Just released: The 2026 Global Threat Report is now available.Download report
Enterprise AI, cybersecurity, cloud and software for organizations worldwide.
2026 Edition

The 2026 Global Threat Report

A definitive look at the cyber threat landscape — the adversaries, tradecraft and inflection points shaping enterprise risk in the year ahead.

27 secfastest recorded eCrime breakout time
89%increase in attacks by AI-enabled adversaries
82%of detections in 2025 were malware-free
27 sec
fastest recorded eCrime breakout time
89%
increase in attacks by AI-enabled adversaries
82%
of detections in 2025 were malware-free
281
tracked adversaries across the globe
What's inside

A definitive look at the cyber threat landscape.

Distilled from front-line intelligence, incident response engagements and telemetry across cloud, endpoint and identity — the report equips leaders with a clear read on adversary priorities and defender imperatives.

The rise of AI-enabled adversaries

Generative AI has collapsed the cost of social engineering and malware iteration. Voice-cloned vishing, deepfake executive impersonation and LLM-generated phishing kits are now standard tradecraft.

Cloud is the new battleground

Cloud-conscious intrusions surged as attackers pivot from endpoints to identity providers, SaaS control planes and misconfigured cloud workloads to reach crown-jewel data.

Identity is the primary attack surface

Valid account abuse, MFA fatigue and session-token theft outpaced traditional malware. Defenders must treat identity as tier-zero infrastructure.

Breakout times keep collapsing

The window between initial access and lateral movement is now measured in seconds. Detection, investigation and response must be automated to keep pace.

Inside the report

Six chapters. One clear view of the adversary.

CHAPTER 01

Threat Landscape Overview

The macro picture: adversary counts, attack velocity and the shifting economics of intrusion.

Read chapter
CHAPTER 02

AI & the Adversary

How generative models are weaponized across reconnaissance, initial access and post-exploitation.

Read chapter
CHAPTER 03

Cloud & Identity Intrusions

Attack paths through IdPs, SaaS control planes and cloud workloads — and how to close them.

Read chapter
CHAPTER 04

eCrime Ecosystem

Access brokers, RaaS operators and data-extortion crews reshaping the criminal supply chain.

Read chapter
CHAPTER 05

State-Nexus Operations

Espionage, disruptive and influence campaigns from named adversary groups worldwide.

Read chapter
CHAPTER 06

Recommendations for Defenders

Prioritized controls, telemetry and operating-model changes that meaningfully reduce risk.

Read chapter
Adversary universe

281 tracked adversaries. A shared naming convention for a fragmented threat.

Our intelligence team catalogs adversaries with animal designators tied to region and motivation — turning noisy indicators into a clear narrative.

State-nexus
BEAR
Russia
State-nexus
PANDA
China
State-nexus
CHOLLIMA
DPRK
State-nexus
KITTEN
Iran
eCrime
SPIDER
Global
Activist
JACKAL
Hacktivist
eCrime
OCELOT
Colombia
State-nexus
BUFFALO
Vietnam
Key findings

The four shifts defining 2026.

Attackers moved faster, quieter and more automated than at any point on record. These are the shifts every security program must plan against.

Malware-free intrusions dominate
82% of detections relied on valid accounts, living-off-the-land binaries and legitimate remote tooling.
Breakout time under 30 seconds
The fastest observed hands-on-keyboard pivot compressed from minutes to a single half-minute.
AI-augmented tradecraft up 89%
Generative models power reconnaissance, lure creation and code generation at scale.
Cross-border operations expand
State-nexus and eCrime crews increasingly collaborate through shared access markets.
For defenders

What to do about it — this quarter.

A short list of moves that meaningfully reduce risk against the tradecraft observed in the report. Prioritize, sequence, and measure.

  • Assume identity compromise — enforce phishing-resistant MFA everywhere.
  • Invest in cloud detection and response with runtime visibility, not just posture.
  • Consolidate telemetry; measure and shrink mean-time-to-respond.
  • Rehearse against AI-enabled social engineering across executives and help desks.
  • Treat third-party and SaaS integrations as extensions of your attack surface.

Get the full 2026 Global Threat Report.

80+ pages of adversary intelligence, incident data and defender playbooks — delivered instantly to your inbox.

By submitting, you agree to receive occasional intelligence briefings. Unsubscribe anytime.