In recent months several high-volume data breaches have been disclosed. They have impacted companies all over the world in different sectors. One thing is common in them: thousands of company and customer data was leaked, and it was followed by reputational and financial loss.
In the European Union, companies can face severe fines if the personal data of their employees or customers is compromised. Under GDPR, the most serious infringements carry penalties of up to 20 million euros or 4% of global annual turnover, whichever is higher.[^2] This exposure applies regardless of the root cause, whether the breach stemmed from business e-mail compromise (BEC), ransomware, an insider threat, or something as simple as a misconfiguration.
In the last few months quite a few companies have had to face hard financial and operational consequences.
EOGB Energy Products Ltd, a UK-based energy equipment supplier, experienced a cyber incident in June 2026 involving unauthorized access and potential data exposure.[^3] The breach affected business operations tied to energy product distribution and internal systems. Although technical specifics are limited, the case reflects increasing targeting of energy-related supply chains.
The University of Oxford was affected by a third party data breach in May 2026 through its vendor Group GTI, which operates the CareerConnect platform.[^4] Attackers gained unauthorized access to GTI systems, exposing names, email addresses, and encrypted passwords of students, alumni, and staff. The impacted business function was student career services relying on external SaaS infrastructure. The university itself was not directly compromised, highlighting supply chain risk.
Foxconn, the world’s largest contract electronics manufacturer, confirmed a ransomware attack on its North American operations in May 2026.[^5] The Nitrogen ransomware group claimed to have exfiltrated approximately 8TB of data across 11 million files, including technical drawings, project documentation, and financial records tied to major customers. The incident disrupted production at facilities in Wisconsin and Texas and shows that even the largest, most well resourced organizations remain exposed, particularly through supply chain relationships.
No system is 100% secure, but the use of Cyber Threat Intelligence (CTI) services could help prevent breaches. According to the 2026 Verizon Data Breach Investigations Report, vulnerability exploitation has become the leading way attackers gain initial access, but compromised credentials still play a major role throughout the breach lifecycle, showing up in close to 40% of breaches overall.[^1] CTI providers are able to monitor usernames and passwords involved in breaches, therefore able to give a timely warning, before an incident happens.
What is CTI?
CTI, Cyber Threat Intelligence, is the collection, processing and analysis of data to understand various threat actors’ motives, tactics, techniques and procedures (TTPs). It provides context and action-oriented advice via evidence-based knowledge, while also helping anticipate potential attacks.
The Threat Intelligence Lifecycle
CTI isn’t a one-off report, it’s a continuous cycle that repeats as new threats emerge and old ones evolve. The lifecycle is generally broken down into the following phases:
Planning and direction – defining what needs to be protected and what questions the intelligence effort should answer, based on the organization’s own risk profile and priorities
Collection – gathering raw data from a wide range of sources, including dark web forums, malware repositories, breach databases, and open source feeds
Processing – converting that raw data into a usable format, filtering out noise and duplicate information so analysts aren’t drowning in irrelevant data
Analysis – interpreting the processed data to understand what it actually means for the organization, connecting indicators to known threat actors, campaigns, and TTPs
Dissemination – delivering the finished intelligence to the people who need it, whether that’s a SOC analyst, an incident responder, or a member of the leadership team, in a format they can act on
Feedback – reviewing how useful the intelligence was in practice and using that to refine priorities for the next cycle
This cycle runs continuously rather than as a single project, since threat actors change their tools and techniques constantly, and intelligence that was accurate last month can be outdated today.
There are three types of threat intelligence:
Tactical – focuses on malware analysis and behavioral threat indicators, provided in IoCs (indicators of compromise, such as a malicious file hash or IP address), CVEs and technical descriptions
Operational – focuses on understanding adversarial capabilities, infrastructure and TTPs
Strategic – focuses on understanding high level trends and adversarial motives and translates that into strategic security, which may affect business decisions
Why it matters from a security operations perspective
Beyond the financial and reputational stakes, CTI changes how a security team actually works day to day.
IoC enrichment gives raw indicators, a suspicious IP, a file hash, a malicious domain, real meaning. On their own they tell an analyst very little. With CTI, each indicator can be tied to a specific threat actor, a known campaign, and a typical method of deployment, turning a bare alert into something an analyst can prioritize and act on with confidence.
This is closely related to a concept known as the Pyramid of Pain,[^6] a model that ranks indicators by how much difficulty they actually cause an attacker when defenders block them. Simple indicators like file hashes or IP addresses sit at the bottom, since a threat actor can change them in seconds and carry on. TTPs sit at the top, because they represent an attacker’s actual behavior and are far harder to change without significant retooling. CTI helps security teams move their detection efforts up the pyramid, focusing on TTPs and adversary behavior rather than chasing indicators that a threat actor can swap out with almost no effort.
Earlier warning is another major benefit. Credentials remain heavily involved across the breach lifecycle even when they aren’t the initial entry point, so CTI providers monitoring underground markets and breach dumps can flag exposed usernames and passwords before they are used to gain access, turning what could have been a breach into a routine password reset.
Reduced dwell time is closely related. The longer an attacker sits undetected inside a network, the more they are able to exfiltrate. CTI-driven monitoring helps shorten the gap between compromise and detection, limiting how much damage is done before anyone notices.
Smarter patch prioritization also depends on good CTI. With tens of thousands of new CVEs published every year, no team can patch everything immediately. CTI helps prioritize patching based on which vulnerabilities are actively being exploited by threat actors targeting a company’s specific sector, rather than relying on severity score alone.
Fewer false positives means analysts spend less time chasing noise and more time on genuine threats, which matters for retention and burnout just as much as it does for security outcomes.
Finally, at the leadership level, strategic CTI feeds directly into business decisions: where to invest security budget, which third party vendors need closer scrutiny (as the Oxford and GTI case illustrates), and how to brief the board on current risk exposure.
Who are threat actors?
In order to provide a high quality CTI service, it is necessary to properly understand threat actors and their way of operation. A threat actor (TA) can be any individual, group or organization that intentionally causes harm, spreads malware, steals information from target victims. These TAs can be state sponsored (APT) or motivated by financial gain (cybercriminals) or political and religious views (hacktivists). Most of them are quite public and are even proud of their “achievements,” often publishing stolen data either for free or after offering the victim a deadline to pay.
Threat actors can be categorized into the following main groups:
Organized – motivated by financial gain, usually targets cash or data rich organizations and businesses. For example: Blind Eagle, Cobalt Group
Hacktivists – their goal and target group includes the exposing of secrets and organizations they deem “evil.” Usually they have strong political, social and/or religious views and ideologies. Example: Molerats, Marigold Sandstorm
State-sponsored – goals include espionage, theft, other disruptive activity, targets are mainly businesses and government-run organizations, which could prove useful to the initiating state. Example: Lazarus, APT19
Individuals
However, it’s important to note that TAs are evolving, are having multiple goals and motivations, and sometimes cannot clearly be put into one or the other category. As an example, Andariel, a North Korean state-sponsored threat group, is also conducting cyber financial operations.
As of June 2026 the top active groups, according to ransomware live statistics, are concentrated in a few key sectors. The most targeted sectors currently are business services, manufacturing technology, healthcare, and consumer services.
New groups are popping up quite often. Some of them are publishing valid data, while others are scamming by using fake, old or inaccessible data. It’s important for a potential victim to contact a company with the correct services and request professional help, as acting on their own could result in worse outcomes than doing nothing at all.
How We Can Help: Managed CTI Services
Running an in-house CTI program end to end requires dedicated analysts, access to paid and closed source intelligence feeds, and round the clock monitoring capacity, resources most organizations simply don’t have available internally. As an MSSP, we offer a Managed CTI service that takes this burden off your team while still delivering the earlier warnings and context described above.
Continuous monitoring of underground markets, breach databases, and leak sites for credentials and data tied to your domains
Vulnerability and CVE monitoring tailored to your specific technology stack, so patching efforts are prioritized around what’s actually being exploited
Domain and email takedown services, targeting malicious or impersonating domains, phishing infrastructure, and messages that impersonate your organization or your employees, before they can be used in phishing or fraud campaigns
External attack surface monitoring, keeping track of what your organization exposes to the internet, such as open ports, exposed services, and forgotten subdomains, so gaps can be closed before a threat actor finds them
Regular reporting, ranging from tactical IoC feeds for your security team to strategic summaries for leadership
Rather than building this capability from scratch, our clients get a dedicated team monitoring their exposure around the clock, with response actions like domain and email takedowns built directly into the service, so exposure isn’t just detected, it’s actively reduced.
As part of our CTI blog series, we will explore some of the most known threat actor groups in upcoming articles, looking at how each one operates, who they target, and what that means for your organization’s defenses.
Active Directory Certificate Services (AD CS) has long been a favorite target for attackers. The recently disclosed CertiGhost (CVE-2026-54121 – our CVE of the Week) vulnerability demonstrates that even well-managed environments can still contain unexpected paths to full domain compromise. [...]
What is Cyber Threat Intelligence, and why does it matter? Learn the CTI lifecycle, intelligence types, and how threat intelligence helps prevent cyberattacks.
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes.The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.