SK Shieldus published a KARA (Korea Anti Ransomware Alliance) ransomware trends report analysing global ransomware attack trends and key cases in the first half of 2026. It analysed that key intrusion routes in recent ransomware attacks are increasingly focused on exploiting corporate security vulnerabilities or stolen accounts rather than the malware itself.
The report put the number of ransomware 피해 cases worldwide in the first half at a total of 4,744. It showed the scale of second-quarter damage rose about 48 percent from a year earlier.
Through the report, SK Shieldus highlighted that attackers are exploiting infrastructure essential to corporate operations, such as virtual private networks (VPNs), work platforms and management systems, to secure initial access and then spread damage.
In the first half of this year, attacks targeting shared platforms and infrastructure followed one after another. The Qilin ransomware group exploited VPN vulnerabilities to damage a global automaker and a British medical testing services company. ShinyHunters and Clop were also known to have tried large-scale intrusions by targeting work platforms and management systems used by multiple organisations.
The report particularly stressed the importance of managing internet-exposed systems and accounts in responding to ransomware.
According to the report, it is becoming more important to check externally exposed assets through Attack Surface Management (ASM) and to build a real-time detection and response system based on Managed Detection & Response (MDR).
The report explained that always-on checks of internet-connected assets such as VPNs, firewalls, servers and remote access systems, rapid security patching and the application of multi-factor authentication (MFA) are essential.
Kim Byung-moo (김병무), head of SK Shieldus' cyber business division and a vice president, said recent ransomware attacks are appearing in a form that targets common infrastructure shared by multiple organisations rather than individual companies. He said that because a single vulnerability or account compromise can lead to cascading damage, companies should proactively inspect externally exposed assets and account management systems and strengthen real-time detection and response capabilities to secure cyber resilience.