Draft:Unit 42
Submission declined on 21 September 2026 by Helpful Raccoon (talk). This draft's references do not show that the subject meets Wikipedia's criteria for inclusion for organizations and companies. The draft requires multiple published secondary sources that:
Where to get help
How to improve a draft
You can also browse Wikipedia:Featured articles and Wikipedia:Good articles to find examples of Wikipedia's best writing on topics similar to your proposed article. Improving your odds of a speedy review To improve your odds of a faster review, tag your draft with relevant WikiProject tags using the button below. This will let reviewers know a new draft has been submitted in their area of interest. For instance, if you wrote about a female astronomer, you would want to add the Biography, Astronomy, and Women scientists tags. Editor resources
|
Comment: Sources that just summarize/repeat their research are not significant coverage about the organization itself. Helpful Raccoon (talk) 02:00, 21 September 2026 (UTC)
Comment: In accordance with the Wikimedia Foundation's Terms of Use, I disclose that I have been paid by my employer for my contributions to this article. ThePlay82 (talk) 16:29, 17 September 2026 (UTC)
Unit 42 is the threat intelligence and incident response organization of Palo Alto Networks, an American cybersecurity company. The organization conducts research into cyberespionage, malware, ransomware and software vulnerabilities and provides incident-response services.
History and organization
[edit]Unit 42 originated as Palo Alto Networks' threat intelligence research team. Its activities subsequently expanded to include incident response and security consulting.
The organization has been cited in independent reporting concerning cyberespionage campaigns, malware, vulnerability exploitation and major cybersecurity incidents.
Cybersecurity research
[edit]Unit 42 conducts research into state-sponsored cyberespionage, malware and other cyber threats.
In February 2026, Recorded Future News reported on a Unit 42 investigation into a cyberespionage campaign that had compromised institutions in 37 governments. Unit 42 said it had tracked compromises of at least 70 institutions and reconnaissance activity affecting organizations in 155 countries.[1]
Reuters subsequently reported that Unit 42 researchers had initially connected the campaign to China but that Palo Alto Networks chose not to directly attribute the activity to China in the published report. Reuters reported that the decision reflected concerns about potential retaliation by Beijing and risks to company personnel and customers in China.[2]
In 2024, TechTarget reported on Unit 42 research documenting an increase in malware-initiated vulnerability scanning. The research described attackers compromising systems and then using those systems to scan other networks for vulnerabilities, allowing attackers to obscure the origin of scanning activity.[3]
Incident response
[edit]In addition to threat research, Unit 42 performs incident-response work for organizations affected by cyberattacks. Its incident responders and researchers have participated in investigations of ransomware, data theft, network intrusions and other cybersecurity incidents.
References
[edit]- ↑ Greig, Jonathan; Matishak, Martin (February 5, 2026). "Researchers uncover vast cyberespionage operation targeting dozens of governments worldwide". Recorded Future News. Retrieved September 16, 2026.
- ↑ "Palo Alto chose not to tie China to hacking campaign for fear of retaliation from Beijing, sources say". Reuters. February 12, 2026. Retrieved September 16, 2026.
- ↑ Culafi, Alexander (April 9, 2024). "Unit 42: Malware-initiated scanning attacks on the rise". TechTarget. Retrieved September 16, 2026.

LLM-generated pages with certain obvious signs of being machine generated may be deleted without notice.
Instead, only summarize in your own words a range of independent, reliable, published sources that discuss the subject.
See the advice page on large language models for more information.