Category: Article

  • 56 Million Records, 461 Stakeholders, Two Universities Down: What Indonesia’s 2025-2026 Breach Wave Reveals About the Security Maturity Gap

    56 Million Records, 461 Stakeholders, Two Universities Down: What Indonesia’s 2025-2026 Breach Wave Reveals About the Security Maturity Gap

    The Numbers Indonesia Cannot Ignore

    Indonesia recorded 56,128,160 personal data exposures across 461 stakeholders in 2024, according to BSSN’s Indonesian Cyber Security Landscape report. Through August 2025, BSSN counted 3.64 billion cyber attacks. In May 2026, breach disclosures have continued at pace: a high-severity compromise of Brawijaya University internal systems and an active dark-web sale of the Kota Gunungsitoli municipality database have surfaced within days of each other.

    Indonesia is ASEAN’s largest digital market. The threat is growing faster than the maturity. The PDP Law (UU No. 27/2022) has been fully in force since October 17, 2024. BSSN Regulation No. 1/2024 requires 24-hour incident reporting to Nat-CSIRT. The PDP Agency, Indonesia’s new data protection authority, is targeted for operational launch in mid-2026. The regulatory clock is running.

    This post is the executive briefing for any organization with Indonesian operations or Indonesian customer data. It explains the breach landscape, the regulatory expectations now in force, and the specific control upgrades that will determine whether the next incident is contained, public, or punitive.

    What Is Indonesia’s Current Data Protection Regime?

    Indonesia’s data protection framework rests on three pillars in 2026:

    1. UU No. 27/2022 (PDP Law). Fully enforceable since October 17, 2024. Maximum penalty is 2% of annual revenue plus criminal liability.
    2. BSSN Regulation No. 1/2024. Requires reporting of cyber incidents to the Nat-CSIRT within 24 hours, and registration of organizational CSIRTs. BSSN has registered 537 CSIRTs across government and private sector entities.
    3. PDP Agency. Targeted for operational launch in mid-2026 pending Presidential Regulation approval. Will hold enforcement authority including monetary penalties and criminal referral.

    For multinational organizations, Indonesia’s framework now sits alongside GDPR, NIS2, and DORA in a layered global compliance stack. Each adds its own incident classification logic and reporting deadlines.

    The Problem: Indonesia’s Maturity Gap

    Volume is overwhelming structural defenses

    3.64 billion cyber attacks recorded through August 2025 represents an attack volume no manual SOC can absorb. BSSN reports that 90% of attacks in Indonesia originate from malware, but the actual successful intrusions increasingly involve identity abuse and supply chain compromise as well.

    The 24-hour reporting clock leaves no room

    BSSN Regulation No. 1/2024 requires Nat-CSIRT notification within 24 hours of incident detection. For many organizations, that window expires before forensic clarity is achieved. Without pre-built incident classification workflows, the report is either rushed and incomplete or late and punitive.

    Critical sector incidents continue

    The 2024 National Data Centre ransomware attack disrupted 282 government services and was met with a USD 8 million ransom demand. The Brawijaya University compromise alleged in May 2026 and the active dark-web sale of the Kota Gunungsitoli database show that sub-national institutions remain undersecured even as the regulatory environment hardens.

    Compliance documentation is not yet operational

    Many organizations have policies on paper that meet PDP Law on the surface, but no operational evidence pipeline that proves continuous compliance. When the PDP Agency examines incidents in 2026, paper-only programs will not survive.

    What Happens When Indonesian Organizations Do Not Solve This?

    • PDP Law penalties of up to 2% of annual revenue, plus criminal liability for executives.
    • Nat-CSIRT reporting failures, which are publicly traceable and reputationally costly.
    • Customer attrition, particularly for fintech and e-commerce, where data trust is the brand.
    • Cross-border vendor exclusion, as multinational customers limit partnership with non-compliant Indonesian providers.

    Old Way vs. New Way: Indonesia Incident Posture

    Capability Pre-2024 Indonesian Practice 2026 Mandate
    Incident reporting Internal escalation only 24-hour Nat-CSIRT notification, audit-ready
    DPO function Optional or undefined Mandatory under PDP Law for many controllers
    Data classification Inconsistent Documented schema with consent and retention mapping
    CSIRT registration Ad hoc Formal BSSN-registered CSIRT for impacted sectors
    Threat intelligence Generic feeds Indonesia-specific actors, dark-web monitoring

    How Peris.ai Supports Indonesian Compliance Operations

    Peris.ai is registered with BSSN and operates from offices in Jakarta, Singapore, and Abu Dhabi. The platform is engineered to support the specific operational expectations of the PDP Law, BSSN Regulation No. 1/2024, and the incoming PDP Agency. Four components carry the weight.

    IRP for 24-hour Nat-CSIRT-ready reporting

    Peris.ai IRP captures audit-ready incident documentation from the first alert. The case template is aligned to BSSN’s 24-hour Nat-CSIRT submission format, so the report writes itself as the investigation proceeds. A leading Peris.ai client in financial services reported a 35% reduction in analyst workload after IRP rollout.

    BrahmaFusion for automated compliance evidence collection

    BrahmaFusion executes continuous control monitoring playbooks against PDP Law and BSSN regulatory baselines. Evidence is collected continuously, not reactively. A Peris.ai client achieved 40% SOC cost savings after this class of automation.

    INDRA CTI for Indonesia-specific threat intelligence

    INDRA CTI maintains intelligence on actors targeting Indonesian sectors, dark-web sales of Indonesian datasets, and credentials tied to Indonesian organizations. When data attributable to your organization surfaces in a forum, INDRA CTI notifies your team before the breach becomes public.

    Corporate Compliance consultation

    Peris.ai‘s 1-on-1 corporate compliance service supports organizations through PDP Law alignment, BSSN CSIRT registration, ISO/IEC 27001 (BSSN’s recommended reference standard), and PDP Agency readiness.

    Use Case: From Detection to Nat-CSIRT in Under 6 Hours

    A mid-market Indonesian e-commerce company using Peris.ai experiences the following.

    1. INDRA CTI detects a sample of customer email addresses tied to the company appearing in a Telegram channel known to broker Indonesian datasets.
    2. Our XDR confirms an unusual outbound data transfer from one of the company’s customer service tools two days earlier, correlated to an identity that recently failed an AiTM-pattern login defense.
    3. BrahmaFusion contains the impacted identity and isolates the source system.
    4. IRP opens a case, populates the Nat-CSIRT submission template, and pre-fills 80% of required fields from automated evidence.
    5. The compliance team submits the Nat-CSIRT notification within 5 hours 47 minutes of detection, well inside the 24-hour window.

    Outcomes That Matter

    Benefit Outcome
    24-hour Nat-CSIRT alignment Reporting met without scramble
    Continuous control monitoring Compliance evidence captured before audit
    Indonesia-specific threat intelligence Dark-web disclosures detected early
    BSSN-registered CSIRT support Organizational CSIRT operationalized to BSSN expectations
    Multilingual incident response English and Bahasa workflows in one platform

    Conclusion

    Indonesia’s regulatory and threat environment in 2026 will not reward paper compliance. The combination of PDP Law enforcement, BSSN 24-hour reporting, the incoming PDP Agency, and an attack volume measured in billions creates an operational threshold that only autonomous threat detection, hyperautomation SOC, and continuous compliance evidence can meet. Peris.ai is built for that threshold, and operates inside Indonesia, for Indonesian organizations and the multinationals that serve them.

    Learn how platforms like BrahmaFusion by Peris.ai empower lean security teams to automate incident response, scale compliance operations, and build trust where it matters most. Want more insights? Visit Peris.ai.

    FAQ

    What is the PDP Law in Indonesia?

    The PDP Law, UU No. 27/2022, is Indonesia’s comprehensive personal data protection regulation, fully enforceable since October 17, 2024. Penalties include up to 2% of annual revenue and criminal liability.

    When does the PDP Agency launch?

    The PDP Agency is targeted for operational launch in mid-2026, pending Presidential Regulation approval. It will hold enforcement authority over the PDP Law.

    How quickly must Indonesian organizations report cyber incidents?

    BSSN Regulation No. 1/2024 requires reporting to the Nat-CSIRT within 24 hours of detection. BSSN has registered 537 CSIRTs across government and private sector to facilitate this.

    What was the 2024 National Data Centre ransomware impact?

    The attack disrupted 282 government services and was accompanied by a USD 8 million ransom demand, making it one of the most consequential incidents in Indonesian cyber history.

    How does Peris.ai help with Indonesian compliance?

    Peris.ai IRP aligns to BSSN’s 24-hour Nat-CSIRT reporting format. BrahmaFusion automates continuous PDP Law and ISO/IEC 27001 control monitoring. INDRA CTI provides Indonesia-specific threat intelligence. Peris.ai‘s Corporate Compliance service guides PDP Law and PDP Agency readiness.

  • The Agentic SOC: Why Your Alert Queue Is a Relic and What Replaces It

    The Agentic SOC: Why Your Alert Queue Is a Relic and What Replaces It

    Microsoft’s Security Blog published a post in April 2026 with a clear argument: the alert queue is a relic. “The agentic SOC: Rethinking SecOps for the next decade” laid out a fundamental restructuring of how security operations centers should work, one in which autonomous AI agents investigate, triage, and recommend remediation without human analysts manually reviewing every alert in a queue.

    This is not a vendor roadmap item or a 2030 prediction. It is a description of what leading security teams are building right now in 2026. The SIEM, XDR, and SOAR are converging into a single AI-powered detection-investigation-response layer. SOC team structures built around the alert queue model are becoming operationally obsolete.

    This post explains the agentic SOC architecture emerging in 2026, why the two-layer model replacing the alert queue represents a structural improvement, and how Peris.ai‘s BrahmaFusion platform positions security teams at the front of this transition.

    What Is an Agentic SOC?

    An agentic SOC is a security operations center in which AI agents handle routine detection, investigation, and triage decisions autonomously, escalating to human analysts only when genuine judgment or authority is required. The key distinction from traditional automation is the word “agentic”: these systems do not just execute predefined rules. They reason, adapt, and act across multi-step investigation and response sequences.

    In a conventional SOC, an alert fires, lands in a queue, waits for an analyst, gets triaged by a human, and if warranted, triggers an investigation. The bottleneck is the human queue. In an agentic SOC, the AI agent handles the queue autonomously: it investigates the alert, correlates it with threat intelligence and historical context, assesses severity, and either closes it with documentation or escalates it with a full investigation summary for human review.

    The Two-Layer Agentic SOC Architecture

    Microsoft’s April 2026 framework describes two functional layers:

    Layer 1: Deterministic Autonomous Disruption

    This layer handles known, high-confidence threat patterns with fully automated responses. No human review required. Examples include:

    • Known malware signatures detected on an endpoint: automatic isolation
    • Credential stuffing attack against an authentication endpoint: automatic session revocation and MFA enforcement
    • Brute force attempt exceeding threshold: automatic IP block and account lockout

    The defining characteristic of Layer 1 is speed: responses execute in seconds without waiting for any human decision.

    Layer 2: Generative Agentic Triage and Investigation

    This layer handles novel, ambiguous, or multi-step incidents where a reasoning agent is needed to correlate signals, form hypotheses, and develop a recommended response. Examples include:

    • Behavioral anomalies that don’t match known attack signatures
    • Multi-stage attack chains spanning endpoint, network, and identity telemetry
    • Low-and-slow intrusions that look like normal activity when any single signal is viewed in isolation

    Layer 2 AI agents produce investigation summaries with recommended actions, which human analysts review and approve. The analyst’s role shifts from “process every alert” to “review AI-generated case summaries and make final decisions on complex incidents.”

    Why the Alert Queue Model Is Failing

    The Volume Problem

    Modern enterprise environments generate thousands of security alerts per day. No human analyst team can process that volume without significant triage shortcuts. The practical result is alert fatigue: analysts tune out low-priority alerts, miss genuine signals buried in noise, and accumulate backlogs of uninvestigated cases.

    The Speed Problem

    Attackers are not waiting in your analyst queue. A credential theft and lateral movement sequence can complete in minutes. A ransomware pre-cursor can stage across an environment in under an hour. By the time an analyst reviews a queued alert from six hours ago, the attack may already be in its exfiltration phase.

    The Talent Problem

    Experienced SOC analysts are scarce and expensive. Building a human team large enough to process enterprise alert volumes at human review speed is not a viable solution for most organizations. The agentic model reduces the analyst requirement without reducing security coverage.

    What Happens When Teams Stay With the Old Model

    • Alert fatigue leads to missed detections
    • Long mean time to detect (MTTD) allows attackers to complete operations before investigation begins
    • Analyst burnout from repetitive triage work reduces retention
    • Security coverage has a hard ceiling set by team headcount

    The Platform Convergence Happening Now

    The agentic SOC is being enabled by the convergence of tools that were previously separate:

    Old Model New Converged Model
    SIEM (log collection and correlation) Unified AI detection platform
    XDR (cross-domain telemetry) Integrated telemetry layer with agentic analysis
    SOAR (playbook automation) AI agent that builds and executes response workflows
    Threat intelligence platform Embedded CTI that informs every investigation
    Case management tool AI-generated case summaries with recommended actions

    This convergence is what BrahmaFusion by Peris.ai is built on: a single platform that integrates detection, investigation, response automation, and threat intelligence into a unified agentic operating layer.

    How BrahmaFusion Powers the Agentic SOC

    The No-Code AI Playbook Builder

    BrahmaFusion’s no-code AI Playbook Builder allows security teams to define agentic response workflows without engineering overhead. Playbooks trigger on behavioral indicators, execute multi-step investigation sequences, and perform containment actions automatically. The result is Layer 1 and Layer 2 capability without requiring custom integration development.

    A finance startup using BrahmaFusion achieved 40% SOC cost savings by replacing manual triage cycles with automated playbook execution. A leading telco reduced incident response time from 30 minutes to 3.3 minutes.

    XDR Integration for Full-Spectrum Telemetry

    Peris.ai‘s XDR provides the telemetry foundation that agentic investigation requires: behavioral data across endpoint, network, and cloud environments. Without full-spectrum telemetry, an AI agent investigating a complex incident will reach the same dead ends a human analyst reaches when visibility is incomplete. XDR’s cross-domain correlation enables the Layer 2 investigation capability that makes the agentic model work for novel and multi-stage incidents.

    IRP for Human-in-the-Loop Escalation

    Peris.ai IRP provides the case management layer where agentic investigations are escalated to human analysts. Rather than presenting raw alerts, IRP delivers AI-generated investigation summaries with full event timelines, recommended response actions, and supporting evidence. The analyst reviews, approves, and escalates. The investigation work is already done.

    A finance company CEO using Peris.ai IRP reported a 35% reduction in analyst workload, exactly the shift the agentic SOC model is designed to produce.

    100+ Integrations for the Converged Stack

    BrahmaFusion integrates with 100+ security and IT tools, enabling the platform convergence the agentic SOC requires. Whether your environment includes legacy SIEM infrastructure, cloud-native detection tools, or a mix of vendor-specific endpoint solutions, BrahmaFusion connects across the stack and provides the unified agentic layer that the alert queue model never could.

    A Real-World Agentic SOC Scenario

    At 2:47 AM on a Tuesday, an anomalous authentication event fires from a legitimate employee account: the login is from an unfamiliar IP, at an unusual hour, followed immediately by access to a file server the user has never accessed before.

    In a traditional alert-queue SOC: the alert sits in the morning queue. By 9 AM, an analyst picks it up. By 10 AM, they’ve confirmed it’s suspicious. By 11 AM, they’ve initiated containment. The attacker has had eight hours.

    In a BrahmaFusion agentic SOC: within 90 seconds, the AI agent correlates the authentication anomaly with XDR telemetry, identifies the lateral movement pattern, cross-references INDRA CTI for similar TTPs, and executes a Layer 1 playbook: session revocation and endpoint isolation. A Layer 2 investigation summary is generated and queued for analyst review with a complete timeline. The analyst reviews and approves at 9 AM. The incident is already contained.

    Benefits of the Agentic SOC with Peris.ai

    Benefit Outcome
    Automated triage and investigation Eliminates alert queue backlog and fatigue
    Layer 1 autonomous containment Stops known threats in seconds without human review
    Layer 2 AI-generated investigation summaries Analyst reviews conclusions, not raw alerts
    40% SOC cost reduction Documented outcome from BrahmaFusion deployment
    35% analyst workload reduction Documented outcome from Peris.ai IRP deployment

    Conclusion

    The alert queue model served the SOC well for two decades. It is no longer adequate for an environment where attack speed is measured in minutes and alert volume is measured in thousands per day. The agentic SOC is not a future state. Microsoft, Peris.ai, and the organizations running these platforms today are demonstrating that it is the present one.

    If your SOC is still built around a human-reviewed alert queue, you are already behind the operational curve. The transition to an agentic model is not just an efficiency upgrade. It is a structural security improvement.

    Explore the Peris.ai Automation Layer and BrahmaFusion’s no-code AI Playbook Builder at brahma.peris.ai. Visit Peris.ai to see how leading organizations are building the agentic SOC today.

    Frequently Asked Questions

    What is an agentic SOC?

    A security operations center in which AI agents handle detection, investigation, and triage autonomously, escalating to human analysts only for complex or high-stakes decisions. It replaces the human-reviewed alert queue model.

    What are the two layers of the agentic SOC architecture?

    Layer 1 handles known, high-confidence threats with fully automated responses (no human review). Layer 2 handles novel or complex incidents through generative AI investigation, producing summaries that human analysts review and approve.

    Why is the traditional alert queue model failing?

    Alert volume has outpaced human triage capacity, attack speed has outpaced human review cycles, and alert fatigue means genuine threats are regularly missed in high-volume queues.

    How does BrahmaFusion enable the agentic SOC?

    BrahmaFusion provides a no-code AI Playbook Builder, 100+ integrations, and automated response workflows that execute both Layer 1 containment and Layer 2 investigation sequences without requiring custom engineering.

    What is the difference between SOAR and an agentic SOC platform?

    Traditional SOAR executes predefined, rule-based playbooks. Agentic SOC platforms use AI agents that reason, adapt, and handle novel situations that predefined rules cannot anticipate.

  • October 2026 Is Your Final Warning: A CISO’s Practical Roadmap to NIS2 and DORA Compliance

    October 2026 Is Your Final Warning: A CISO’s Practical Roadmap to NIS2 and DORA Compliance

    The first NIS2 audit deadline is June 30, 2026. The full compliance deadline is October 2026. DORA has been in force since January 17, 2025. And the European Commission’s Digital Omnibus package is converging NIS2, GDPR, eIDAS, DORA, and the CER Directive into a single incident reporting pathway.

    For CISOs and compliance officers at essential and important entities across Europe, the compliance runway is nearly exhausted. Essential entities face fines up to €10 million or 2% of global annual turnover for failing to meet NIS2 cybersecurity risk-management requirements. Important entities face fines up to €7 million or 1.4% of global turnover. These are not theoretical penalties; national supervisory authorities across Germany, Portugal, and Austria are already actively enforcing.

    This post gives CISOs a clear, action-oriented roadmap: what NIS2 and DORA compliance requires in 2026, where most organizations still fall short, and how agentic automation dramatically shortens the compliance gap.

    What Is NIS2 DORA Compliance in 2026?

    NIS2 (Network and Information Systems Directive 2) is the European Union’s updated cybersecurity framework, requiring essential and important entities to implement at least 10 cybersecurity risk-management measures, including incident response capabilities, supply chain security, access control, and business continuity planning. DORA (Digital Operational Resilience Act) applies specifically to financial entities and their critical ICT third-party providers, mandating digital operational resilience testing, ICT risk management, and incident reporting frameworks. Both are in force in 2026.

    Where Are Organizations Still Falling Short on NIS2 DORA Compliance?

    1. Incident Reporting Timelines Are Not Operationalized

    NIS2 requires notification within 24 hours of becoming aware of a significant incident, with a detailed report within 72 hours. DORA has similar requirements for financial entities. Most organizations have a compliance policy that references these timelines, but lack the automated tooling to generate the required reports at speed during an active incident when security teams are already under maximum pressure.

    2. Supply Chain Security Requirements Are Broadly Unfulfilled

    NIS2 Article 21 includes explicit supply chain security requirements: organizations must assess and manage security risks in their relationships with direct suppliers and service providers. For organizations with dozens or hundreds of third-party integrations, this represents a significant gap. Manual vendor assessments are neither scalable nor continuous.

    3. The 10 Risk-Management Measures Are Partially Implemented

    NIS2 Article 21 mandates at least 10 cybersecurity risk-management measures including: policies on risk analysis and information system security; incident handling; business continuity; supply chain security; security in network and information systems acquisition, development, and maintenance; policies and procedures for assessing cybersecurity risk-management measures effectiveness; basic cyber hygiene practices and cybersecurity training; policies and procedures relating to cryptography; human resources security; access control policies; and asset management. Most organizations can check the policy box. Fewer have operationalized these as measurable, continuously monitored controls.

    4. Management Body Accountability Is Underestimated

    NIS2 explicitly places accountability on the management body of essential and important entities. Senior leadership can be held personally liable for failures to approve and oversee cybersecurity risk-management measures. This is a structural shift from treating cybersecurity as an IT department function.

    What Happens When Organizations Miss the NIS2 DORA Compliance Deadline

    Essential entities face administrative fines up to €10 million or 2% of global annual turnover. Important entities face fines up to €7 million or 1.4% of turnover. Beyond financial penalties, supervisory authorities can issue binding instructions, suspend certifications, and impose temporary prohibitions on individuals in managerial positions from exercising managerial functions. For financial entities under DORA, non-compliance also creates ICT risk management gaps that increase operational resilience requirements under European Banking Authority oversight.

    NIS2 Compliance Gap Analysis: Where Most Organizations Stand Today

    NIS2 Article 21 Requirement Common Compliance Gap
    Incident handling policies Policies exist; automated reporting timelines not operationalized
    Business continuity and crisis management Plans documented; not tested under realistic breach conditions
    Supply chain security assessment Periodic vendor questionnaires; no continuous monitoring
    Risk analysis and information system security Annual assessments; not continuous risk monitoring
    Effectiveness measurement policies No automated metrics collection for control effectiveness
    Cryptography and encryption Policies in place; implementation inconsistency across systems
    Access control MFA deployed for primary systems; gaps in legacy and shadow IT
    Asset management Primary asset inventory maintained; cloud and shadow assets incomplete

    How Peris.ai Helps Close the NIS2 DORA Compliance Gap

    BrahmaFusion: Automated Evidence Collection and Compliance Playbooks

    BrahmaFusion is Peris.ai‘s agentic AI hyperautomation platform. For NIS2 and DORA compliance, BrahmaFusion enables automated evidence collection that continuously documents the operation of cybersecurity controls, compliance playbooks that trigger the correct notification and documentation workflows within NIS2’s 24-hour and 72-hour incident reporting windows, and continuous monitoring across 100+ integrations that generates the asset and control coverage data needed for Article 21 effectiveness measurement.

    A finance startup using BrahmaFusion reduced SOC costs by 40% while increasing detection and documentation coverage, directly addressing the resource constraint that most compliance teams face.

    Peris.ai IRP: Audit-Ready Incident Documentation and Response Timelines

    Peris.ai IRP provides the structured incident case management that NIS2 and DORA notification requirements demand. When an incident is detected, IRP automatically generates a timestamped case record, MITRE ATT&CK mapping, AI-powered incident summaries, and response timeline documentation aligned to regulatory reporting windows. The incident report that supervisory authorities request is generated as part of the response process, not assembled afterward under deadline pressure.

    INDRA CTI: Continuous Threat Intelligence for NIS2 Article 21 Risk Management

    NIS2 Article 21 requires organizations to conduct ongoing risk analysis and information system security assessments. INDRA CTI provides the continuous external threat intelligence that informs this risk analysis: real-time intelligence on vulnerabilities affecting your industry sector, threat actor campaigns targeting your supply chain partners, and early warning on zero-day exploits being weaponized against your technology stack.

    Real-World Scenario: Meeting a 24-Hour NIS2 Notification Requirement Under Pressure

    A financial services essential entity under NIS2 detects at 11pm on a Friday that a threat actor has accessed a customer data environment through a compromised vendor integration. The security team is managing active containment while simultaneously needing to generate a notification to their national supervisory authority within 24 hours.

    Peris.ai IRP’s automated documentation has already compiled: the incident timeline from first detection through containment actions, the affected systems and data categories, the MITRE ATT&CK techniques observed, and the initial impact assessment. BrahmaFusion’s compliance playbook generates a draft NIS2 initial notification aligned to Article 23 requirements, pre-populated with verified incident data.

    The compliance team reviews and submits the notification at 8am Saturday, well within the 24-hour window. The 72-hour detailed report is pre-populated from IRP’s continuous case documentation. No compliance deadline is missed, and the security team’s containment effort is not disrupted by parallel documentation demands.

    Benefits at a Glance

    Benefit Outcome
    Automated NIS2 notification workflows 24-hour and 72-hour reporting deadlines met without crisis documentation scramble
    Continuous control effectiveness documentation Article 21 evidence available for audit without manual compilation
    35% analyst workload reduction via IRP Compliance and response teams maintain capacity during incidents
    INDRA CTI for ongoing risk analysis Continuous external threat intelligence fulfills Article 21 risk assessment requirement
    Supply chain monitoring integration Third-party security assessment automation aligned to NIS2 supply chain requirements
    Management-level reporting dashboards Board-level cybersecurity oversight documentation for management body accountability

    Conclusion

    The NIS2 DORA compliance deadline is not a future problem. It is a present operational requirement. Essential and important entities that have not operationalized their Article 21 controls, automated their incident reporting workflows, and established continuous risk monitoring have months, not years, to close the gap before audit exposure becomes financial liability.

    BrahmaFusion, Peris.ai IRP, and INDRA CTI give compliance teams and CISOs the automation infrastructure to meet NIS2 and DORA requirements at operational speed, without multiplying headcount. The compliance journey starts with visibility. Build it now.

    Learn how platforms like BrahmaFusion by Peris.ai empower compliance teams to automate evidence collection, accelerate incident reporting, and maintain continuous control effectiveness documentation. Want more insights? Visit Peris.ai.

    Frequently Asked Questions

    What is the NIS2 compliance deadline in 2026?

    The first NIS2 audit deadline is June 30, 2026, with full compliance required by October 2026. DORA has been in force across all EU nations since January 17, 2025.

    What are the fines for NIS2 non-compliance?

    Essential entities face fines up to €10 million or 2% of global annual turnover. Important entities face fines up to €7 million or 1.4% of global annual turnover, as well as potential personal liability for management body members.

    What does NIS2 Article 21 require?

    NIS2 Article 21 mandates at least 10 cybersecurity risk-management measures including incident handling, supply chain security, access control, risk analysis, business continuity, cryptography policies, asset management, and effectiveness measurement.

    How does DORA differ from NIS2?

    DORA applies specifically to financial entities and their critical ICT third-party providers, focusing on digital operational resilience testing, ICT risk management frameworks, and ICT incident reporting. NIS2 is broader, covering essential and important entities across multiple sectors with cybersecurity risk-management requirements.

    How can automation help with NIS2 DORA compliance?

    Automation addresses the two biggest compliance execution gaps: incident reporting timelines and continuous control documentation. Platforms like BrahmaFusion by Peris.ai generate compliance-ready documentation during incidents and maintain continuous control evidence that satisfies Article 21 effectiveness measurement requirements without manual compilation.

  • The $360 Billion Target: Why Indonesia’s Digital Economy Growth Is Making It Southeast Asia’s Most Attacked Nation

    The $360 Billion Target: Why Indonesia’s Digital Economy Growth Is Making It Southeast Asia’s Most Attacked Nation

    Indonesia’s digital economy will reach $360 billion by 2030. It already faces 3,300 cyberattacks per week. The cyber defenses are not keeping pace with the growth.

    In 2030, Indonesia is projected to host ASEAN’s largest digital economy at $360 billion, up from $130 billion in 2025. It will be one of the fastest-growing digital markets in the world: hundreds of millions of internet users, a booming e-commerce sector, a rapidly digitalizing government, and an explosion of fintech adoption.

    And right now, in 2026, Indonesia is already the most attacked nation in the ASEAN region. An average of 3,300 cyberattacks per week, measured across the February to August 2024 period. Nation-state actors. Ransomware groups. BEC fraud operations. Data theft campaigns. All targeting Indonesia because it is valuable, growing, and, in many respects, still building the cyber defenses its ambitions require.

    The gap between Indonesia’s digital growth trajectory and its cybersecurity readiness is not just a technology problem. It is a business risk that every enterprise operating in the country needs to take seriously, now, before the next wave of attacks finds the vulnerabilities that current defenses are not monitoring.

    Why Is Indonesia the Most Attacked Nation in ASEAN?

    Indonesia’s vulnerability is structural, not accidental. Several converging factors make it a disproportionately attractive target:

    Scale Without Equivalent Security Investment

    The Indonesian digital economy’s scale is enormous: 277 million people, widespread mobile-first internet adoption, and one of the highest smartphone penetration rates in the Asia-Pacific. This scale creates a massive attack surface. But the security investment has not scaled proportionally. Many organizations, particularly small and mid-sized enterprises, operate with minimal dedicated cybersecurity capability.

    Regulatory Gap During a Period of Rapid Growth

    Indonesia and the Philippines are the only ASEAN nations without a dedicated cybersecurity law. Indonesia relies on broader information technology regulations to address cyber incidents. This creates a compliance environment where security standards are inconsistent across sectors, breach reporting obligations are unclear, and minimum security baselines are unevenly enforced.

    The RUU Keamanan Siber dan Ketahanan Siber is in progress, and BSSN is being elevated to ministerial equivalent status. But until these frameworks are fully enacted and enforced, organizations face a regulatory environment that does not compel cybersecurity investment at the pace the threat landscape demands.

    Nation-State Interest in ASEAN Infrastructure

    Salt Typhoon compromised 600+ organizations across 80 countries specifically targeting telecommunications infrastructure. ASEAN’s rapidly expanding 5G networks and digital government platforms are directly in the crosshair of nation-state espionage operations. Indonesia’s growing role in ASEAN’s digital economy makes its infrastructure strategically valuable as an intelligence target.

    What Happens When Digital Growth Outpaces Cyber Defense

    • Fintech platforms with millions of users operate on infrastructure with limited security monitoring
    • Government digital services hold sensitive citizen data protected by inconsistent security standards
    • Supply chain attacks targeting Indonesian vendors cascade into multinational organizations through partner integrations
    • Ransomware groups increasingly target Indonesian organizations, knowing response capability is often limited
    • 3,300 attacks per week means approximately 470 attacks every single day, against organizations of all sizes

    Indonesia in the ASEAN Cybersecurity Landscape

    ASEAN’s cybersecurity landscape is characterized by significant variation in maturity across member states:

    • Singapore: Highest cybersecurity maturity in ASEAN, comprehensive legal framework, mandatory breach reporting
    • Malaysia, Thailand, Vietnam: Progressing regulatory frameworks with increasing enforcement
    • Indonesia, Philippines: Highest attack volumes, developing regulatory frameworks, significant investment gaps

    ASEAN’s overall cybersecurity posture is constrained by a lack of homegrown cybersecurity capabilities and a unified regional framework. The ASEAN Cybersecurity Cooperation Strategy (CCS) 2021-2025 aimed to address this through policy harmonization, but national implementation has been uneven.

    Peris.ai is uniquely positioned in this landscape: headquartered in Singapore with offices in Jakarta (Tokopedia Care Tower), Peris.ai provides regional coverage for ASEAN organizations navigating this complex and rapidly evolving threat environment.

    The Old Way vs. The New Way: Cybersecurity for Indonesia’s Digital Economy

    Legacy Security Posture Modern Cybersecurity Posture
    Reactive security after incidents occur Continuous monitoring and proactive threat hunting
    Compliance-driven minimum security standards Risk-driven security investment calibrated to actual attack surface
    Single-vendor perimeter tools Unified XDR, EDR, and NVM coverage across the full environment
    No incident response automation BrahmaFusion automated containment and IRP case management
    No threat intelligence on regional threats INDRA CTI with ASEAN-relevant threat actor attribution

    How Does Peris.ai Support Indonesian Enterprises?

    As an agentic AI cybersecurity company with a registered presence in Indonesia and operational knowledge of the BSSN regulatory environment, Peris.ai is positioned to help Indonesian and ASEAN enterprises build the security capabilities their digital growth requires.

    Full platform coverage for Indonesian enterprise environments:

    • XDR: Unified detection across endpoint, network, and identity layers, providing the comprehensive threat visibility that traditional perimeter security cannot deliver
    • EDR: Endpoint protection covering the diverse device environments common in Indonesian enterprise and SME contexts
    • NVM: Network Visibility Monitor providing packet-level inspection to detect nation-state lateral movement and data exfiltration patterns
    • INDRA CTI: Real-time threat intelligence with threat actor attribution covering ASEAN-relevant campaigns including Salt Typhoon, Handala, and ransomware groups actively targeting Indonesian organizations
    • BrahmaFusion: Agentic AI and hyperautomation platform enabling lean security teams to operate at enterprise scale

    The regional presence advantage:

    Peris.ai’s Jakarta office means in-country expertise for Indonesian organizations navigating the specific regulatory requirements of BSSN compliance, UU PDP implementation, and the forthcoming cybersecurity law. This is not remote support from Singapore. It is local understanding of the threat landscape, the regulatory environment, and the operational realities of Indonesian enterprise security.

    A leading telco using Peris.ai’s platform reduced incident response time from 30 minutes to 3.3 minutes, directly relevant to an environment where 3,300 weekly attacks mean the response clock is always running.

    Real-World Scenario: Protecting an Indonesian Fintech During Rapid Growth

    An Indonesian fintech platform has grown from 500,000 to 4 million users in 18 months. Its security infrastructure has not scaled proportionally. The platform processes $2 billion annually in transactions and holds personal and financial data for 4 million customers.

    Without comprehensive security: The platform is targeted by a ransomware group that identifies its rapid growth and limited security monitoring as an opportunity. Initial access is gained through a credential stuffing attack on a poorly monitored administrative interface. The attack is not detected for 11 days.

    With Peris.ai full platform deployment:

    • INDRA CTI surfaces credential stuffing activity targeting the fintech’s domain from a known threat actor infrastructure within hours of initial attack attempts.
    • EDR detects anomalous authentication patterns on the administrative interface and triggers an alert.
    • BrahmaFusion automatically locks the compromised administrative account and initiates an investigation playbook.
    • The security team receives a complete incident report. The attack is contained before lateral movement begins.

    Four million customer records protected. Business continuity maintained.

    Benefits of the Peris.ai Platform for Indonesian Enterprise Security

    Benefit Outcome
    Local Jakarta presence and BSSN registration Regulatory expertise and in-country support
    INDRA CTI with ASEAN threat actor coverage Indonesia-relevant threat intelligence in real time
    Full XDR, EDR, NVM platform coverage No blind spots in the Indonesian enterprise attack surface
    BrahmaFusion agentic AI automation Lean security teams operating at enterprise scale
    53% breach impact reduction Documented outcome protecting high-growth digital environments

    Conclusion

    Indonesia’s path to a $360 billion digital economy is one of the most compelling growth stories in the Asia-Pacific. But every additional billion dollars in digital economic value increases the attractiveness of Indonesia as a cyber target. The organizations that will succeed in this environment are those that build their security posture ahead of their growth curve, not after the breach that makes it a priority.

    Peris.ai, with offices in Singapore and Jakarta, is built for exactly this challenge. Real-time threat intelligence, agentic AI response, and regional expertise in the ASEAN threat landscape.

    Learn how Peris.ai supports Indonesian enterprise security at peris.ai. Your digital ambition deserves protection that matches its scale.

    Frequently Asked Questions

    Why is Indonesia the most attacked nation in ASEAN?

    Indonesia combines several factors that make it a disproportionately attractive cyber target: ASEAN’s largest population (277 million), one of the region’s fastest-growing digital economies, relatively high-value targets across fintech and e-commerce, and a regulatory environment still developing the enforcement mechanisms to compel consistent security investment across sectors.

    How does Indonesia’s lack of a dedicated cybersecurity law affect enterprise security?

    Without a dedicated cybersecurity law, Indonesia lacks unified minimum security standards, clear breach reporting obligations, and consistent enforcement across sectors. This creates a compliance environment where security investment is driven by each organization’s own risk assessment rather than regulatory requirement, resulting in significant variation in security maturity across the Indonesian enterprise landscape.

    What is Peris.ai’s presence in Indonesia?

    Peris.ai has an office at the Tokopedia Care Tower in Jakarta and is registered with BSSN, Indonesia’s national cybersecurity agency. This gives Peris.ai both the regulatory standing and the in-country expertise to support Indonesian enterprises navigating the specific requirements of the BSSN framework, UU PDP compliance, and the forthcoming cybersecurity law.

    What should Indonesian enterprises prioritize for cybersecurity investment in 2026?

    Given the 3,300 weekly attacks and the imminent strengthening of BSSN’s enforcement powers, Indonesian enterprises should prioritize: unified threat detection coverage (XDR/EDR/NVM), automated incident response capability (IRP/SOAR), real-time threat intelligence relevant to ASEAN threat actors (INDRA CTI), and documentation of security controls for regulatory compliance. Peris.ai’s full platform addresses all four of these priorities.

  • Inside the $200 AiTM Phishing Kit Economy: How Tycoon 2FA, EvilProxy, and Mamba 2FA Industrialized MFA Bypass

    Inside the $200 AiTM Phishing Kit Economy: How Tycoon 2FA, EvilProxy, and Mamba 2FA Industrialized MFA Bypass

    The $200 Toolkit That Killed Your MFA

    For years, security teams have told executives that multi-factor authentication stops phishing. In 2026, that statement is no longer technically accurate. The reason is a commoditized class of phishing infrastructure called adversary-in-the-middle, or AiTM, that you can rent on a dark web marketplace for less than the cost of a mid-tier streaming bundle.

    AiTM kits including Tycoon 2FA, Rockstar 2FA, EvilProxy, Greatness, and Mamba 2FA have industrialized session-token theft. They defeat OTP, push notifications, and even hardware tokens used as a second factor. The CrowdStrike 2026 Global Threat Report attributes 82% of detections in 2025 to malware-free identity abuse, and AiTM session theft is the dominant pattern inside that majority.

    This post is a technical breakdown. We will look at how AiTM kits work at the HTTP layer, what telemetry signatures detection engineers can hunt, and how Peris.ai builds session-anomaly detection that survives the new normal.

    What Is an AiTM Phishing Kit?

    An adversary-in-the-middle phishing kit is a reverse proxy that sits between a victim and a legitimate authentication portal. The victim believes they are typing credentials into Microsoft 365 or Google Workspace. They are. The credentials reach the real provider. The MFA challenge fires. The victim approves it. And at the moment the session cookie is issued, the attacker captures it from the proxy, ending the legitimate authentication on the victim side and resuming it on the attacker side.

    From the user’s perspective, login worked. From the attacker’s perspective, the user just delivered a fully authenticated session.

    Anatomy of the attack flow

    • Phishing email or messaging lure points to a look-alike URL.
    • The look-alike URL is the AiTM reverse proxy.
    • The proxy fetches the legitimate Microsoft or Google login page in real time.
    • The victim enters credentials. The proxy relays them.
    • The legitimate provider issues an MFA prompt. The victim approves it.
    • The session cookie is issued. The proxy logs the cookie and the credentials.
    • The attacker replays the session cookie to the legitimate service and is now logged in as the user.

    Which MFA Methods Survive AiTM, and Which Do Not?

    MFA Method AiTM Resistance
    SMS OTP None. Cookie theft bypasses entirely.
    TOTP authenticator None. Same cookie theft path.
    Push notification None. User approves a legitimate prompt.
    Hardware token as second factor (OTP-generating) None. Cookie still issued.
    WebAuthn / FIDO2 / passkeys Resistant. Cryptographic challenge bound to origin URL, cannot be replayed through proxy.

    WebAuthn and FIDO2 are the only widely deployed phishing-resistant standards. CISA’s Phishing-Resistant MFA Implementation Guidance, updated in 2025, explicitly recommends FIDO2 as the standard for high-value identities.

    What Detection Engineers Should Hunt

    AiTM activity leaves telemetry, but it lives at the seam between authentication logs and session cookie issuance. Detection engineers should baseline and alert on:

    • Successful authentication followed by session cookie issuance to an unexpected source IP within seconds.
    • TLS fingerprint anomalies, particularly JA3 or JA4 mismatches between the user’s normal client and the source of cookie reuse.
    • User-agent strings that do not match the user’s installed inventory.
    • Geographic impossibility patterns: successful login from country A, session token used from country B within sixty seconds.
    • Anomalous OAuth consent grants immediately following AiTM-pattern logins, which often persist access after credential rotation.
    • Mass campaigns targeting energy, finance, and government sectors via SharePoint and Outlook Web Access proxies, consistent with the January 2026 multi-stage AiTM campaign observed by Microsoft.

    The Problem: Why Traditional SIEM Misses AiTM

    Most SIEM detections operate on authentication events. From the SIEM’s point of view, the login succeeded, MFA was satisfied, and the session is healthy. The fraudulent reuse of the cookie happens out-of-band, often from a different network, and looks like normal user activity unless behavioral baselines are explicit.

    This is the structural reason AiTM has become the dominant initial access vector for BEC, VEC, and ransomware deployment in 2026. The kit is cheap, the defenders’ tooling is misaligned, and the user behaves correctly throughout.

    How Peris.ai Detects and Contains AiTM Sessions

    Peris.ai’s agentic AI cybersecurity stack treats identity as the new perimeter and correlates authentication events with session behavior in real time. Three components carry the detection load.

    XDR for identity threat detection

    Our XDR ingests authentication and session-cookie telemetry across Microsoft Entra ID, Google Workspace, Okta, and on-premises identity providers. It compares each successful authentication to the user’s behavioral baseline: typical source IPs, TLS fingerprints, user-agent strings, and session reuse patterns. When the post-authentication session deviates, XDR raises an identity-tier anomaly.

    BrahmaFusion for automated session revocation

    When XDR raises the alert, BrahmaFusion executes the response playbook in seconds. It revokes the active session, forces a step-up authentication, and isolates downstream systems the user had access to. A Peris.ai telco client reduced response time from 30 minutes to 3.3 minutes after BrahmaFusion deployment. Identity-tier incidents are a perfect fit for that automation gain.

    INDRA CTI for AiTM kit infrastructure intelligence

    INDRA CTI maintains attribution-grade intelligence on AiTM kit operators: domain registration patterns, hosting providers, TLS fingerprints, and kit-specific signatures. When a phishing URL is flagged in your gateway logs, INDRA CTI tells you which kit family hosted it and which downstream actors typically operate it.

    Use Case: From Login to Lockout in Under Five Minutes

    A mid-size financial firm using Peris.ai sees the following sequence one afternoon.

    • An employee receives a phishing email pointing to a Tycoon 2FA-hosted reverse proxy.
    • The employee enters credentials and approves the MFA push.
    • Microsoft Entra ID logs a successful authentication. The session cookie is issued.
    • Within 1.7 seconds, our XDR observes the same session cookie reused from a source IP previously unseen for this user, with a JA4 TLS fingerprint inconsistent with the user’s known clients.
    • INDRA CTI confirms the source IP is part of an active Tycoon 2FA campaign cluster.
    • BrahmaFusion revokes the session, forces password reset and step-up to a passkey, and opens an IRP case with the full evidence trail.
    • Time from successful proxy login to attacker lockout: under five minutes.

    For comparison, without behavioral session detection and automation, similar campaigns historically reach mailbox access, OAuth consent persistence, and downstream BEC within an hour.

    Outcomes That Matter

    Benefit Outcome
    Session-level behavioral baselines Detects AiTM session theft within seconds
    Automated revocation and step-up Attacker locked out before mailbox or data access
    AiTM kit attribution Faster triage and targeted intelligence sharing
    OAuth grant monitoring Closes the persistence gap after credential rotation
    Phishing-resistant MFA orchestration Step-up to passkeys for high-value identities

    Conclusion

    The defining phishing technique of 2026 is not cleverness. It is commodity. AiTM kits at USD 200 per month make MFA bypass the default initial access path, not an edge case. Security teams that still equate MFA with phishing resistance will keep losing identities they thought were protected. The path forward is autonomous threat detection at the session layer, phishing-resistant authentication for high-value identities, and the agentic AI cybersecurity backbone that ties them together. Peris.ai is built for that operating model.

    Explore the Peris.ai Automation Layer at brahma.peris.ai.

    FAQ

    What is an AiTM phishing kit?

    An adversary-in-the-middle phishing kit is a reverse proxy framework that relays credentials and MFA prompts between a victim and a legitimate provider, capturing the post-authentication session cookie so the attacker can impersonate the user.

    Which AiTM kits are most active in 2026?

    Tycoon 2FA, Rockstar 2FA, EvilProxy, Greatness, and Mamba 2FA are the most observed AiTM kits according to Talos Intelligence 2026 reporting and Microsoft Threat Intelligence.

    Does WebAuthn stop AiTM phishing?

    Yes. WebAuthn and FIDO2 bind the cryptographic challenge to the legitimate origin URL, so a reverse proxy cannot replay the authentication. This is the only widely deployed MFA family that is structurally resistant to AiTM.

    What telemetry detects AiTM session theft?

    Key signals include session cookie reuse from a new source IP within seconds of legitimate login, JA3 or JA4 TLS fingerprint mismatches, and user-agent strings inconsistent with the user’s known clients. Peris.ai XDR baselines and alerts on these.

    How fast can Peris.ai contain an AiTM incident?

    Peris.ai customer deployments contain AiTM session theft in under five minutes, with mean response times improved by an order of magnitude over manual SIEM workflows.

  • 2026 Is the Year AI Stopped Assisting Attackers and Started Leading Them

    2026 Is the Year AI Stopped Assisting Attackers and Started Leading Them

    For years, the cybersecurity industry described AI as a tool that attackers might one day use to accelerate their campaigns. That future arrived in 2026 and it arrived faster and more completely than most threat models anticipated.

    CrowdStrike’s 2026 Global Threat Report documents an 89% year-over-year surge in AI-enabled adversarial activity. New malware families like PROMPTFLUX, PROMPTSTEAL, and PROMPTLOCK don’t just use AI to choose their targets or craft phishing emails. They embed large language models directly into their execution runtime, generating obfuscated exploit code on demand, adapting to the specific environment they’re operating in, and producing new attack variants that have never existed in any threat database before.

    This is the inflection point the industry has been warning about. The question is whether your defense architecture was built for it.

    What Is AI-Powered Cyberattack Capability in 2026?

    AI-powered cyberattacks in 2026 go far beyond automated phishing. The term now describes attacks where AI actively participates in offensive decision-making: selecting targets, generating payloads, adapting to defensive responses, and evading detection in real time. Three tiers of capability are now in active use:

    Tier 1: AI-assisted attacks — Human operators use AI to accelerate specific tasks (phishing content generation, code reuse, target profiling). This was the dominant model in 2024-2025.

    Tier 2: AI-augmented attacks — AI handles entire phases of the attack chain autonomously while humans supervise. Reconnaissance, initial payload generation, and vulnerability matching now run at machine speed.

    Tier 3: Agentic AI attacks — The malware itself contains an AI model that makes operational decisions without human input. PROMPTFLUX, PROMPTSTEAL, and PROMPTLOCK represent this tier. They are not AI-assisted; they are AI-led.

    The Malware Families Rewriting the Rules

    Three newly documented malware families define the 2026 threat landscape:

    PROMPTFLUX generates entirely novel obfuscated code at runtime. Each execution produces unique code that has never existed before, bypassing signature-based and hash-based detection entirely. There is no static indicator of compromise to match against.

    PROMPTSTEAL uses embedded LLM capability to understand the context of the environment it has accessed, identifying high-value credentials, sensitive documents, and communication patterns, and exfiltrates with surgical precision rather than bulk extraction.

    PROMPTLOCK is a ransomware variant that generates unique encryption implementations per target, making decryptor development impractical. It also uses LLM analysis to identify the most operationally damaging files to encrypt first.

    The precursors to these families are already documented: MalTerminal, the earliest known GPT-4-powered malware generating ransomware and reverse-shell code at runtime. LAMEHUG, which uses live LLM interactions to generate system commands on demand rather than using a fixed command set.

    The Speed Advantage Has Shifted

    The 89% increase in AI-enabled attacks is not just a volume story. It’s a speed story. AI can analyze newly published patches the moment they’re released and generate working exploit code in minutes. 61% of new CVEs are now weaponized within 48 hours of disclosure. The time-to-exploit window with AI assistance has compressed to a single day for high-value vulnerabilities.

    Defense teams operating on weekly patching cycles or manual triage workflows are structurally misaligned with this tempo.

    The Defense Paradigm That No Longer Works

    The legacy defense model was built on a core assumption: that known-bad indicators, file hashes, IP addresses, domain names, YARA signatures, could be collected, shared, and used to block attacks before they succeeded.

    This model worked when attackers reused tools, infrastructure, and code across campaigns. It fails when:

    • Each payload is unique and generated on demand
    • C2 infrastructure rotates faster than threat intelligence feeds update
    • Exploitation occurs within hours of vulnerability disclosure
    • The malware itself adapts to the detection environment it encounters

    Signature-based detection, static vulnerability scanning, and human-speed triage are not wrong, they remain necessary, but they are no longer sufficient as the primary defensive layer.

    What Happens When Teams Don’t Adapt

    Legacy Defense Failure Mode Against AI-Led Attacks
    Signature-based AV/EDR PROMPTFLUX generates unique code per execution; no signature exists
    IOC-based threat intel Infrastructure rotates in hours; IOCs expire before distribution
    Manual SOC triage AI attacks exploit and exfiltrate before humans complete first review
    Weekly patch cycles 61% of CVEs weaponized in 48 hours; patch window exceeds exploit window
    Perimeter-only detection Agentic malware operates laterally within trusted zones

    Only Autonomous, Agentic AI Defense Can Match Autonomous, Agentic Offense

    The industry’s response to AI-led attacks cannot be faster humans. It has to be autonomous AI defense: systems that detect, analyze, and respond at machine speed, without waiting for an analyst to click approve.

    This is the core design principle behind BrahmaFusion, Peris.ai’s agentic AI and hyperautomation platform. BrahmaFusion does not wait for a human to review an alert. It ingests telemetry from EDR, XDR, NVM, and external threat intelligence simultaneously, identifies behavioral patterns that indicate AI-generated attack activity, including runtime code generation, anomalous API call sequences, and unusual LLM-style query patterns, and executes containment workflows automatically.

    INDRA CTI provides real-time threat actor attribution and campaign tracking. When a new AI-enabled malware family is documented, INDRA CTI maps its behavioral indicators to your environment’s telemetry and surfaces exposure within minutes, not days.

    Our XDR and EDR provide the multi-layer telemetry that BrahmaFusion’s AI operates on. Behavioral baselines established over time allow anomaly detection that doesn’t depend on known-bad signatures, exactly what’s needed against PROMPTFLUX-style polymorphic payloads.

    A leading financial startup using BrahmaFusion achieved 40% SOC cost savings while simultaneously improving detection coverage. The platform reduced analyst workload by 35% by automating triage, enrichment, and containment for the majority of alerts, freeing human analysts to focus on the cases that genuinely require human judgment.

    Real-World Scenario: Detecting PROMPTFLUX in a Financial Environment

    • T+0:00 — A finance employee opens a phishing PDF; PROMPTFLUX is dropped and begins LLM-based environment analysis
    • T+0:04 — EDR detects anomalous API call sequences inconsistent with any known malware family
    • T+0:05 — BrahmaFusion correlates the API pattern with behavioral indicators from INDRA CTI’s LLM malware taxonomy
    • T+0:07 — The host is automatically isolated; PROMPTFLUX’s exfiltration attempt fails
    • T+0:09 — An IRP case is created with full behavioral trace, MITRE ATT&CK mapping (T1059, T1027), and automated remediation steps
    • T+2:15 — Analyst reviews case, confirms containment, and approves host restoration

    Total analyst involvement: 4 minutes of review. Total attack window: under 10 minutes, zero exfiltration.

    Benefits of Agentic AI Defense Against AI-Led Attacks

    Benefit Outcome
    Behavioral detection independent of signatures Catches PROMPTFLUX-style polymorphic payloads
    Machine-speed automated response Containment executes before human review cycle completes
    INDRA CTI LLM malware tracking New AI malware families mapped to your environment in real time
    BrahmaFusion correlation across all layers No single telemetry source is a detection bottleneck
    40% SOC cost savings Proven in production at financial sector clients
    53% breach impact reduction Across Peris.ai customer base

    Conclusion

    The 89% surge in AI-enabled attacks documented by CrowdStrike in 2026 is not a trend line to monitor. It’s a structural shift in the threat landscape that has already outpaced the legacy defense model’s ability to respond. PROMPTFLUX, PROMPTSTEAL, and PROMPTLOCK are not hypothetical. They are in active deployment against organizations that have not yet updated their defense architecture for the era of autonomous AI offense.

    Peris.ai was built for this moment. BrahmaFusion’s agentic AI, INDRA CTI’s real-time intelligence, and our XDR and EDR telemetry layers are specifically designed to meet autonomous attacks with autonomous defense. Learn more about how Peris.ai protects organizations at machine speed: visit Peris.ai.

    FAQ

    What are AI-powered cyberattacks?

    AI-powered cyberattacks use artificial intelligence to automate or enhance offensive capabilities, including payload generation, target selection, evasion adaptation, and autonomous decision-making during an intrusion. In 2026, the most advanced variants embed LLMs directly into malware execution runtimes.

    What is PROMPTFLUX malware?

    PROMPTFLUX is a malware family that uses an embedded LLM to generate unique, obfuscated exploit code at runtime on every execution. Because each instance is unique, traditional signature-based detection cannot identify it.

    How fast are AI-generated exploits developed?

    With AI assistance, working exploits can be developed within minutes of a patch release. 61% of newly disclosed CVEs are weaponized within 48 hours, and some high-value vulnerabilities are exploited within a single day of public disclosure.

    How does agentic AI defense work?

    Agentic AI defense uses autonomous AI systems to ingest multi-source telemetry, detect behavioral anomalies that indicate attacks, and execute containment workflows automatically, without waiting for human approval. Platforms like BrahmaFusion by Peris.ai operate at machine speed to match the tempo of AI-led attacks.

    What is the difference between AI-assisted and agentic AI attacks?

    AI-assisted attacks use AI to speed up specific human-directed tasks. Agentic AI attacks embed AI into the malware itself, allowing it to make operational decisions autonomously during an intrusion, selecting targets, generating payloads, and adapting to defenses without human input.

  • When Your CFO’s Voice Isn’t Really Your CFO: The $1.1 Billion Deepfake Fraud Wave Hitting Finance

    When Your CFO’s Voice Isn’t Really Your CFO: The $1.1 Billion Deepfake Fraud Wave Hitting Finance

    Deepfake voice fraud drained $1.1 billion from US corporate accounts in 2025. In 2026, the attacks are faster, cheaper, and more convincing than ever. Here is how they work, and what finance and security leaders need to do about it.

    The call sounded exactly like the CFO. The voice, the cadence, even the slight impatience in the tone. The wire transfer instruction was specific, urgent, and entirely plausible. The finance associate on the other end of the call had no reason to question it.

    That call was a fraud. The CFO never made it. A criminal did, using a voice cloned from three seconds of publicly available audio.

    Deepfake CEO fraud, also called vishing executive impersonation, is the fastest-growing financial crime targeting enterprises in 2026. This post explains how it works, what the data says, and how organisations can defend against it before the next fraudulent wire instruction lands in their inbox.

    What Is Deepfake CEO Fraud?

    Deepfake CEO fraud is a form of business email compromise (BEC) evolved to the voice channel. Attackers use AI voice synthesis tools to clone the voice of a senior executive, then use the synthetic voice in real-time phone calls or audio messages to authorise fraudulent wire transfers, request credential resets, or instruct employees to bypass security controls. The attack exploits the inherent trust that employees place in the voices of their leadership.

    The Scale of the Problem: $1.1 Billion and Rising

    The numbers attached to deepfake voice fraud in 2025 and 2026 are not projections. They are documented losses:

    • Deepfake voice attacks drained $1.1 billion from US corporate accounts in 2025, tripling the prior year’s figure of $360 million
    • 243% surge in deepfake voice attacks over the past year
    • Average loss per deepfake vishing case: approximately $600,000
    • 10% or more of financial institutions have suffered deepfake vishing attacks exceeding $1 million per incident
    • Deloitte projects the trajectory of deepfake fraud losses reaching $40 billion in the coming years
    • A Swiss businessman was defrauded of several million Swiss francs via voice cloning in January 2026

    The technology enabling these attacks is not expensive or restricted. A convincing voice clone can now be generated from as little as three seconds of audio. Every earnings call, conference keynote, podcast interview, and media appearance that a finance executive has ever recorded is raw training data for criminals.

    How Attackers Execute a Deepfake Voice Fraud

    Step 1: Target Selection and Audio Harvesting

    Attackers identify a target organisation and select an executive whose voice is publicly available. CFOs, CEOs, and General Counsels are the most common targets because they have authority to authorise financial transactions. Public audio sources include YouTube interviews, investor calls, conference recordings, and podcasts.

    Step 2: Voice Synthesis

    Using commercial or criminal AI voice tools, attackers generate a synthetic voice model capable of producing real-time speech in the target’s voice. Criminal AI toolkits purpose-built for fraud, including tools tracked by INDRA CTI, have removed the technical barriers that previously required specialist knowledge.

    Step 3: The Call

    The attacker calls a finance associate, accounts payable team member, or IT help desk. The synthetic voice delivers an urgent instruction: a wire transfer to a new account, an emergency credential reset, or a request to bypass normal approval workflows due to time pressure. The social engineering is often reinforced by a follow-up email from a spoofed or compromised address.

    Step 4: Covering Tracks

    Once the transfer is made or credentials are compromised, the attacker moves quickly. Funds are often through multiple accounts within hours. By the time the real executive is informed, recovery is typically impossible.

    What Happens When Organisations Are Unprepared?

    Organisations without voice verification protocols and deepfake detection capabilities face several compounding risks:

    • Finance teams have no way to distinguish a legitimate executive call from a synthetic one in real time
    • Standard callback verification can be defeated if the attacker has also compromised the executive’s phone number or email
    • HR teams receive fraudulent payroll diversion requests using the same technique
    • Reputational damage extends beyond the financial loss, particularly for publicly listed companies

    Before vs. After: Deepfake Defence Maturity

    Capability Unprepared Organisation Prepared Organisation
    Voice verification None, relies on caller recognition Multi-factor verbal authentication codes
    Wire transfer approval Single phone authorisation accepted Out-of-band dual approval required
    Executive audio monitoring Not tracked Alerts on new public executive audio
    Incident response for fraud Ad-hoc, no playbook Peris.ai IRP with dedicated BEC/fraud workflow
    Threat intelligence Generic advisories INDRA CTI tracks criminal AI toolkits in real time

    How Peris.ai Protects Against Deepfake Executive Fraud

    INDRA CTI monitors the criminal AI toolkit ecosystem, including voice synthesis tools and the marketplaces where they are sold and leased. When new deepfake voice fraud toolkits targeting finance executives are identified, INDRA CTI surfaces intelligence on their capabilities, infrastructure, and indicators of compromise to your security team before your organisation becomes a target.

    BrahmaFusion, Peris.ai’s agentic AI and hyperautomation platform, can be configured to detect the specific combination of signals that precede a deepfake vishing attack: anomalous wire transfer requests in email chains that reference a phone call as authorisation, executive name mentions combined with financial transaction keywords, and unusual patterns in help desk credential reset requests. When these signals appear together, BrahmaFusion triggers automated review workflows before a transfer is approved.

    Peris.ai IRP provides the incident response framework for organisations that have already been targeted. When a deepfake fraud incident is suspected, Peris.ai IRP opens a structured case with a pre-built workflow covering evidence collection, financial institution notification, regulatory reporting requirements, and post-incident controls review.

    Scenario: The $2.4 Million Phone Call

    A mid-size fintech company receives a call from the CFO’s number at 4:45pm on a Friday. The voice instructs the accounts payable manager to release a $2.4 million payment to a new vendor account before close of business, citing a signed contract that will be emailed shortly.

    Without deepfake defence controls, the transfer is approved.

    With Peris.ai controls in place:

    • BrahmaFusion detects the pattern: Friday afternoon wire request + phone authorisation + new vendor account, and flags it for secondary review
    • INDRA CTI confirms that a criminal voice synthesis toolkit has been actively targeting fintech CFOs in the region that week
    • The finance manager receives an automated alert requiring out-of-band confirmation via the company’s verified internal messaging system
    • The real CFO is contacted. The fraud is stopped. The $2.4 million stays where it belongs.

    Benefits at a Glance

    Benefit Outcome
    INDRA CTI criminal AI monitoring Early warning on deepfake toolkits targeting your sector
    BrahmaFusion pattern detection Automated flag on high-risk transaction request combinations
    Peris.ai IRP fraud workflow Structured response when deepfake incidents occur
    Vendor and partner notification BrahmaFusion playbooks cover third-party fraud scenarios

    Final Thought

    Every earnings call your CFO has ever recorded is a training dataset. Every investor presentation is source material. The voice that your finance team trusts most is now replicable from a few seconds of audio, and the tools to do it are available to criminals on underground markets today.

    The organisations that survive this threat are not those with better voice recognition. They are those with better processes: verification controls, threat intelligence, and incident response capabilities that assume synthetic voices are a real and present risk.

    Platforms like BrahmaFusion by Peris.ai, combined with INDRA CTI’s real-time monitoring of criminal AI toolkits, give lean security teams the intelligence and automation to stop these attacks before the wire goes out. Don’t wait for a breach to take action. Secure your organisation today. Stay Secure with Peris.ai.

    Frequently Asked Questions

    What is deepfake CEO fraud?

    Deepfake CEO fraud is a type of business email compromise attack where criminals use AI voice synthesis to clone an executive’s voice and make fraudulent phone calls authorising wire transfers or credential changes. A convincing voice clone can be created from as little as 3 seconds of publicly available audio.

    How much money has been lost to deepfake voice fraud?

    Deepfake voice attacks drained $1.1 billion from US corporate accounts in 2025, tripling the prior year’s losses. The average loss per deepfake vishing case is approximately $600,000, and over 10% of financial institutions have suffered attacks exceeding $1 million per incident.

    How do attackers clone an executive’s voice?

    Attackers harvest publicly available audio from earnings calls, podcasts, conference recordings, and media interviews. Using commercial or criminal AI voice synthesis tools, they generate a real-time voice model. The process requires minimal technical skill and can be completed in hours.

    What is the best defence against deepfake voice fraud?

    Effective defence combines multi-factor out-of-band verification for financial authorisations, real-time threat intelligence on criminal AI toolkits (such as INDRA CTI), automated detection of anomalous transaction patterns (such as BrahmaFusion), and a prepared incident response workflow for when attacks occur.

    How does BrahmaFusion detect deepfake fraud attempts?

    BrahmaFusion analyses combinations of signals that correlate with deepfake fraud: wire transfer requests referencing phone authorisations, executive name mentions combined with financial transaction keywords, and unusual help desk credential reset patterns. When these signals appear together, it triggers automated secondary approval workflows before transactions are processed.

  • When the Phishing Email Knows Your CFO’s Writing Style: The AI-BEC Threat Banks Cannot Ignore

    When the Phishing Email Knows Your CFO’s Writing Style: The AI-BEC Threat Banks Cannot Ignore

    The tell-tale sign of a phishing email used to be the grammar. Awkward phrasing, misaligned tone, a CFO who suddenly writes like a non-native speaker, these were the signals security awareness training taught employees to catch.

    Those signals are gone.

    Generative AI has closed the stylistic gap between a real executive’s writing and a synthetic impersonation. Today, 40% of business email compromise (BEC) phishing emails are AI-generated, producing personalized, contextually accurate messages that match the target executive’s known vocabulary, communication cadence, and organizational context. The click-through rate on AI-crafted lures is 450% higher than on traditional phishing emails. And the financial sector is the primary target.

    For CISOs at banks, insurers, and fintech firms, this is not an incremental escalation of a known threat. It is a qualitative change in what BEC actually is.

    What Is AI-Powered Business Email Compromise?

    Business email compromise (BEC) is a class of fraud where attackers impersonate executives, vendors, or business partners to manipulate employees into transferring funds, divulging credentials, or executing unauthorized transactions. Traditional BEC relied on social engineering and domain spoofing. AI-powered BEC adds stylometric matching, voice cloning, real-time context harvesting from LinkedIn and corporate websites, and automated multi-channel targeting.

    The FBI IC3 reported that BEC caused more than $2.7 billion in adjusted losses in 2024 and accounts for 73% of all reported cyber incidents.

    How the AI-BEC Threat Has Evolved in 2026

    Adversary-in-the-Middle (AiTM) Phishing

    In January 2026, Microsoft documented a multi-stage AiTM phishing and BEC campaign targeting the energy sector via SharePoint. Rather than simply spoofing an email, the attacker positioned themselves between the victim and a legitimate Microsoft authentication flow, intercepting session tokens in real time.

    Dual-Channel BEC Attacks

    The dominant 2026 BEC pattern is the dual-channel attack: simultaneous multi-vector contact where the target receives a spoofed email from an “executive” and a concurrent phone call or SMS confirming the request. The second channel creates urgency and authenticity reinforcement that significantly increases compliance rates.

    Callback Phishing

    Callback phishing, where a phishing email instructs the target to call a fraudulent number staffed by social engineers posing as IT or finance support, more than doubled in popularity in 2025 and continues accelerating into 2026.

    What Happens When Financial Security Teams Don’t Address This

    According to 2026 threat intelligence, 59% of financial services organizations hit by ransomware had their data successfully encrypted. The median ransom demand in financial services reached $3 million.

    The Financial Sector’s Structural Vulnerability

    Attack Vector Why Financial Sector Is Exposed
    Executive impersonation Finance employees are trained to prioritize urgent requests from leadership
    Vendor impersonation High transaction volumes create normalcy for wire transfer requests
    AiTM MFA bypass Widespread MFA adoption has driven attackers to session hijacking rather than credential theft
    AI style matching Executives’ communication styles are well-documented through public statements and filings
    Dual-channel attacks Second communication channel creates false authentication signal

    How Peris.ai Defends Financial Institutions Against AI-BEC

    BrahmaFusion: Behavioral Analytics and Anomalous Communication Detection

    BrahmaFusion, Peris.ai’s agentic AI and hyperautomation platform, applies behavioral analytics to communication patterns across email, endpoint, and identity systems. While content filtering can be defeated by stylistically accurate AI-generated text, behavioral analytics focuses on what is unusual about how and when a communication occurs: an executive sending a wire transfer request from an unusual IP, at an unusual hour, to a new payee, without the corresponding approval workflow.

    A FeedLoop customer using BrahmaFusion’s automation reported a 70% reduction in response time for anomalous communication incidents.

    INDRA CTI: Tracking BEC Campaigns Targeting Financial Institutions

    INDRA CTI provides real-time intelligence on threat actor campaigns, including BEC operations targeting specific industries and geographies. When a threat actor group begins targeting the Indonesian banking sector with AiTM infrastructure, INDRA CTI surfaces the relevant indicators before the first targeted email reaches your inbox.

    Use Case: Catching an AI-BEC Attack Before the Wire Transfers

    A regional bank’s CFO receives what appears to be an email from the CEO requesting an urgent $4.2M wire transfer to a new overseas account for a confidential acquisition. The email matches the CEO’s known writing style precisely.

    BrahmaFusion flags the transaction request before it reaches the wire desk:

    • The email originated from an AiTM proxy domain registered 48 hours earlier (INDRA CTI IOC match)
    • The CEO’s actual session shows no corresponding activity in the corporate email system around the email’s timestamp
    • The payee account has no prior relationship in the organization’s transaction history
    • The request bypassed the standard dual-approval workflow required for transfers above $1M

    The BrahmaFusion playbook pauses the request, alerts the SOC and compliance team, and generates a case in Peris.ai IRP with full evidence chain. The attack is neutralized without reaching the wire desk.

    Benefits at a Glance

    Benefit Outcome
    BrahmaFusion behavioral analytics Detects AI-BEC even when content bypasses stylistic filters
    Automated workflow tripwires Wire transfer anomalies caught before human approval stage
    INDRA CTI campaign tracking Known BEC infrastructure blocked before first email lands
    IRP evidence chain Full forensic record for regulatory and legal response
    70% faster response (BrahmaFusion) Rapid containment reduces exposure window for AiTM session hijacks

    The Authentication Stack Is No Longer Sufficient on Its Own

    MFA was the correct response to credential theft. AiTM attacks are the response to MFA. The adversarial cycle does not stop at the authentication layer, and financial institutions that treat identity security as the final defense will be repeatedly outmaneuvered.

    Behavioral analytics, real-time threat intelligence, and automated anomaly response are the layers that catch what authentication cannot. Peris.ai was built to operate at this level, with BrahmaFusion providing the intelligence-driven automation that financial security teams need to stay ahead of AI-powered fraud.

    Visit peris.ai to see how Peris.ai’s agentic AI platform protects financial institutions from the next generation of BEC attacks.

    Frequently Asked Questions

    What is AI-powered BEC?

    AI-powered business email compromise uses generative AI to create hyper-personalized, stylistically accurate executive impersonation emails, increasing click-through rates by up to 450% versus traditional phishing.

    How does adversary-in-the-middle (AiTM) phishing bypass MFA?

    AiTM phishing intercepts a user’s live authentication session, capturing the session token after the user completes genuine MFA. The attacker uses the captured token to authenticate as the user without ever needing the password or MFA code.

    What are the signs of a dual-channel BEC attack?

    An unsolicited request arriving simultaneously via email and phone or SMS, with urgency framing and a request that bypasses normal approval processes, is a strong indicator of a dual-channel BEC operation.

    How much do BEC attacks cost financial organizations?

    The FBI IC3 reported $2.7B+ in BEC-adjusted losses in 2024. The median ransom demand in financial services reached $3 million in 2026.

    How does behavioral analytics catch AI-generated BEC emails?

    Behavioral analytics focuses on communication context, not content: unusual timing, new payees, bypassed workflows, mismatched session activity, and infrastructure anomalies that AI-generated text cannot replicate.

  • Foxconn Was Just the Beginning: How Nitrogen Ransomware Is Putting Manufacturers in Its Crosshairs

    Foxconn Was Just the Beginning: How Nitrogen Ransomware Is Putting Manufacturers in Its Crosshairs

    On May 11, 2026, the Nitrogen ransomware group listed Foxconn on its public leak site, claiming exfiltration of approximately 8TB of data spanning more than 11 million files. Foxconn confirmed disruption to North American operations the following day. Here is why manufacturers are the next major ransomware battleground.

    Foxconn is not a small target. It is one of the largest electronics manufacturers on the planet, a supplier to Apple, Microsoft, and Sony, operating factories on multiple continents. If Nitrogen ransomware can penetrate Foxconn’s North American operations and walk out with 8TB of sensitive data, no manufacturer should consider itself safe.

    This post examines how Nitrogen operates, why the manufacturing sector has become a primary target, and what security architecture prevents an EDR killer from disabling your defences before the encryption begins.

    What Is Nitrogen Ransomware?

    Nitrogen ransomware is a ransomware-as-a-service (RaaS) operation that gained significant attention in 2026 for its targeting of large manufacturing, industrial, and logistics organisations. The group maintains a public leak site, NitroBlog, where it lists confirmed victims and publishes exfiltrated data to pressure ransom payment.

    Nitrogen’s defining technical characteristic is its use of EDR killers as a standard pre-attack preparation step. EDR killers are tools specifically designed to disable, crash, or evade endpoint detection and response software before the ransomware payload is deployed. Their inclusion in Nitrogen’s standard attack playbook reflects a sector-wide trend: Kaspersky’s 2026 International Anti-Ransomware Day report confirmed that EDR killers are now standard components of ransomware attack chains across the industry.

    How Nitrogen Gets In: The Malvertising Initial Access Vector

    Nitrogen does not rely on zero-day exploits for initial access. Its approach is more insidious: malvertising campaigns that deliver trojanized installers of legitimate, trusted software.

    The tools commonly used as lures include:

    • WinSCP (popular Windows file transfer tool)
    • AnyDesk (remote desktop software widely used in manufacturing IT)
    • Advanced IP Scanner (network administration tool)
    • PuTTY (SSH client used by IT and OT teams)

    An IT technician searching for a free download of WinSCP may land on a malvertised page serving a trojanized installer that looks identical to the legitimate version. The installer runs, the legitimate software installs correctly, and in the background Nitrogen’s initial access malware establishes persistence. The technician sees nothing unusual.

    The Foxconn Attack: Timeline and Impact

    • May 11, 2026: Nitrogen lists Foxconn on NitroBlog, claiming exfiltration of 8TB of data across more than 11 million files
    • May 12, 2026: Foxconn publicly confirms disruption to North American operations, affecting facilities in Wisconsin and Texas
    • Scope of data claimed: manufacturing specifications, supplier contracts, employee records, and operational data

    The attack follows a pattern that Nitrogen has repeated across multiple manufacturing sector targets in 2026. The group increasingly favours encryptionless extortion, exfiltrating data and threatening to publish it rather than encrypting systems and demanding a decryption key.

    Why Is Manufacturing a Ransomware Target?

    Operational Technology Exposure

    Modern manufacturing environments blend IT systems with OT (operational technology): industrial control systems, SCADA platforms, programmable logic controllers, and connected assembly-line equipment. These OT systems are often decades old, running software that cannot be updated without re-certifying the manufacturing process.

    High Operational Cost of Downtime

    A ransomware-induced shutdown of a manufacturing line costs thousands to tens of thousands of dollars per hour in lost production.

    Interconnected Supply Chains

    A breach at Foxconn has downstream implications for every organisation in its supply chain.

    What Happens When EDR Is the First Casualty?

    Nitrogen’s EDR killer deployment is specifically designed to neutralise your primary detection capability before the attack proceeds. When EDR is disabled:

    • Endpoint behavioural detection goes dark
    • The ransomware payload deploys without triggering the controls that should stop it
    • Security teams receive no alerts until encryption is already underway
    • Recovery scope expands dramatically because the attack was uncontained

    Nitrogen Attack vs. Defended Environment

    Attack Stage Undefended Environment Peris.ai-Defended Environment
    Malvertised installer download No detection BimaRed surfaces malvertising domain
    EDR killer execution EDR disabled, blind spot created XDR network layer continues detecting
    Lateral movement Undetected across OT/IT boundary NVM packet analysis detects anomalous traversal
    Data exfiltration 8TB exits unnoticed XDR triggers BrahmaFusion isolation playbook
    Ransomware payload Encryption proceeds Automated containment limits blast radius

    How Peris.ai Defends Manufacturing Environments

    Our EDR provides behavioural detection on industrial endpoints and IT workstations. Critically, Peris.ai’s EDR is designed to resist EDR killer techniques through tamper-protection mechanisms.

    Our XDR extends detection to the full manufacturing environment, including OT network segments. In a factory where industrial control systems share network infrastructure with corporate IT, XDR correlates telemetry across both layers.

    Our NVM (Network Visibility Monitor) provides packet-level analysis of all traffic traversing the factory network. Nitrogen’s data exfiltration, typically multi-gigabyte transfers to external infrastructure, generates distinctive network traffic patterns that NVM detects and flags regardless of endpoint agent status.

    BimaRed monitors the attack surfaces that Nitrogen exploits for initial access: internet-facing management interfaces, exposed OT systems, and vulnerabilities in IT administration tools.

    BrahmaFusion ties the detection layers together with automated response playbooks. When XDR or NVM surfaces Nitrogen indicators, BrahmaFusion triggers network segmentation rules that isolate affected systems from OT infrastructure before encryption can spread to production lines.

    Benefits at a Glance

    Benefit Outcome
    EDR with tamper protection EDR killer techniques detected and resisted
    XDR cross-layer visibility OT/IT boundary lateral movement detected
    NVM packet-level analysis Large data exfiltration detected before completion
    BimaRed attack surface monitoring Malvertising domains and exposed assets surfaced early
    BrahmaFusion automated segmentation OT environments isolated before encryption spreads

    Final Thought

    Nitrogen ransomware listed Foxconn on May 11, 2026. The group will list its next target soon. For manufacturing security teams, the question is not whether their sector is being targeted. It is whether their detection architecture will survive an EDR killer long enough to contain the attack.

    Platforms like BrahmaFusion by Peris.ai, combined with XDR, NVM, and INDRA CTI threat intelligence, give manufacturing security teams the layered, agent-independent detection and automated response capability they need to stop Nitrogen and groups like it before the production line goes dark.

    Frequently Asked Questions

    What is Nitrogen ransomware?

    Nitrogen is a ransomware-as-a-service operation that targets manufacturing, industrial, and logistics organisations. The group uses malvertising campaigns to deliver trojanized installers of legitimate tools, deploys EDR killers to disable endpoint detection, and increasingly uses encryptionless extortion by threatening to publish stolen data.

    How did Nitrogen ransomware attack Foxconn?

    On May 11, 2026, Nitrogen listed Foxconn on its leak site claiming 8TB of exfiltrated data across 11 million or more files. Foxconn confirmed disruption to North American operations including facilities in Wisconsin and Texas on May 12, 2026.

    What is an EDR killer and how does it work?

    An EDR killer is a tool designed to disable, crash, or evade endpoint detection and response software before a ransomware payload deploys. By neutralising the primary detection control, attackers create a window where encryption or exfiltration proceeds without triggering alerts.

    Why does Nitrogen use malvertising as an initial access vector?

    Nitrogen uses malvertised downloads of legitimate IT tools (WinSCP, AnyDesk, Advanced IP Scanner, PuTTY) because these tools are trusted and regularly downloaded by IT and OT teams in manufacturing environments.

    How can manufacturers defend against EDR killer attacks?

    Effective defence requires layered detection that operates independently of endpoint agents. This includes network-level visibility (NVM), cross-layer XDR that monitors OT/IT boundaries, EDR with tamper-protection capabilities, and automated isolation playbooks.

  • When the Scalpel Goes Offline: The Stryker Cyberattack and Why Medical Device Security Is Now Critical Care

    When the Scalpel Goes Offline: The Stryker Cyberattack and Why Medical Device Security Is Now Critical Care

    Meta Lede: Stryker was cyberattacked in March 2026. 22% of hospitals have had attacks impact medical devices directly. IoMT security is now a patient safety issue.

    On March 11, 2026, Stryker, one of the world’s largest medical technology companies supplying surgical equipment and devices to hospitals across the globe, was disrupted by a cyberattack affecting operations worldwide.

    This was not a data breach. Stryker’s attack disrupted the operational continuity of a company whose devices are used in operating rooms, ICUs, and emergency departments every hour of every day. And Stryker is not an isolated case. By 2026, 22% of healthcare organizations have experienced cyberattacks that directly impacted medical devices, and 75% of those incidents disrupted patient care. In 24% of medical device attack cases, patients required transfer to other facilities.

    Former FBI officials have proposed terrorist designations for ransomware hackers targeting hospitals, reflecting the recognized severity: when medical devices go offline, patients can die. The Internet of Medical Things (IoMT) is no longer just an IT problem. It is a critical care problem.

    What Is IoMT Security and Why Is It Different from Standard Healthcare IT Security?

    IoMT (Internet of Medical Things) security refers to the protection of network-connected medical devices: infusion pumps, patient monitors, imaging systems, surgical robots, ventilators, diagnostic equipment, and the thousands of other connected devices deployed across modern hospital environments.

    IoMT security differs fundamentally from standard healthcare IT security in three ways:

    • Devices cannot be patched on a normal cycle. Medical device firmware updates require FDA clearance or CE marking in most jurisdictions. A vulnerability disclosed today may not have a patch available for 12 to 18 months.
    • Agents cannot be installed. Most medical devices run proprietary operating systems that cannot accept security agent software. Standard EDR deployment is impossible.
    • Device failure directly harms patients. Unlike an email server outage, a compromised ventilator or infusion pump creates an immediate clinical risk.

    By 2026, smart hospitals deploy more than 7 million IoMT devices globally, double the level from 2021.

    What the Stryker Attack Reveals About Medical Technology Vulnerability

    The March 11, 2026 attack on Stryker demonstrates that the vulnerability extends beyond individual hospital networks to the medical technology supply chain. A cyberattack that disrupts Stryker’s operations can simultaneously affect:

    • Supply chain continuity for hospital procurement teams
    • Software update distribution for connected Stryker devices already deployed in hospitals
    • Remote monitoring and diagnostics capabilities for equipment under service contracts
    • Customer support and technical assistance for clinical staff

    The Scale of the IoMT Security Crisis in 2026

    By the Numbers

    • 7 million+ IoMT devices deployed in smart hospitals globally (double 2021 levels)
    • 22% of healthcare organizations experienced cyberattacks directly impacting medical devices
    • 75% of medical device attacks disrupted patient care
    • 24% of medical device attacks required patient transfers to other facilities
    • $10.9 million average cost of a hospital ransomware attack (downtime, recovery, regulatory fines)
    • 276 million health records breached in 2024 alone

    How Peris.ai Addresses IoMT Cybersecurity

    Agentless Medical Device Monitoring with NVM

    Because agents cannot be installed on medical devices, the detection layer must be network-based. Peris.ai’s NVM (Network Visibility Monitor) performs passive packet-level inspection of medical device network traffic without requiring any software installation on the devices themselves and without causing any device operational impact.

    NVM establishes behavioral baselines for each device type: the normal communication patterns of an infusion pump differ from those of a patient monitor. Deviations from baseline, including unexpected outbound connections, unusual authentication attempts, and command-and-control traffic patterns, trigger alerts without disrupting device function.

    Cross-Network Threat Detection with XDR

    Peris.ai’s XDR platform correlates signals from NVM (medical device network), EDR (clinical IT endpoints), and cloud environments into a unified detection view.

    Automated Clinical Isolation with BrahmaFusion

    BrahmaFusion, Peris.ai’s agentic AI and hyperautomation platform, enables automated response playbooks specifically designed to isolate compromised devices without disrupting clinical workflows. When NVM detects anomalous communication from a medical device, a BrahmaFusion playbook can:

    • Isolate the affected device’s network access at the switch level without powering down the device
    • Alert clinical biomedical engineering and the security team simultaneously
    • Trigger a structured incident response workflow via Peris.ai IRP
    • Preserve all network traffic captures for forensic investigation

    Healthcare-Specific Threat Intelligence with INDRA CTI

    INDRA CTI provides healthcare sector-specific threat intelligence: ransomware group tactics targeting medical devices, active campaign IOCs for healthcare-focused threat actors, and vulnerability intelligence for common medical device platforms and operating systems.

    Real-World Scenario: A Ransomware Attack on Hospital IoMT

    A regional hospital system with 2,400 connected medical devices across three facilities:

    • An attacker gains initial access through a phishing email to a hospital IT administrator
    • They move laterally through the hospital IT network to reach the medical device VLAN, which lacks proper segmentation
    • An infusion pump with a known unpatched CVE is exploited as a pivot point into the medical device network
    • Ransomware is deployed targeting the device management server and clinical data systems simultaneously
    • 40 infusion pumps require manual operation; two ICU patients require transfer to another facility
    • Total incident cost: $12.4 million over 8 weeks of recovery

    With Peris.ai: NVM detects the lateral movement into the medical device VLAN. BrahmaFusion isolates the compromised VLAN segment while preserving device function. The infusion pump CVE exploitation is flagged before pivot occurs. INDRA CTI confirms the attacker’s infrastructure matches a known ransomware group’s healthcare campaign.

    Healthcare IoMT Security Priorities

    Priority Action Peris.ai Capability
    1 Deploy agentless network monitoring for all IoMT NVM passive packet inspection
    2 Segment medical device network from general IT NVM-identified boundary enforcement via BrahmaFusion
    3 Inventory all IoMT devices with firmware versions BimaRed asset discovery
    4 Monitor for healthcare-specific threat actor activity INDRA CTI
    5 Test network pivot paths into medical device VLANs Pandava penetration testing

    Conclusion

    The Stryker cyberattack and the data from 2026 make one thing clear: IoMT security is no longer a future concern. With 22% of healthcare organizations already experiencing attacks that directly impact medical devices and 24% of those incidents forcing patient transfers, the question is not whether your hospital will face an IoMT security incident, but whether you will detect it before it reaches patients.

    Peris.ai’s healthcare security stack, built around agentless NVM monitoring, cross-network XDR detection, and clinically aware BrahmaFusion automated response, provides the coverage that standard IT security tools cannot deliver in medical device environments.

    Don’t wait for a breach to take action. Secure your organization today. Stay Secure with Peris.ai.

    Frequently Asked Questions

    What is IoMT cybersecurity?

    IoMT (Internet of Medical Things) cybersecurity refers to the protection of network-connected medical devices including infusion pumps, patient monitors, imaging systems, surgical equipment, and diagnostic devices against cyberattacks that could disrupt clinical operations or compromise patient safety.

    What happened in the Stryker cyberattack in 2026?

    On March 11, 2026, Stryker, one of the world’s largest medical technology companies, was disrupted by a cyberattack affecting its global operations, including supply chain, software update distribution, and technical support capabilities for its connected medical devices.

    Why are medical devices difficult to secure against cyberattacks?

    Medical devices are difficult to secure because they typically run proprietary operating systems that cannot accept security agents, require regulatory approval for firmware updates creating long patch cycles, and cannot be taken offline without clinical risk to patients.

    How common are cyberattacks on medical devices?

    As of 2026, 22% of healthcare organizations have experienced cyberattacks that directly impacted medical devices. Of those, 75% disrupted patient care and 24% required patient transfers to other facilities.

    What is the best way to monitor medical device security without disrupting clinical operations?

    Passive, agentless network monitoring (such as NVM) is the recommended approach. It inspects medical device network traffic at the packet level without installing any software on devices and without causing any operational impact.