Cybersecurity 2026

USA Trends and Developments Contributed by: Brock Dahl, Beth George, Timothy Howard and Megan Kayo, Freshfields

Launching Attacks Against the Weakest Link in the Security Program One such effective technique leveraged by threat actors has been exploiting vulnerabilities in widely used third-party service platforms in order to gain access to the systems of such platforms’ customers. A third-party vendor with access to its customers’ systems presents an entry point that can be lever - aged, as an organisation’s cyber resilience is only as strong as that of each of its third-party vendors. For example, an organisation may update and patch vul - nerabilities in its own systems, but if its cloud pro - vider, software-as-a-service (SaaS) vendor, or hard - ware supplier lacks adequate security controls, the customer could be vulnerable to attack. Through this tactic, threat actors no longer need to target a single organisation. Rather than targeting and compromis - ing a single, widely used platform, they can attempt to gain access to thousands of downstream victims. A widely known and highly successful example of this was the MOVEit Transfer exploit, which demonstrated how a single zero-day vulnerability in a single enter - prise file transfer application could lead to numerous incidents affecting thousands of organisations. The Clop ransomware group discovered and exploited this zero-day. Before the software developer discovered it, Clop automated an attack that scanned the internet for vulnerable MOVEit servers and systematically exfil - trated massive amounts of data from them. There have also been reports of threat actors sys - tematically scanning for vulnerable systems after zero-day vulnerabilities are announced and attempt - ing to exploit them before patches can be applied. This trend ties back to how capable AI tools can be used to rapidly and efficiently scan for vulnerabilities in order to launch attacks against several organisa - tions. Security analysts have found that the average dwell time for ransomware, meaning the length of time threat actors remain undetected within systems, has dropped to less than a week. Many organisations only discover that their systems have been breached and that data has been exfiltrated when they are notified by the attackers themselves. Beyond vulnerabilities in systems, including third- party systems, humans have often been called the

as source code repositories, internal networks, data - bases, communications platforms, as well as creden - tials and private keys that secure sensitive information and financial assets. Sometimes, a single IT worker can secure work at multiple organisations and send it to less-skilled workers back in North Korea or other foreign jurisdictions. Through this insider threat cam - paign, North Korea has generated millions in illicit income. While the initial motivation for such IT worker schemes is typically financial, this insider access can also be leveraged to conduct espionage and gather threat intelligence. For example, with legitimate, trusted access, the IT worker can map internal networks, steal credentials, or embed hidden backdoors into systems that can be exploited later. These incidents have also turned into extortion campaigns involving data exfil - tration when the IT worker has been tipped off that the organisation suspects or knows that the IT worker is a foreign agent. Similarly, crypto theft is another scheme popular in North Korea. For example, in 2025, North Korea’s Lazarus group was attributed with stealing approxi - mately USD1.5 billion in Ethereum from the ByBit exchange. Reportedly, the threat actor group manipu - lated transaction approvals and drained approximate - ly 2,600 cold wallets. This incident demonstrates that financial gains from cybercrime can be a direct alter - native to international trade. Beyond direct state action, the distinction between financially motivated criminal groups and nation- states is increasingly blurring. In addition to North Korea using cyber criminals to help fund the regime’s weapons development and to evade sanctions, Iran also reportedly has used cybercrime to similarly cir - cumvent sanctions, and Russia has worked with cyber criminals to fund its war against Ukraine. Moreover, state actors frequently adopt the most effective tech - niques pioneered by cyber criminals to enhance their own espionage, disruption, and illicit revenue-gener - ating campaigns.

476 CHAMBERS.COM

Powered by