Cybersecurity statistics of the week (August 10th - August 16th)
Hi guys, I send out a weekly newsletter with the latest cybersecurity vendor reports and research, and thought you might find it useful, so sharing it here.
All the reports and research below were published between August 10th - August 16th.
You can get the below into your inbox every week if you want: https://www.cybersecstats.com/cybersecstatsnewsletter/
Cloud Security
2026 Cloud Security Index (Intruder)
How misconfigurations differ across AWS, Azure, and Google Cloud.
Key stats:
- More than two-thirds of organizations operate multi-cloud environments.
- 83% of AWS accounts have IAM policies that allow privilege escalation.
- 75% of Google Cloud accounts are missing OS Login controls.
Read the full report here.
DDoS
Cloudflare DDoS Threat Report H1 2026 (Cloudflare)
Cloudflare's mid-year DDoS report.
Key stats:
- 96.62% of network-layer DDoS attacks remained under 500 Mbps in the first half of 2026.
- 90.60% of network-layer DDoS attacks ended in under 10 minutes.
- Brazil was the top DDoS source country in H1 2026 at 14.9%, overtaking the United States at 13.4%.
Read the full report here.
Enterprise Perspective
2026 State of Secure AI Access (NetFoundry)
A survey of CISOs and CTOs about how AI is changing their security posture.
Key stats:
- 100% of CISOs and CTOs at enterprises say AI is expanding their organization's attack surface.
- 15% are very confident their current security solutions adequately protect their AI deployments.
- 58% have experienced security events due to lack of machine identity oversight.
Read the full report here.
Consumer Scams
Love/hate relationship: The AI affair (Malwarebytes)
Young people are particularly susceptible to AI scams.
Key stats:
- 70% of young adults ages 18 to 22 experienced an AI-related scam in the past year, compared to 50% of the general population.
- 19% of young adults have been a victim of a deepfake or virtual kidnapping scam, compared to 8% of the general population.
- 14% of young adults have been a victim of an impersonation scam, compared to 10% of the general population.
Read the full report here.
Industry-Specific
2026 Professional Services Protect Brief (SonicWall)
Professional services are being targeted far more than any other industry, at least according to SonicWall.
Key stats:
- 3 billion IPS events in the first half of 2026, the largest absolute attack volume of any industry tracked.
- 69.9 million ransomware hits in the first half of 2026, more than any other vertical.
- Ten active ransomware families operated simultaneously against the professional services sector, including Filecoder (19.1 million hits across 113 organizations), Gandcrab (11.9 million) and Ryuk (10.5 million).
Read the full report here.
Industrial Ransomware Analysis for Q2 2026 (Dragos)
Who's getting hit by ransomware in the industrial sector (and by whom).
Key stats:
- 1,140 ransomware incidents affected industrial organizations worldwide in Q2 2026, a 12% increase over the 1,020 incidents recorded in Q1.
- Manufacturing was the most affected sector with 747 incidents (65%) across all subsectors.
- The US was the country most impacted, with 431 incidents (38% of all incidents).
Read the full report here.
Regional Spotlight
Cyber Security In Manufacturing (Make UK)
A UK-specific look at how cyber incidents are disrupting manufacturers, and how few have a tested plan for when it happens.
Key stats:
- 30% of manufacturers experienced a cyber incident in the past year, either directly or through their supply chain.
- More than one in five manufacturers (22.7%) believe available cybersecurity solutions are not relevant to their business, while 18.2% report that providers lack a sufficient understanding of manufacturing operations.
- Firewalls are the most widely adopted measure (92%) among manufacturers, followed by malware protection (80%), secure configuration (67%) and access controls (61%).
Read the full report here.