Do you have an incident?

Our S.O.S. line:

+49 89 262 025954

Our team of experts is ready to assist your organization in the event of a cyberattack.

details

Introduction to Cyber Threat Intelligence and Threat Actors

Cyber Threat Intelligence WhiteHat todayAugust 6, 2026

Background

In recent months several high-volume data breaches have been disclosed. They have impacted companies all over the world in different sectors. One thing is common in them: thousands of company and customer data was leaked, and it was followed by reputational and financial loss.

In the European Union, companies can face severe fines if the personal data of their employees or customers is compromised. Under GDPR, the most serious infringements carry penalties of up to 20 million euros or 4% of global annual turnover, whichever is higher.[^2] This exposure applies regardless of the root cause, whether the breach stemmed from business e-mail compromise (BEC), ransomware, an insider threat, or something as simple as a misconfiguration.

In the last few months quite a few companies have had to face hard financial and operational consequences.

  • EOGB Energy Products Ltd, a UK-based energy equipment supplier, experienced a cyber incident in June 2026 involving unauthorized access and potential data exposure.[^3] The breach affected business operations tied to energy product distribution and internal systems. Although technical specifics are limited, the case reflects increasing targeting of energy-related supply chains.
  • The University of Oxford was affected by a third party data breach in May 2026 through its vendor Group GTI, which operates the CareerConnect platform.[^4] Attackers gained unauthorized access to GTI systems, exposing names, email addresses, and encrypted passwords of students, alumni, and staff. The impacted business function was student career services relying on external SaaS infrastructure. The university itself was not directly compromised, highlighting supply chain risk.
  • Foxconn, the world’s largest contract electronics manufacturer, confirmed a ransomware attack on its North American operations in May 2026.[^5] The Nitrogen ransomware group claimed to have exfiltrated approximately 8TB of data across 11 million files, including technical drawings, project documentation, and financial records tied to major customers. The incident disrupted production at facilities in Wisconsin and Texas and shows that even the largest, most well resourced organizations remain exposed, particularly through supply chain relationships.

No system is 100% secure, but the use of Cyber Threat Intelligence (CTI) services could help prevent breaches. According to the 2026 Verizon Data Breach Investigations Report, vulnerability exploitation has become the leading way attackers gain initial access, but compromised credentials still play a major role throughout the breach lifecycle, showing up in close to 40% of breaches overall.[^1] CTI providers are able to monitor usernames and passwords involved in breaches, therefore able to give a timely warning, before an incident happens.

What is CTI?

CTI, Cyber Threat Intelligence, is the collection, processing and analysis of data to understand various threat actors’ motives, tactics, techniques and procedures (TTPs). It provides context and action-oriented advice via evidence-based knowledge, while also helping anticipate potential attacks.

The Threat Intelligence Lifecycle

CTI isn’t a one-off report, it’s a continuous cycle that repeats as new threats emerge and old ones evolve. The lifecycle is generally broken down into the following phases:

  • Planning and direction – defining what needs to be protected and what questions the intelligence effort should answer, based on the organization’s own risk profile and priorities
  • Collection – gathering raw data from a wide range of sources, including dark web forums, malware repositories, breach databases, and open source feeds
  • Processing – converting that raw data into a usable format, filtering out noise and duplicate information so analysts aren’t drowning in irrelevant data
  • Analysis – interpreting the processed data to understand what it actually means for the organization, connecting indicators to known threat actors, campaigns, and TTPs
  • Dissemination – delivering the finished intelligence to the people who need it, whether that’s a SOC analyst, an incident responder, or a member of the leadership team, in a format they can act on
  • Feedback – reviewing how useful the intelligence was in practice and using that to refine priorities for the next cycle

CTI-1-Cyber-Threat-Intelligence-Lifecycle

This cycle runs continuously rather than as a single project, since threat actors change their tools and techniques constantly, and intelligence that was accurate last month can be outdated today.

There are three types of threat intelligence:

  • Tactical – focuses on malware analysis and behavioral threat indicators, provided in IoCs (indicators of compromise, such as a malicious file hash or IP address), CVEs and technical descriptions
  • Operational – focuses on understanding adversarial capabilities, infrastructure and TTPs
  • Strategic – focuses on understanding high level trends and adversarial motives and translates that into strategic security, which may affect business decisions

Why it matters from a security operations perspective

Beyond the financial and reputational stakes, CTI changes how a security team actually works day to day.

IoC enrichment gives raw indicators, a suspicious IP, a file hash, a malicious domain, real meaning. On their own they tell an analyst very little. With CTI, each indicator can be tied to a specific threat actor, a known campaign, and a typical method of deployment, turning a bare alert into something an analyst can prioritize and act on with confidence.

This is closely related to a concept known as the Pyramid of Pain,[^6] a model that ranks indicators by how much difficulty they actually cause an attacker when defenders block them. Simple indicators like file hashes or IP addresses sit at the bottom, since a threat actor can change them in seconds and carry on. TTPs sit at the top, because they represent an attacker’s actual behavior and are far harder to change without significant retooling. CTI helps security teams move their detection efforts up the pyramid, focusing on TTPs and adversary behavior rather than chasing indicators that a threat actor can swap out with almost no effort.

CTI-1-Pyramid-of-Pain

Earlier warning is another major benefit. Credentials remain heavily involved across the breach lifecycle even when they aren’t the initial entry point, so CTI providers monitoring underground markets and breach dumps can flag exposed usernames and passwords before they are used to gain access, turning what could have been a breach into a routine password reset.

Reduced dwell time is closely related. The longer an attacker sits undetected inside a network, the more they are able to exfiltrate. CTI-driven monitoring helps shorten the gap between compromise and detection, limiting how much damage is done before anyone notices.

Smarter patch prioritization also depends on good CTI. With tens of thousands of new CVEs published every year, no team can patch everything immediately. CTI helps prioritize patching based on which vulnerabilities are actively being exploited by threat actors targeting a company’s specific sector, rather than relying on severity score alone.

Fewer false positives means analysts spend less time chasing noise and more time on genuine threats, which matters for retention and burnout just as much as it does for security outcomes.

Finally, at the leadership level, strategic CTI feeds directly into business decisions: where to invest security budget, which third party vendors need closer scrutiny (as the Oxford and GTI case illustrates), and how to brief the board on current risk exposure.

Who are threat actors?

In order to provide a high quality CTI service, it is necessary to properly understand threat actors and their way of operation. A threat actor (TA) can be any individual, group or organization that intentionally causes harm, spreads malware, steals information from target victims. These TAs can be state sponsored (APT) or motivated by financial gain (cybercriminals) or political and religious views (hacktivists). Most of them are quite public and are even proud of their “achievements,” often publishing stolen data either for free or after offering the victim a deadline to pay.

Threat actors can be categorized into the following main groups:

  • Organized – motivated by financial gain, usually targets cash or data rich organizations and businesses. For example: Blind Eagle, Cobalt Group
  • Hacktivists – their goal and target group includes the exposing of secrets and organizations they deem “evil.” Usually they have strong political, social and/or religious views and ideologies. Example: Molerats, Marigold Sandstorm
  • State-sponsored – goals include espionage, theft, other disruptive activity, targets are mainly businesses and government-run organizations, which could prove useful to the initiating state. Example: Lazarus, APT19
  • Individuals

CTI-1-Type-of-Threat-Actors

However, it’s important to note that TAs are evolving, are having multiple goals and motivations, and sometimes cannot clearly be put into one or the other category. As an example, Andariel, a North Korean state-sponsored threat group, is also conducting cyber financial operations.

As of June 2026 the top active groups, according to ransomware live statistics, are concentrated in a few key sectors. The most targeted sectors currently are business services, manufacturing technology, healthcare, and consumer services.

New groups are popping up quite often. Some of them are publishing valid data, while others are scamming by using fake, old or inaccessible data. It’s important for a potential victim to contact a company with the correct services and request professional help, as acting on their own could result in worse outcomes than doing nothing at all.

How We Can Help: Managed CTI Services

Running an in-house CTI program end to end requires dedicated analysts, access to paid and closed source intelligence feeds, and round the clock monitoring capacity, resources most organizations simply don’t have available internally. As an MSSP, we offer a Managed CTI service that takes this burden off your team while still delivering the earlier warnings and context described above.

Our Managed CTI service includes:

  • Continuous monitoring of underground markets, breach databases, and leak sites for credentials and data tied to your domains
  • Vulnerability and CVE monitoring tailored to your specific technology stack, so patching efforts are prioritized around what’s actually being exploited
  • Domain and email takedown services, targeting malicious or impersonating domains, phishing infrastructure, and messages that impersonate your organization or your employees, before they can be used in phishing or fraud campaigns
  • External attack surface monitoring, keeping track of what your organization exposes to the internet, such as open ports, exposed services, and forgotten subdomains, so gaps can be closed before a threat actor finds them
  • Regular reporting, ranging from tactical IoC feeds for your security team to strategic summaries for leadership

Rather than building this capability from scratch, our clients get a dedicated team monitoring their exposure around the clock, with response actions like domain and email takedowns built directly into the service, so exposure isn’t just detected, it’s actively reduced.

As part of our CTI blog series, we will explore some of the most known threat actor groups in upcoming articles, looking at how each one operates, who they target, and what that means for your organization’s defenses.


Sources

[^1]: Verizon, 2026 Data Breach Investigations Reporthttps://www.verizon.com/business/resources/reports/dbir/

[^2]: Regulation (EU) 2016/679 (GDPR), Article 83(5) – https://gdpr-info.eu/art-83-gdpr/

[^3]: DeXpose, “Stormous Targets EOGB Energy in Sophisticated Ransomware Attack” – https://www.dexpose.io/stormous-targets-eogb-energy-in-sophisticated-ransomware-attack/

[^4]: BleepingComputer, “Oxford University discloses data breach after careers platform hack” – https://www.bleepingcomputer.com/news/security/oxford-university-discloses-data-breach-after-careerconnect-platform-hack/

[^5]: The Register, “Apple supplier Foxconn confirms ransomware attack affected North American factories” – https://www.theregister.com/cyber-crime/2026/05/12/foxconn-confirms-cyberattack-after-nitrogen-claims-apple-nvidia-data-theft/5239144

[^6]: David J. Bianco, “The Pyramid of Pain” – https://detect-respond.blogspot.com/2013/03/the-pyramid-of-pain.html

 

Written by: WhiteHat

Tagged as: , , , .

Previous post

Similar posts