Cyber Attacks in 2026 Show Criminals and States Converging

Photo: BleepingComputer

Article

Cyber Attacks in 2026 Show Criminals and States Converging

The Ploutus arrest, the Air Force BEC sentencings and Russia's RedFlick tactic all point to one trend: attacks now blend criminal profit with state tradecraft.

JaysuryaOctober 5, 20264 min read

The thread: profit and statecraft are merging

Three recent cases logged on this beat describe what look like different crimes: ATM jackpotting, business email compromise, and a Russian state hacking campaign. Read together, they show a single pattern. The actors behind significant cyber attacks are converging on the same playbook, the same targets and often the same infrastructure, whether their motive is cash or espionage. For US technology companies and consumers, that convergence erodes the old assumption that financially motivated crime and nation-state operations can be defended against separately.

A malware economy with a long memory

The U.S. Department of Justice has announced the arrest of the alleged developer of Ploutus, malware used to steal millions of dollars in ATM jackpotting attacks across the United States, as BleepingComputer reported. Ploutus is not a new name. Its persistence is the point. A tool built to force ATMs to dispense cash has remained viable long enough for prosecutors to pursue the person allegedly responsible for writing it. That suggests the criminal side of this beat has developed something closer to a product lifecycle than a series of one-off schemes, with code that outlives individual crews and can be reused across campaigns.

Insiders who understand the plumbing

In a separate case, two former members of the United States Air Force were sentenced to a combined 189 months in federal prison for their roles in a multi-year series of business email compromise scams and phishing campaigns, again per BleepingComputer. BEC is the least exotic attack on this list, and that is exactly why it matters. It requires no zero-day and no novel exploit, only convincing messages and an understanding of how organizations route money and authority. The defendants' military backgrounds point to a broader hazard: the people best positioned to abuse a system's normal operation are often the ones trained to protect it. For US companies, the lesson is that the phishing threat model cannot be reduced to external strangers.

State tradecraft borrowing criminal techniques

The third case moves in the opposite direction. The Russian state actor Star Blizzard has been using a new malware installation tactic dubbed RedFlick to deploy its signature CosmicPulse backdoor, according to BleepingComputer. Nation-state operators have long favored stealth and patience over the smash-and-grab economics of ransomware or ATM jackpotting. Yet the mechanics of establishing a foothold, delivering a payload and keeping it resident overlap heavily with what criminal crews do. When a state actor adopts a fresh installation technique, it is effectively consuming the same innovation pipeline that criminal malware developers feed.

Why the convergence matters to US defenders

For US technology companies, the practical consequence is that threat intelligence and defenses built around a clean split between crime and espionage will underperform. An ATM malware developer, a pair of BEC fraudsters and a Russian state hacking team all exploit the same weak points: trust in email, trust in endpoints and trust in the software supply chain. A control that stops a phishing campaign also raises the cost of a state intrusion, and vice versa. Vendors that sell separate products for fraud prevention and nation-state defense are selling a distinction that attackers have already stopped observing.

For the US market, the cases suggest that losses attributed to cyber attacks will continue to concentrate in areas where identity and payment flows intersect. BEC targets wire transfers. Ploutus targets cash machines. Neither requires breaking strong cryptography; both require defeating human and process controls. That has implications for how financial institutions, retailers and technology providers allocate security budgets, and for insurers trying to price risk that does not respect the criminal-versus-state boundary.

For US consumers, the direct exposure runs through the same channels. A jackpotting attack at an ATM, a fraudulent payment instruction arriving in a compromised inbox and a state-backed backdoor inside widely used software all ultimately land on individuals' money, accounts or devices. The convergence does not necessarily mean more attacks, but it does mean each successful technique diffuses faster across actor types.

Enforcement as a signal, not a solution

The Justice Department's Ploutus arrest and the Air Force sentencings show that US law enforcement can reach actors across the spectrum, from malware authors to insider fraudsters. Prosecutions matter because they remove capability and impose cost. But enforcement is episodic, and the RedFlick case shows state actors operating beyond the practical reach of US courts. The pattern here is not that enforcement is failing; it is that enforcement alone cannot keep pace with a threat landscape where tools, techniques and talent move freely between profit-driven and state-directed operations.

What to watch

Watch whether the Ploutus prosecution reveals how widely the malware was shared or resold, since that would confirm how industrialized ATM jackpotting has become. Watch whether the BEC sentencings prompt US organizations to tighten controls on insider access to payment systems, rather than treating the case as an isolated instance of two bad actors. And watch how quickly RedFlick-style installation techniques appear in criminal campaigns, which would be the clearest evidence yet that the state and criminal toolchains are now effectively one. Each of these threads was logged separately on this beat. The value in 2026 is in reading them together.

More on this beat: Cybersecurity on TechManNews.

#cyber attacks#ATM malware#business email compromise#nation-state hacking#US cybersecurity

Newsletter

Get Tech News in Your Inbox

The latest AI, gadgets, software and startup stories from TechManNews, delivered every morning - free.