site-logo
site-logo
site-logo
Hero BG

Report

Lessons from Major Cyberattacks of 2026

The 2026 Cyber Threat Reality: Attackers Exploiting What Organizations Trust

On 11 March 2026, Stryker Corporation lost use of much of its Microsoft environment in a single day, not through a self-propagating wiper or a novel exploit, but through legitimate administrative functions in its endpoint-management tenant. Nine days earlier, on the other side of the evidence set this report examines, attackers reached Polish energy infrastructure through trusted remote-access and carrier paths, corrupting firmware and erasing logs on OT devices. Different sectors, different actors, the same underlying failure: defenses built around the endpoint and the perimeter did not address a position attackers actually used.

Shieldworkz built this report around eight incidents that became public during 2026, selected not for media volume but for the transferable lesson each one carries. It covers destructive nation-state activity against enterprise and energy targets, control-plane zero-days exploited for years before disclosure, a developer-tool supply-chain compromise that reached a government cloud, SaaS extortion, a stale third-party credential, and attacks on internet-exposed controllers in water and energy infrastructure.

Seven findings the evidence supports, graded by source confidence throughout the report:

Management planes were a force multiplier: Stryker's endpoint-management tenant, Cisco's SD-WAN control plane, Ivanti EPMM, and the Trivy CI/CD pipeline each gave attackers reach far beyond the system first touched.
Credential and token lifecycle failures recurred: a four-year-old credential at Klue, non-atomic secret rotation at Trivy, a long-lived AWS key at the European Commission, a VPN without MFA and PLCs with default credentials in Poland.
Some state-linked operations aimed at denying recovery, not only theft: Stryker and Polish devices were wiped, firmware-corrupted, or factory-reset, erasing logs in the process, while criminal groups in the same period continued to rely on data theft and extortion.
Incomplete containment allowed re-entry: residual Trivy credentials enabled further releases, Canvas was re-entered through the same issue the day after it was declared contained, and further Ivanti exploitation followed disclosure.

Every claim in this report is tagged against a six-level evidence standard, from confirmed fact stated by the affected organization or a government body, through technical finding, threat-intelligence assessment, attribution claim, unverified report, to expert interpretation, so readers always know exactly how much weight a given statement can bear.

Why This Report Matters

Most annual threat round-ups summarize headlines. This report reconstructs eight full attack chains, initial access through recovery, each scored across sixteen separate dimensions: victim and sector, threat actor, timeline, exploitation technique, persistence, privilege escalation, data impact, business consequence, and critically, which controls failed and which controls could have interrupted the attack.

Stryker: destruction through the endpoint-management plane. A compromised administrator account, a newly created Global Administrator role, and mass remote-wipe commands via Intune disrupted order processing, manufacturing, and shipping, and materially affected Q1 2026 results.
Cisco Catalyst SD-WAN (UAT-8616): a control plane exploited for three years. Disclosed only in February 2026, this intrusion went unseen for at least three years, illustrating how little perimeter and endpoint tooling sees of control-plane compromise.
Internet-exposed PLCs: Iranian-affiliated activity in US water and energy. Controllers reachable directly from the internet required no IT pivot at all, a distinct exposure route from the trusted remote-access path Polish energy infrastructure experienced in the same period.
Trivy and TeamPCP: a security scanner becomes a credential stealer. A developer-tool supply-chain compromise that reached a government cloud, with residual credentials enabling further releases even after the issue was reportedly addressed.

Each case study is paired with the specific controls that failed or were bypassed and the specific controls that could have interrupted the attack, drawn from CISA guidance, vendor advisories, and named technical researchers, not generic best practice.

Why Downloading This Report Is Critical for Your Organization

If your organization operates any system that administers other systems, an endpoint-management tenant, an SD-WAN controller, an MDM console, a CI/CD pipeline, you share the exact exposure class behind at least four of the eight incidents this report reconstructs. And if your environment spans both IT and OT, the report's cross-incident analysis of how IT techniques reached, or could reach, OT through remote access, flat carrier networks, engineering workstations, and Active Directory dependencies maps directly onto architecture most converged environments still carry.

Here's what this report puts in your hands:

Eight lessons, each fully operationalized: observed pattern, why conventional defenses failed, warning signals, preventive and detective controls, response actions, recovery measures, telemetry sources, KPIs/KRIs, ownership, and priority, mapped directly to a time-phased playbook.
A detection and threat-hunting reference: seven specific detection patterns, from destructive bulk actions in management planes to OT PLC manipulation and private-APN abuse, each with the telemetry source that would surface it.
A 12-month security roadmap and board-level risk register: so findings translate directly into budget and governance conversations, not just a technical reading list.
Full source transparency: a discrepancy register documenting where sources disagree, and an evidence-label system so every claim's confidence level is visible, not asserted.

Key Takeaways From the Report

Protect the management plane as a tier-zero asset. Actions through legitimate administrative functions look like normal operations to tools watching for malware and exploits; multi-person approval for destructive actions and phishing-resistant MFA on management roles is the control this report's cases most consistently lacked.
Treat credential and token lifecycle as a control, not an administrative task. A credential that lived for four years, rotation treated as done when merely begun, default PLC passwords, these recur across unrelated sectors and actors.
Do not declare containment until the exploited path is closed. Residual access re-opened at least two of the eight incidents in this report after containment was publicly declared.
OT exposure arrives by two distinct, separately defensible routes. Trusted remote-access and carrier paths require segmentation and zero-trust carrier treatment; direct internet exposure of controllers requires nothing less than removing that exposure entirely.
Detection worked where behavior-based tooling existed, and failed where it did not. EDR interrupted one wiper run in progress; a three-year control-plane compromise went unseen; a failed OT device was initially attributed to an engineering error rather than intrusion.
Some operations now aim at denying recovery, not just extracting value. Factory resets, firmware corruption, and log erasure were observed alongside traditional extortion in the same reporting period, meaning offline, tested backup and recovery capability is now a frontline control, not a compliance checkbox.

How Shieldworkz Supports Your 2026 Lessons-Learned Program

Reading what happened to eight other organizations is the easy part. Testing whether the same exposure exists in your own environment, especially where OT sits inside the blast radius, is where Shieldworkz comes in.

OThello Assess: maps your actual management-plane footprint and OT/IT exposure, including internet-reachable controllers and carrier-connected remote-access paths, the two routes into OT this report documents, in sub-24-hour assessment cycles.
OT network detection and response: delivers the behavior-based detection this report identifies as the difference between an intrusion caught in progress and one that goes unseen for years, covering the seven detection patterns Section 9 of the report specifies.
Incident response and tabletop exercises: scoped against this report's own case studies, management-plane compromise, credential-lifecycle failure, incomplete containment, so your team rehearses the exact failure modes documented here.
Credential and privileged-access review: closing the rotation, expiry, and ownership gaps behind Lesson 2, across human, service, and third-party credentials alike.

Organizations that act on this report's findings before their next audit or incident aren't just reading about 2026. They're closing the exact gaps the year's attackers already found and used.

Download the Report

Eight organizations already learned these lessons the hard way, at real operational and financial cost. This report exists so yours doesn't have to be the ninth.

Fill in the form to receive your free copy of Lessons from Major Cyberattacks of 2026. You'll also have the option to book a no-obligation consultation with a Shieldworkz OT security expert, who can help you test your own management-plane blast radius and prioritize this report's eight lessons against your environment.

Schedule a Demo With Shieldworkz OT Security Experts

Download your copy now!

Get the Full 2026 Cyberattack Report Explore the key attack patterns, critical findings, and actionable lessons shaping cyber resilience in 2026.