logo

Six Supply Chain Attack Groups to Watch Out for in 2026

ID: e07afe18-a9f8-57d3-af10-446f7138e085

STIX ID: report--e07afe18-a9f8-57d3-af10-446f7138e085

Feed Name: Group-IB Blog

Threat Score
90/100

Date Published: 2026-03-13

Date Updated: 2026-04-28

...
...

**Executive summary:** Group-IB’s report warns that supply-chain attacks have become industrialized and profiles six threat actors that exploit identity, OAuth/API keys, open-source package ecosystems, MSP integrations, and RMM vulnerabilities to scale compromises — resulting in large data exposures, malware distribution via npm packages, multi-tenant ransomware, and high-value thefts (examples include millions of accounts affected, an alleged $1.5B Bybit-related theft, and hundreds of compromised packages).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.