If you want the short version of 2026: the thing most likely to breach you is an unpatched internet-facing appliance, a stolen session token, or a supplier you never audited — not a quantum computer. Verizon's 2026 Data Breach Investigations Report, the 19th edition, found that exploitation of vulnerabilities became the single most common way into a breach for the first time in the report's history, at 31%, while abuse of stolen credentials as an initial vector dropped to 13%.
This piece replaces an earlier post on this site. That post was a roughly 80-word list — "AI-powered attacks, quantum threats, deepfake social engineering" — with no incident data, no report cited, and no numbers. It was not researched, and its framing was wrong in a way worth naming: it put quantum computing alongside ransomware as if both were things happening to organisations right now. They are not in the same category. AI-assisted attack activity is measurable today. Deepfake fraud has produced confirmed multi-million-dollar losses. The quantum problem in 2026 is a migration and procurement deadline with legal force behind it, not an attack anyone has suffered. What follows is the evidence-based version, with every figure traceable to a named source.
The four reports that actually describe 2026
Four datasets carry most of the weight this year, and they broadly agree with each other.
Verizon DBIR 2026 covers incidents from 1 November 2024 to 31 October 2025. Beyond the 31% vulnerability-exploitation headline, its uncomfortable finding is that defenders got slower while attackers got faster: median time to remediate rose from 32 to 43 days, and only 26% of critical vulnerabilities were fully remediated during the period, down from 38%. Verizon's own newsroom summary attributes part of that compression to automation: attackers are using AI to accelerate the time to exploit known vulnerabilities, "shrinking the window for defense from months to mere hours." The human element featured in 62% of breaches. Third parties featured in 48% — supply-chain involvement rose 60% year over year.
ENISA's Threat Landscape 2025 analysed 4,875 incidents between 1 July 2024 and 30 June 2025 across the EU. Phishing remained the leading intrusion vector at 60%, vulnerability exploitation at 21.3%. Hacktivist DDoS made up close to 80% of all recorded incidents by count — noisy, mostly low-impact, and a useful reminder that incident volume and incident damage are different metrics. Public administration was the most targeted sector at 38%. On ransomware, ENISA recorded Akira as the most frequently deployed strain against EU organisations, ahead of SafePay and Qilin.
Microsoft's Digital Defense Report 2025 (data through June 2025) found that more than 52% of attacks with a known motive were driven by extortion or financial gain, while espionage-only operations accounted for about 4%. The identity finding is the one to memorise: over 97% of identity attacks Microsoft observed were password attacks — spray and brute force against weak or reused credentials — and identity-based attacks rose 32% in the first half of 2025.
The FBI's IC3 2025 Internet Crime Report logged 1,008,597 complaints and $20.877 billion in reported losses, up 26% on 2024's $16.6 billion, and the first year past a million complaints. Investment fraud led at over $8.6 billion, business email compromise at $3.046 billion across 24,768 complaints, tech support scams at $2.1 billion. Reported ransomware losses were just over $32 million — a number that tells you how little of the real ransomware economy reaches IC3, not how small the problem is.
Ransomware economics: more attacks, fewer payers, bigger cheques
The most interesting security chart of the last two years is the divergence between ransomware activity and ransomware revenue. Chainalysis's 2026 Crypto Crime Report traced roughly $820 million in on-chain ransom payments during 2025, down 8% from a revised $892 million in 2024 and the lowest annual figure since 2021. Over the same period, claimed victims on leak sites rose about 50% to a record. The implied payment rate fell to roughly 28%, which Chainalysis describes as potentially an all-time low. The DBIR's parallel figure: ransomware appeared in 48% of breaches it analysed, up from 44%, and 69% of victims did not pay.
Extortion crews responded the way any business under margin pressure does — they raised prices on the customers who still pay. The median on-chain ransom payment went from $12,738 in 2024 to $59,556 in 2025, a 368% increase. Meanwhile the supply side got cheaper: Chainalysis put the average price of initial access sold by brokers at about $439 in Q1 2026, down from roughly $1,427 in Q1 2023, with at least 85 distinct extortion groups active.
| Ransomware metric | 2024 | 2025 |
|---|---|---|
| On-chain payments (Chainalysis) | $892M | $820M |
| Median payment | $12,738 | $59,556 |
| Claimed victims on leak sites | baseline | +50%, record high |
| Estimated share of victims paying | higher | ~28% |
| Ransomware share of breaches (DBIR) | 44% | 48% |
Read that table honestly and you get the real 2026 picture: refusing to pay works at an industry level, and it does nothing for the individual company that just lost five weeks of production. Jaguar Land Rover is the case study. After an incident disclosed in late August 2025, factories at Solihull, Halewood and Wolverhampton stood idle for roughly five weeks, with phased restart from 8 October. The UK's Cyber Monitoring Centre classified it a Category 3 systemic event and modelled a £1.9 billion hit to the UK economy — range £1.6–2.1 billion, more than 5,000 affected UK organisations — the most economically damaging cyber event the UK has recorded. JLR's own Q2 FY26 results booked £238 million in exceptional items, of which £196 million was cyber-related. The UK government issued a £1.5 billion loan guarantee to keep the supplier base solvent.
Marks & Spencer is the other one worth studying, because the entry point was a phone call. Attackers linked to Scattered Spider social-engineered a third-party IT contractor into resetting credentials, then exfiltrated the domain controller's NTDS.dit file — every domain password hash in one artefact. Online orders stopped for 46 days from late April 2025, and M&S guided to roughly £300 million of operating profit impact. Four people, aged 17 to 20, were arrested in the UK in July 2025 in connection with the M&S, Co-op and Harrods incidents.
Identity: the login is fine, the session is the problem
The DBIR's finding that credential abuse fell to 13% of initial vectors should not be read as "credentials stopped mattering." It means the credential economy moved downstream. Flashpoint counted 7.4 million devices infected with infostealer malware in the first half of 2026 — up 27% on the previous six months — harvesting about 1.7 billion credentials between January and June, with Vidar, StealC and Lumma the top three families. Those logs contain more than passwords. They contain browser cookies and authentication tokens, which is to say post-MFA material.
That is the mechanic that matters. A session cookie captured after a successful MFA prompt is a bearer token. Replay it and, depending on how the application is configured, there is no second factor to satisfy because the authentication already happened. Multi-factor authentication remains the highest-leverage control you can deploy — Microsoft states it blocks over 99% of identity-based attacks — but it protects the moment of sign-in, not the hours or days of session that follow.
The Salesloft Drift incident showed the same gap at platform scale. Between 9 and 17 August 2025, an actor Google Threat Intelligence tracks as UNC6395 used OAuth tokens stolen from the Drift chatbot's Salesforce integration to pull data from over 700 organisations' Salesforce tenants. No password was guessed and no MFA was bypassed, because an OAuth grant is access that was already approved. The attacker then combed support-case text for what it actually wanted: AWS keys, VPN credentials and Snowflake tokens pasted into tickets by well-meaning engineers. In September 2025 the FBI issued a Flash alert covering both UNC6395 and UNC6040, the latter running voice-phishing calls that talked users into authorising a malicious connected app disguised as Salesforce Data Loader.
The edge is where the perimeter actually is
If you run anything internet-facing with a vendor firmware image on it, that device is your highest-risk asset in 2026. CISA issued Emergency Directive 25-03 on 25 September 2025 over Cisco ASA and Firepower appliances, covering CVE-2025-20333 (unauthenticated remote code execution) and CVE-2025-20362 (authentication bypass to restricted endpoints). Chained, they hand a remote attacker full control. Cisco tied the activity to the ArcaneDoor cluster and confirmed the actor could modify read-only memory to survive reboots and upgrades.
Then it got worse in exactly the way perimeter incidents do. In November 2025 CISA reported finding devices marked "patched" in agency reporting that had been updated to versions still vulnerable. In April 2026 the directive was revised: applying the September 2025 fixes does not necessarily evict the actor, because a previously unknown persistence mechanism survived the upgrade. Agencies were told to physically pull the power — a reboot was not sufficient — by 30 April 2026, run CISA's core-dump hunt instructions, and apply future updates within 48 hours of release.
CISA followed with Binding Operational Directive 26-02 on 5 February 2026, targeting end-of-support edge devices: firewalls, routers, load balancers, VPN concentrators, wireless controllers and IoT gateways reachable from the internet. Federal agencies must inventory listed EOS devices within three months, decommission them within 12 to 18 months, and stand up continuous discovery within 24. That schedule is a reasonable template for a private company too, because the adversary set is the same one. The joint advisory AA25-239A of 27 August 2025 — co-signed by agencies from 21 governments — documented Chinese state-linked actors tracked as Salt Typhoon exploiting exactly this class of equipment: Cisco IOS XE (CVE-2023-20198, CVE-2023-20273), Cisco Smart Install (CVE-2018-0171), Palo Alto PAN-OS (CVE-2024-3400) and Ivanti Connect Secure (CVE-2024-21887), against telecoms, government, transport and military networks.
Supply chain: your build server is an attack surface
Two campaigns define the current shape of software supply-chain risk.
The first is Cl0p's Oracle E-Business Suite campaign. CVE-2025-61882 is a CVSS 9.8 unauthenticated remote code execution flaw in the BI Publisher Integration component, affecting EBS 12.2.3 through 12.2.14. Oracle shipped an emergency patch on 4 October 2025 — but Cl0p had been exploiting it since early August, and extortion emails started reaching victim executives from 29 September. A second flaw, CVE-2025-61884, followed. The operational lesson: for a mass zero-day campaign, patching tells you nothing about whether you were already hit. You have to hunt.
The second is the npm worm. In September 2025 CISA warned about "Shai-Hulud," self-replicating malware that compromised over 500 npm packages. Its loop was elegant and nasty: a post-install script scanned for GitHub personal access tokens and AWS, GCP and Azure keys, published the stolen secrets to a public GitHub repository under the victim's own account, then used the stolen npm token to inject itself into every other package that maintainer owned. A December 2025 wave moved execution to the preinstall phase so it ran before any test or scan, and hit maintainer accounts on widely used projects. Further waves continued through 2026. Removing the bad package does not end the incident — anything that ran on that machine must be treated as disclosed and rotated.
AI: what is documented, and what is marketing
Start with what is documented. ENISA found that over 80% of phishing emails it identified between September 2024 and February 2025 used AI to some extent. That is the boring, high-volume reality: the grammar tells are gone, localisation is free, and phishing-as-a-service kits ship with generation built in. The DBIR reports mobile-channel social engineering engaging at rates about 40% higher than email, and separately that regular workplace AI use jumped from 15% to 45% of employees, with 67% of that access happening through non-corporate accounts — a data-egress problem more than an attack problem, but a real one.
On the offensive-automation end, the most concrete public case is Anthropic's November 2025 disclosure of GTG-1002, which it attributes to a Chinese state-sponsored group. The operator jailbroke Claude Code by role-playing as a security firm running authorised testing, decomposed the intrusion into small decontextualised tasks, and ran reconnaissance, exploitation, credential harvesting and exfiltration against roughly 30 organisations. Anthropic says the AI performed 80–90% of the campaign with humans intervening at only four to six decision points, and that the model sometimes hallucinated credentials or claimed to have found secrets that were public. Two caveats belong with that story: the tradecraft was ordinary — what changed was tempo, not technique — and the account rests on one vendor's telemetry without published independent forensic corroboration.
Deepfake fraud is where you should be most careful with numbers, because nearly all of them come from companies selling detection. The confirmed case everyone cites is still Arup: in January 2024 a finance employee in Hong Kong joined a video call populated entirely by synthetic recreations of the CFO and colleagues, and executed 15 transfers totalling HK$200 million, about $25.6 million. On trend data, Entrust's 2026 Identity Fraud Report (published November 2025, based on over a billion identity verifications across 195 countries) says deepfakes now account for one in five biometric fraud attempts and that injection attacks rose 40% year over year. Sumsub's 2025–2026 report puts the overall identity fraud rate at 2.2%, down from 2.6%, while multi-technique "sophisticated" fraud rose 180%. Note the denominators before quoting any of it. IC3, for its part, recorded AI as a category for the first time in 2025, with reported losses in the region of $893 million — meaningful, but roughly 4% of total reported cybercrime loss.
The quantum threat, stated honestly
No one has decrypted anything with a quantum computer. The credible near-term risk is "harvest now, decrypt later" (HNDL): an adversary copies encrypted traffic or archives today and stores it until a cryptographically relevant quantum computer exists. It is worth being precise about the evidence here, because vendor material routinely overstates it. Agency language is conditional — the NSA's formulation is that adversaries may be collecting encrypted data now — and there is no publicly attributed HNDL campaign. The argument for acting is not proof; it is asymmetry. Harvesting is cheap, storage keeps getting cheaper, and you cannot retroactively re-encrypt data that already left.
What did change is the resource estimate. In May 2025 Craig Gidney of Google Quantum AI published a paper (arXiv:2505.15917) estimating that RSA-2048 could be factored in under a week by a machine with fewer than a million noisy qubits — revising the 2019 Gidney–Ekerå figure of 20 million qubits in eight hours, a roughly twentyfold reduction in qubit count for a longer runtime. Gidney is careful about the limits of his own result, writing that he sees no way to shave another order of magnitude under the same physical assumptions. No machine anywhere is close to a million high-quality qubits today.
The deadlines, however, are now real and legal. NIST IR 8547 proposes deprecating quantum-vulnerable public-key algorithms after 2030 and disallowing them after 2035. In the US, Executive Order 14412 of 22 June 2026 sets 31 December 2030 for post-quantum key establishment and 31 December 2031 for post-quantum signatures on federal high-value and high-impact systems, with OMB memorandum M-26-15 two days later laying out a phased 2026–2035 plan and a January 2030 TLS 1.3 baseline. NSA's CNSA 2.0 runs its own faster clock for national security systems. If you sell into any of those supply chains, this is a procurement requirement arriving before it is a technical one.
| Milestone | Date | Applies to |
|---|---|---|
| NIST IR 8547: classical public-key deprecated | after 2030 | Guidance, US federal baseline |
| EO 14412: PQ key establishment | 31 Dec 2030 | Federal high-value/high-impact systems |
| EO 14412: PQ digital signatures | 31 Dec 2031 | Federal high-value/high-impact systems |
| NIST IR 8547: classical public-key disallowed | after 2035 | Including legacy deployments |
| Cloudflare full post-quantum platform | 2029 | Vendor roadmap |
The encouraging part is that the encryption half is already happening without most people noticing. Cloudflare reported in April 2026 that over 65% of human traffic reaching its network is post-quantum encrypted, up from roughly 2% of TLS 1.3 connections in early 2024, driven by browsers enabling the hybrid X25519MLKEM768 key agreement by default. Cloudflare has pulled its own target for a fully post-quantum platform forward to 2029, and its stated priority now is authentication rather than encryption — ML-DSA on origin connections in mid-2026, Merkle Tree Certificates for visitor connections by mid-2027 — because certificates and long-lived signing keys are the hard part.
What to do, in priority order
Ranked by evidence, not by vendor category.
- This week. Enumerate every internet-facing device and service with an IP and a firmware version. Subscribe to CISA's Known Exploited Vulnerabilities catalogue and commit to a hard SLA — days, not the 43-day median the DBIR recorded. Turn on phishing-resistant MFA (FIDO2 security keys or passkeys) for administrators, VPN and remote access first; push-based MFA is no longer enough for privileged accounts. Disable legacy authentication protocols that bypass MFA entirely.
- This month. Attack the session layer. Shorten refresh-token and session lifetimes, bind sessions to device posture where your identity provider supports it, and build a one-click mass revocation runbook. Inventory every OAuth grant and connected third-party app in Microsoft 365, Google Workspace, Salesforce, GitHub and Slack, and delete what nobody can justify. Rewrite the help-desk password and MFA reset procedure so identity is never established by voice — that single control would have blunted the M&S intrusion. Add out-of-band verification for payment changes: call back on a number from your own records, using an agreed code word, never a number supplied on the call.
- This quarter. Build the end-of-support replacement plan BOD 26-02 describes, on the same clock. Harden the build pipeline: pin exact dependency versions, disable install scripts by default, add a soak period before new versions reach your builds, replace long-lived npm and cloud tokens with short-lived scoped credentials, and put EDR on developer machines. Test a restore, not a backup — immutable and offline copies only count once you have timed a real recovery. Run a tabletop for data-theft-only extortion, where there is nothing to decrypt and the only question is disclosure.
- This year. Build a cryptographic inventory — a CBOM — before anyone mandates one. Enable hybrid post-quantum key agreement wherever your stack already supports it; on modern TLS 1.3 endpoints that is often a configuration flag. Ask every vendor with a multi-year contract for their ML-KEM and ML-DSA roadmap in writing. Prioritise by secret lifetime: anything that must stay confidential past 2035 — medical records, legal archives, national-security material, long-lived signing keys — is what HNDL actually threatens.
None of that list is exotic. That is the point. The 2026 evidence says the exotic scenarios are not what breaks organisations; slow patching, standing access, unverified humans and unaudited suppliers are.
FAQ
Is quantum computing going to break my encryption in 2026?
No. There is no quantum computer close to breaking RSA-2048, and the current best public estimate — Gidney's May 2025 paper — still requires fewer than a million noisy qubits running for under a week, which is far beyond any existing machine. The real 2026 issue is deadlines: NIST IR 8547 deprecates classical public-key algorithms after 2030 and disallows them after 2035, and US Executive Order 14412 sets 2030 and 2031 dates for federal systems. Treat it as a migration programme, not an active threat.
If most companies refuse to pay, is ransomware in decline?
Payments are declining; attacks are not. Chainalysis measured about $820 million in on-chain ransoms in 2025, down 8% and the lowest since 2021, with an estimated 28% of victims paying. Over the same window claimed victims on leak sites rose roughly 50% to a record, and the median payment rose 368% to $59,556. Fewer payers, higher prices, more attempts.
Are AI-driven attacks genuinely new, or just faster versions of old ones?
Mostly the latter, which is still a serious problem. ENISA found over 80% of the phishing emails it identified between September 2024 and February 2025 used AI to some degree, and Anthropic's GTG-1002 disclosure describes an operation that was 80–90% AI-executed against about 30 targets — but using standard reconnaissance, exploitation and exfiltration techniques. Volume, translation quality and tempo changed. The tradecraft did not.
My company has MFA everywhere. Am I covered?
Partly. Microsoft states MFA blocks over 99% of identity attacks, and over 97% of the identity attacks it sees are password attacks, so MFA is still the highest-return control available. But MFA protects sign-in, not the session afterwards. Stolen cookies from infostealers and abused OAuth grants — as in the Salesloft Drift incident that touched over 700 Salesforce tenants — bypass it entirely. Short session lifetimes, token revocation and third-party app review close that gap.
How do I know if my organisation's credentials are already in infostealer logs?
Assume some are and design around it. Flashpoint counted 7.4 million infected devices and about 1.7 billion harvested credentials in the first half of 2026 alone. Practically: monitor your domains through a credential-exposure service, force resets and session revocation on any hit, keep corporate identities off unmanaged devices, and stop treating a valid password plus a completed MFA prompt as proof of who is on the other end.
Should I trust the big deepfake statistics?
Read the denominator first. Entrust's figure that deepfakes make up one in five fraud attempts is specifically about biometric fraud attempts during identity verification, not all attacks. Most deepfake statistics come from vendors selling detection, which does not make them false but does warrant care. The verified losses are real enough on their own: Arup's Hong Kong office transferred about $25.6 million across 15 payments after a video call with synthetic executives.
Sources
- Verizon — 2026 Data Breach Investigations Report announcement
- Verizon — DBIR report page
- Help Net Security — Lessons from the Verizon DBIR 2026
- ENISA — Threat Landscape 2025
- Microsoft — Digital Defense Report 2025
- SecurityWeek — FBI IC3 2025 Internet Crime Report figures
- Chainalysis — Crypto Crime Report 2026, ransomware chapter
- Cyber Monitoring Centre — Jaguar Land Rover incident statement
- CISA — Emergency Directive 25-03 (Cisco ASA/Firepower)
- CISA — Binding Operational Directive 26-02
- CISA — Advisory AA25-239A (Salt Typhoon / PRC state-sponsored actors)
- CISA — npm supply chain compromise alert (Shai-Hulud)
- Palo Alto Unit 42 — Shai-Hulud npm worm analysis
- Help Net Security — Cl0p and Oracle EBS CVE-2025-61882
- Anthropic — Disrupting the first reported AI-orchestrated cyber espionage campaign
- Infosecurity Magazine — Flashpoint infostealer figures, H1 2026
- AppOmni — Salesloft Drift / Salesforce UNC6395 breach analysis
- Craig Gidney — How to factor 2048 bit RSA integers with less than a million noisy qubits
- NIST IR 8547 (draft) — Transition to Post-Quantum Cryptography Standards
- Executive Order 14412 — Securing the Nation Against Advanced Cryptographic Attacks
- Cloudflare — Targeting 2029 for full post-quantum security
- Entrust — 2026 Identity Fraud Report
- Sumsub — Identity Fraud Report 2025–2026
- World Economic Forum — Lessons from the $25m Arup deepfake attack
- Insurance Journal — Arrests linked to M&S and Harrods attacks


