RH-ISAC Intelligence Trends Summary: April-June 2026
What: Retail cyber risk remained stable but intense in Q2 2026, with rising ransomware activity, impersonation domains, and remote access malware among the key concerns.
Why it is important: This is significant because it connects persistent retail threat patterns with recent evidence of rising account fraud, ransomware disruption, phishing, and remote access malware.
RH-ISAC’s Q2 2026 intelligence summary shows a largely stable threat landscape for retail and hospitality, with threat actors continuing to rely on familiar vectors such as fraud, social engineering, and malware. Intelligence sharing volumes rose significantly from Q1, although the main discussion categories remained broadly unchanged.
The report highlights a sharp rise in domains submitted by members, with more than 106,000 reported in Q2, largely linked to impersonation activity. This points to continuing brand abuse, phishing, and customer trust risks across consumer-facing businesses. Malware reporting also shifted: Amadey disappeared from the top trends after its Q1 appearance, while NetSupportManager RAT surged, suggesting greater use of remote access tooling.
Threat actor reporting stayed mostly consistent, though APT29, BazarCall, and Team PCP replaced MageCart and TA558 as notable trends. Feedly industry tracking showed little change in targeted industries, malware types, attack types, or company-size targeting, but The Gentlemen ransomware group emerged as a key actor. Restaurants continued to contribute unusually strong intelligence sharing relative to their membership weight.
IADS Notes: The RH-ISAC Q2 2026 intelligence summary reinforces a pattern already visible across recent retail cybersecurity reporting: cyber risk is becoming a business resilience issue rather than a narrow IT concern. In July 2026, Retail Insight Network linked retailers’ exposure to the combination of customer data, loyalty systems, payments, omnichannel operations, and connected supply chains, while RH-ISAC in June 2026 showed how account takeovers, loyalty fraud, synthetic identities, and bot-driven attacks are professionalising fraud against retail accounts. RH-ISAC’s March 2026 incident response findings further underline the financial and operational damage caused by ransomware and third-party breaches, while its November 2025 reporting on remote monitoring tools connects directly to the Q2 shift toward remote access malware. The February 2026 RH-ISAC analysis of QR-code phishing also supports the report’s warning that impersonation and social engineering remain central threats to customer trust and retail operations.


