Threat landscape summaries have a tendency toward drama. The honest assessment for 2026 is that the techniques have not changed dramatically. What changed is the economics, and that has consequences for who gets targeted and how often.
Identity Is the Front Door
The majority of intrusions now begin with valid credentials rather than an exploit. That has been directionally true for several years and is now decisively so.
The reasoning is straightforward from an attacker's perspective. Exploiting a vulnerability requires finding one, weaponizing it and evading detection built specifically to catch that behavior. Logging in with a valid credential requires none of that and produces authentication events indistinguishable from legitimate ones.
The supply of credentials is effectively unlimited. Information-stealing malware harvests them from consumer devices at scale, breach corpora accumulate, and password reuse means a credential leaked from an unrelated service frequently works elsewhere.
What matters most in response is the strength of the authentication method rather than its presence. Adversary-in-the-middle phishing defeats every MFA method that produces a code or an approval the user can be induced to provide, which is most of them. Only phishing-resistant methods hold, which is why moving privileged accounts and remote access to hardware keys and passkeys is the highest-value control most organizations can deploy this year. We have covered the mechanics in identity attacks and why MFA is not enough.
Extortion Without Encryption
Ransomware crews increasingly skip the ransomware.
The logic follows the defense. Organizations invested in backups, and many can now restore. Encryption stopped being reliable leverage, while stolen data remained leverage regardless of how good the backups are. Data theft is also faster, quieter and carries less operational risk for the attacker than deploying encryption across an estate.
The practical consequence is that measuring ransomware readiness by recovery capability is now incomplete. Recovery answers the encryption question and does nothing about publication of stolen data. Detecting exfiltration, and limiting what a compromised account can reach in the first place, matters more than it did.
Third Parties Are the Route
A substantial and growing share of incidents arrive through someone else: a software vendor, a managed service provider, a contractor with network access, an open-source dependency.
This is a rational attacker choice rather than a trend. Compromising one managed service provider yields access to every client it administers. Compromising one widely used software package yields access to everyone who installs the update. The return on effort is far better than attacking targets individually.
For defenders, the uncomfortable part is that most third-party risk programs measure the wrong thing. A completed questionnaire tells you what a vendor says about their controls. What you need to know is what that vendor could reach inside your environment if they were compromised tomorrow, which is a reachability question your own architecture answers, not theirs.
Critical Infrastructure Under Sustained Pressure
Operational technology environments across energy, water, manufacturing, transport and healthcare face both financially motivated crews and state-aligned actors, and CISA has issued repeated advisories about intrusions into these environments.
The recurring finding in our own assessments is not sophisticated attacks against control systems. It is that the boundary between corporate IT and operational technology is far more permeable than operators believe, because connectivity accumulates for good reasons and nobody reassesses the total. We have written up a representative example in the air gap that was not.
What AI Actually Changed
Less than the marketing suggests and more than skeptics allow.
The clearest effect is on social engineering. Phishing messages no longer carry the language errors that were, for two decades, the most reliable signal available to an ordinary employee. Awareness training built on spotting bad grammar is obsolete, and voice impersonation has become inexpensive enough that a phone call from a familiar-sounding executive is no longer weak evidence of anything.
The second effect is on reconnaissance economics. Researching a target properly used to require analyst time, which restricted careful targeting to victims worth the effort. That constraint has largely gone, which is a substantial part of why mid-market organizations report more targeted-looking attacks.
What has not appeared, despite persistent claims, is genuinely autonomous attack capability. The realistic assessment is that AI made competent attacks cheaper to produce at volume.
What This Means for Priorities
If the landscape above is accurate, the implications for a constrained budget are fairly specific.
Phishing-resistant MFA on remote access and all privileged accounts, ahead of almost anything else.
Know what you expose. Forgotten internet-facing assets remain over-represented in real incidents, and continuous discovery finds them.
Reduce blast radius. Tiered administration, segmentation and removing standing privilege determine whether one compromised account is an incident or a catastrophe. This is unglamorous and it is what actually limits damage.
Detect internally. Perimeter detection is generally the best-developed part of a monitoring program and the least relevant to an attacker who logged in.
Assess third parties by reachability, not by questionnaire score.
None of these are new. That is rather the point: the landscape shifted toward attacks that basic controls address, and the organizations having a bad year are largely those who invested in tooling that assumes the perimeter is where the fight happens.
To discuss what this means for your environment, get in touch.
Frequently asked questions
What is the biggest change in the threat landscape this year?
The continued shift toward identity as the primary intrusion route, and the commoditization that put credible attacks within reach of far more actors. Most intrusions we investigate begin with valid credentials rather than an exploit, which changes where defensive effort should go: away from perimeter hardening alone and toward identity controls, session security and internal detection.
Are small and mid-sized organizations really targeted?
Directly less often, indirectly very often. A large share of intrusions begin with access obtained opportunistically by a broker who did not know or care who the victim was, then sold to whoever wanted it. Sector and supply chain position matter more than headcount, and organizations supplying defense, healthcare, energy or financial services inherit their customers' threat profile.
Is ransomware declining?
Encryption is becoming less universal while extortion is not. A growing proportion of incidents involve data theft and extortion without any encryption, because it is faster, quieter and defeats the backup investments organizations made. Judging your exposure by whether you can restore from backup is now an incomplete measure.
What role is AI actually playing in attacks?
Mostly in making competent attacks cheaper at scale rather than creating new attack types. The clearest effect is on social engineering quality, where generated messages no longer carry the language errors that were a reliable signal, and increasingly on voice, where convincing impersonation is now inexpensive. Claims of autonomous AI attacks remain largely marketing.
Where should a limited security budget go first?
Phishing-resistant multifactor authentication on remote access and privileged accounts, knowing what you expose to the internet, and reducing what a single compromised account can reach. Those three address the routes that produce the large majority of real incidents, and they cost less than most organizations spend on tooling that assumes the perimeter holds.
