Asia-Pacific Cyberattacks Exceed 75 Million in First Half of 2026, Kaspersky Says
Key Takeaways
- •Kaspersky said more than 75 million online attacks were detected and blocked across Asia-Pacific in the first half of 2026.
- •The company recorded 3.4 million backdoor attacks, 2.4 million password-stealer attacks, and 250,000 ransomware incidents in the region.
- •Advanced Persistent Threats made up 24% of high-severity incidents, followed by social engineering at 15% and malware at 12%.
- •Five of the 12 countries most targeted by APTs were in Asia-Pacific: China, India, Myanmar, Pakistan, and Vietnam.
- •Kaspersky reported rising supply chain and open-source software threats, including 19,484 malicious packages detected in 2025, up 37% from 2024.

More than 75 million attacks from online sources were detected and blocked across the Asia-Pacific (APAC) region during the first half of 2026, a figure that points to a highly active cyberthreat landscape, according to Kaspersky's Global Research and Analysis Team (GReAT).
Data from the Kaspersky Security Network — the company's cloud-based threat intelligence network that pools anonymized detection telemetry from participating users worldwide — recorded 3.4 million backdoor attacks, 2.4 million password-stealer attacks, and 250,000 ransomware incidents in the region over the period. Each plays a distinct role in intrusions: backdoors give attackers persistent remote access to compromised systems, password stealers harvest stored login credentials, and ransomware extorts victims by encrypting their data.
"Threat actors have been busy during the first half of 2026, waging various attacks against companies and individuals in Asia-Pacific," Kaspersky said.
According to the company, the top three categories of high-severity security incidents were Advanced Persistent Threats (APTs) at 24%, social engineering at 15%, and malware at 12%.
Five of the 12 countries most targeted by APTs are in Asia-Pacific: China, India, Myanmar, Pakistan, and Vietnam. An APT is a sophisticated, targeted cyber campaign in which attackers gain unauthorized access to a network and maintain their presence there over time. Such campaigns are typically used long term to steal sensitive information and even to conduct cyber espionage.
"While we observed slight declines in some attack categories during the first half of 2026, this should not be mistaken for a weakening threat landscape in the region. We are also monitoring that threat actors are increasingly leveraging AI to automate reconnaissance, accelerate malware development, and scale attacks, making them faster and more adaptive," said Sergey Lozhkin, head of APAC and META research units at Kaspersky GReAT.
"APAC as a global leader in digital transformation and even in AI agent adoption, coupled with its complex geopolitical environment, makes it a high-value target for threat actors behind the most advanced persistent threats. The concentration of targeted countries in the region underscores the strategic value of continuous threat intelligence, resilient cyber defenses, and stronger regional cooperation," he added.
Kaspersky also noted a rise in supply chain attacks worldwide, with China ranking among the countries with the highest exposure — 40% of businesses there reported supply chain risks. Some incidents involved compromised trusted sources that delivered malware and backdoor installers, illustrating how cybercriminals exploit legitimate software or websites to carry out attacks while evading detection. The method has precedent in one of the industry's most consequential breaches: in the 2020 SolarWinds compromise, attackers tampered with a trusted software update to deliver backdoor malware to thousands of customers.
"We see a rising volume of threats targeting open-source software. In 2025, we detected 19,484 malicious packages, a 37% increase from 14,197 in 2024, while hacktool detections rose 11% year on year from 2,966 to 3,302. The findings underscore the growing need for organizations to strengthen software supply chain security as open-source components become increasingly integral to modern applications," Mr. Lozhkin added. The risk is not hypothetical: in 2024, researchers uncovered an attempted backdoor hidden inside XZ Utils, a widely used open-source compression library, before it could be exploited at scale.
Kaspersky said it is strengthening its focus on securing the open-source software ecosystem through its Open-Source Software Threats Data Feed, which provides organizations with actionable intelligence on vulnerabilities, malicious and compromised packages, and riskware and hacking tools. Such feeds are designed to let security teams automatically block known-malicious packages and flag risky components as they enter their software stacks, rather than waiting for manual review.
Source: Bworldonline