The latest wave of industry threat research paints a picture that should get the attention of every business leader. Attackers are moving faster, automating more of their work, and finding new ways to get around the security measures businesses already have in place. At the same time, many organizations are still relying heavily on basic defenses while leaving significant gaps in monitoring, testing, and incident response.
This article walks through what the most recent data reveals about where cyber risk is heading through the remainder of 2026 and into 2027. It looks at who cybercriminals are targeting most, what they are trying to steal, how familiar attacks are changing, where new attack channels are emerging, how AI is influencing cybercrime, and where businesses remain most exposed.
People Are Still the Primary Target

Despite years of investment in security technology, the human element remains the weakest link in most organizations. Recent survey data show that 29% of businesses identify human error and social engineering as the threat vector they are most concerned about over the next 12 months. That concern is well founded, because poor user practices were blamed for 30% of security incidents, followed closely by a lack of end-user training at 29% and limited cybersecurity expertise at 27%.
These numbers tell a consistent story. Attackers succeed most often not by breaking through firewalls but by convincing an employee to click a link, share credentials, or approve a fraudulent request. That is why security awareness training and a strong security culture have become just as important as any tool in the stack.
Phishing Remains the Most Reliable Weapon in the Attacker’s Arsenal
Phishing continues to dominate the threat landscape, and the scale is staggering. Microsoft detected approximately 7.6 billion phishing threats globally in a single three-month period this year. Microsoft also noted that credential phishing accounted for 94% to 96% of all malicious payload attacks each month during the second quarter of 2026, while traditional malware represented only 4% to 6%. This shows that attackers are no longer focused on just infecting devices. They want your passwords because a stolen credential opens doors quietly and often goes undetected far longer than malware ever would.
2026 has also seen other phishing tactics rise. Phishing doesn’t just mean an email; it can also be through QR Codes. In fact, QR code phishing peaked at 18.7 million attacks in March 2026. That said, Strong identity controls can help reduce this risk. Multifactor authentication, limited account privileges, conditional access policies, and monitoring for unusual sign-ins can make stolen credentials less useful and help businesses identify compromised accounts sooner.
Business Email Compromise Is Becoming More Prevalent
Business email compromise is not new, but the way attackers are using it in 2026 is becoming harder to spot. Instead of immediately asking someone to transfer money or send confidential documents, many attackers are starting with simple conversation starters designed to establish trust.
Between 87% and 92% of initial business email compromise messages observed during the second quarter used generic openings, such as asking whether someone was available. Only a small portion started with an immediate request involving money or documents.
Businesses should encourage employees to verify unusual requests through a second communication method, particularly when money, account information, credentials, or sensitive documents are involved. The warning sign is no longer always an obviously suspicious email. Sometimes it is simply a conversation that does not feel quite right.
Attackers Are Expanding Beyond Inbox
Email security remains critical, but the inbox is no longer the only place where phishing happens. Cybercriminals are increasingly using collaboration platforms such as Microsoft Teams because employees often place more trust in messages and calls that appear inside tools they use every day.
Microsoft reported that Teams phishing activity increased throughout the second quarter of 2026, and malicious voice calls through Teams have also risen sharply. Technical support impersonation has become a common tactic, with attackers posing as support personnel and attempting to convince users to share information, approve access, or take an action on their device.
For businesses, this means security awareness training needs to evolve. Employees may already know to question an unexpected email attachment, but they should apply the same caution to an unexpected message on common collaboration platforms like Microsoft Teams, meeting invitations, phone calls, or QR codes.
The platform may change, but the attack still depends on earning someone’s trust.
Supply Chains and AI Are the New Frontiers of Risk

Two newer risk categories are growing quickly. Large supply chain and third-party compromises have nearly quadrupled since 2020, driven by attackers targeting trusted relationships, software development workflows, SaaS integrations, cloud interfaces, and software dependencies. Your security is now only as strong as that of every vendor connected to your environment.
AI is reshaping both sides of the fight. Attackers are using it to accelerate research, analyze large datasets, and adjust attack paths in real time. AI credentials themselves have become valuable loot, with more than 300,000 ChatGPT credentials found for sale on the dark web in 2025. As businesses connect AI platforms and agents to company data, a compromised AI account can expose sensitive information and every connected system behind it.
The Bottom Line for 2026
Taken together, the data from 2026 presents a clear picture. Cybercriminals continue to target people, phishing is increasingly focused on stealing credentials, and business email compromise has become more patient and far-reaching. Attackers are also extending their tactics beyond email by approaching employees through chat platforms and voice calls. That said, it is important to understand that as the attacks become faster, better, and more prevalent, keeping up implies you’re already taking care of the basics as well as adapting to the latest attacks. If you’re behind on the basics, it will be difficult, if not impossible, to catch up.
Moreover, organizations appear to recognize the growing risk in 2026. According to a Kaseya report published in May 2026, 44% of businesses increased their cybersecurity spending during the previous year, while 48% expect their budgets to grow over the next 12 months. Among those planning an increase, 68% anticipate spending between 5% and 25% more. The real measure of progress will be whether that investment addresses the gaps that continue to appear, including limited monitoring, incident response plans that have not been tested, and employee training that has not kept pace with changing attack methods. The cybersecurity trends of 2026 show that attackers are becoming faster, more automated, and more patient. Organizations that respond to these findings now will be better prepared to close their security gaps before an incident exposes them.


