents originated from stolen, exposed, or misused credentials rather than from infrastructure exploitation. Sector analysis shows hospitals/physician clinics and retail establishments as the #1 target. Large identity populations, federated access models, and complex cloud integrations make these prime targets for malicious hackers.

Inside the Habits of Modern, AI-Enabled Cybercriminals

As FortiGuard Labs Cyberthreat Predictions for 2026 projected, the most capable threat groups function as semi-autonomous enterprises, supported by shadow agents, access brokers, and botnet operators who provide services on demand. Key findings from the 2026 Global Threat Landscape Report show:

  • Shadow agents reduce operator skill requirements while increasing workflow speed. FortiRecon dark web signals captured AI-enabled offensive tooling advertised as services and products, including enhanced versions of WormGPT and FraudGPT, and novel services like HexStrike AI, an offensive AI tool with automated reconnaissance attack path generation; and BruteForceAI, a penetration testing tool that integrates large language models (LLMs) for intelligent form analysis and can execute sophisticated multi-threaded attacks.
  • With AI, criminals work smarter, not harder. FortiGate IPS telemetry recorded a 22% decrease in brute force attempts YoY, pointing to efficiency gains: With optimized, intelligent brute force techniques, threat actors are making fewer attempts against better-selected targets, increasing success probability per credential tested. This activity translates into about 67.65 billion brute force events globally, with approximately 185 million attempts per day; 1.3 billion attempts per week; and 5.6 billion attempts per month. At the same time, intelligence revealed a 25.49% increase in global exploitation attempts YoY.
  • Stolen datasets are more popular than leaked credentials. In the 2025 Global Threat Landscape Report, FortiGuard Labs observed a 500% increase in logs available from systems compromised by infostealer malware. In 2026, FortiRecon intelligence found an additional 79% increase and revealed a shift toward theft of more comprehensive data sets, enabled by agentic AI. Within dark web “database” activity, stealer logs dominated advertised and shared datasets (67.12%), exceeding combolists (16.47%) and leaked credentials (5.96%). Stealer logs reduce attacker effort by bundling identity material with contextual artifacts, including browser-resident data, enabling immediate replay and faster conversion than brute force or password spraying.
  • Credential-stealer malware persists. Credential-stealer malware remains a lucrative industry and primary upstream engine for exposure generation. FortiRecon telemetry shows stealer activity dominated by RedLine: 911,968 infections (50.80%); Lumma: 499,784 (27.84%); and Vidar: 236,778 (13.19%).

Putting Awareness into Action: Disrupting Cybercriminal Ecosystems
Fortinet is committed to disrupting cybercrime by collecting and sharing threat intel and actively working to combat cyberthreats on a global scale.

A recent collaborative effort spearheaded by INTERPOL and supported by Fortinet through the World Economic Forum Cybercrime Atlas resulted in the takedown of a cybercriminal network. Operation Red Card 2.0 took down infrastructure and operators behind online scams, mobile money fraud, and fraudulent loan applications in Africa. Fortinet is a founding member of the Cybercrime Atlas, a global public-private collaboration effort hosted by the World Economic Forum that uses open-source intelligence to map cybercriminal networks, identify infrastructure vulnerabilities, and support joint disruption operations with law enforcement, such as the recent Operation Red Card 2.0 and Operation Serengeti 2.0.

The 2026 Global Threat Landscape Report reveals that incentivizing the disruption of cybercrime has never been more important. To empower defenders to stay ahead of cybercriminals, Fortinet and Crime Stoppers International launched the Cybercrime Bounty program to provide a secure, anonymous channel for citizens and ethical hackers to submit information about cyberthreats.

Discover how FortiGuard Labs Advisory Services combine cutting-edge technology and expert services to help organizations strengthen their security posture before threats emerge. FortiGuard Outbreak Alerts provide key information about ongoing cybersecurity attacks with significant ramifications affecting companies, organizations and industries. In the event of an incident, FortiGuard Labs offers swift, effective response and in-depth forensic analysis to minimize impact and prevent future intrusions, delivering comprehensive protection in today’s increasingly volatile digital landscape.

Register for the FortiGuard Labs webinar to hear experts break down the threats defining 2026 and what they mean for your organization.

Additional Resources

About Fortinet
Fortinet (NASDAQ: FTNT) is a driving force in the evolution of cybersecurity and the convergence of networking and security. Our mission is to secure people, devices, and data everywhere, and today we deliver cybersecurity everywhere you need it with the largest integrated portfolio of over 50 enterprise-grade products. Well over half a million customers trust Fortinet's solutions, which are among the most deployed, most patented, and most validated in the industry. The Fortinet Training Institute, one of the largest and broadest training programs in the industry, is dedicated to making cybersecurity training and new career opportunities available to everyone. Collaboration with esteemed organizations from both the public and private sectors, including CERTs, government entities, and academia, is a fundamental aspect of Fortinet’s commitment to enhance cyber resilience globally. FortiGuard Labs, Fortinet’s elite threat intelligence and research organization, develops and utilizes leading-edge machine learning and AI technologies to provide customers with timely and consistently top-rated protection and actionable threat intelligence. Learn more at https://www.fortinet.com, the Fortinet Blog, and FortiGuard Labs.

Copyright © 2026 Fortinet, Inc. All rights reserved. The symbols ® and ™ denote respectively federally registered trademarks and common law trademarks of Fortinet, Inc., its subsidiaries and affiliates. Fortinet’s trademarks include, but are not limited to, the following: Fortinet, the Fortinet logo, FortiGate, FortiOS, FortiGuard, FortiCare, FortiAnalyzer, FortiManager, FortiASIC, FortiClient, FortiCloud, FortiMail, FortiSandbox, FortiADC, FortiAI, FortiAIOps, FortiAgent, FortiAntenna, FortiAP, FortiAPCam, FortiAuthenticator, FortiCache, FortiCall, FortiCam, FortiCamera, FortiCarrier, FortiCASB, FortiCentral, FortiCNP, FortiConnect, FortiController, FortiConverter, FortiCSPM, FortiCWP, FortiDAST, FortiDB, FortiDDoS, FortiDeceptor, FortiDeploy, FortiDevSec, FortiDLP, FortiEdge, FortiEDR, FortiExplorer, FortiExtender, FortiFirewall, FortiFlex FortiFone, FortiGSLB, FortiGuest, FortiHypervisor, FortiInsight, FortiIsolator, FortiLAN, FortiLink, FortiMonitor, FortiNAC, FortiNDR, FortiPAM, FortiPenTest, FortiPhish, FortiPoint, FortiPolicy, FortiPortal, FortiPresence, FortiProxy, FortiRecon, FortiRecorder, FortiSASE, FortiScanner, FortiSDNConnector, FortiSIEM, FortiSMS, FortiSOAR, FortiSRA, FortiStack, FortiSwitch, FortiTester, FortiToken, FortiTrust, FortiVoice, FortiWAN, FortiWeb, FortiWiFi, FortiWLC, FortiWLM, FortiXDR and Lacework FortiCNAPP.

Other trademarks belong to their respective owners. Fortinet has not independently verified statements or certifications herein attributed to third parties and Fortinet does not independently endorse such statements. Notwithstanding anything to the contrary herein, nothing herein constitutes a warranty, guarantee, contract, binding specification or other binding commitment by Fortinet or any indication of intent related to a binding commitment, and performance and other specification information herein may be unique to certain environments.



Media Contact:
Travis Anderson
Fortinet, Inc.
408-235-7700
pr@fortinet.com

Investor Contact:
Anthony Luscri
Fortinet, Inc.
408-235-7700
investors@fortinet.com

Analyst Contact:
Sarah Goodwin
Fortinet, Inc.
408-832-1428
sgoodwin@fortinet.com

FAQ

What did Fortinet (FTNT) report about ransomware victims in the 2026 threat report?

Fortinet reported 7,831 confirmed ransomware victims in 2025, a 389% YoY increase. According to Fortinet, availability of AI crime kits like WormGPT and BruteForceAI contributed to the spike and identified top sectors and geographies targeted.

How fast are cyberattacks exploiting new vulnerabilities according to Fortinet (FTNT)?

Fortinet found time-to-exploit (TTE) for critical outbreaks is now 24–48 hours. According to Fortinet, AI-driven reconnaissance and weaponization compressed TTE from earlier multi-day timelines, increasing urgency for rapid patching and detection.

What scale of brute force activity did Fortinet (FTNT) observe in 2025?

Fortinet recorded about 67.65 billion brute force events in 2025, roughly 185 million attempts per day. According to Fortinet, smarter, AI-assisted targeting reduced attempt counts but increased success probability per attempt.

Which sectors and countries were most targeted by ransomware in Fortinet’s 2026 report?

Fortinet identified manufacturing (1,284), business services (824), and retail (682) as top sectors; the U.S. (3,381), Canada (374), and Germany (291) were top countries. According to Fortinet, these figures reflect confirmed victim counts from FortiRecon telemetry.

What defensive actions did Fortinet describe in the 2026 Global Threat Landscape Report?

Fortinet highlighted threat sharing, FortiGuard Outbreak Alerts, advisory services, and the Cybercrime Bounty program to surface leads. According to Fortinet, these measures and public‑private takedowns aim to disrupt criminal ecosystems and accelerate incident response.