AI in cyber threats: Why 2026 may become the year of the hackers

January 5, 2026  11:00

In 2026, attackers will likely operate faster and more effectively than corporate security teams. This assessment comes from Rachel Tobac, CEO of SocialProof Security and an ethical hacker known for demonstrating digital vulnerabilities in national media, as reported by Axios.

Her warning aligns with troubling statistics: in just the first half of 2025, more than eight thousand data breaches were recorded worldwide, affecting roughly 345 million records. Experts at Experian already describe this as a preview of a future in which AI becomes the primary amplifier of cyberattacks.

Why Attackers Have the Advantage

According to Tobac, criminals have far fewer restrictions when using AI systems. Unlike companies, they are not constrained by legal requirements, ethical protocols, or lengthy approval processes. Cyber groups experiment more rapidly, scale their operations more cheaply, and act more aggressively.

She also stated that the real level of threat is being significantly underestimated. Many companies had already experienced AI driven attacks in 2025 but chose to conceal the breaches. She noted that organizations rarely share their experiences with such incidents because the topic is alarming and identifying the true source of an attack is often extremely difficult.

This kind of secrecy echoes past cases involving anonymous North Korean IT groups, when corporations remained silent for years. A similar pattern is now emerging: according to CrowdStrike, intrusions increased by 220 percent in a single year, affecting more than 320 companies worldwide.

The New Front: Deepfakes

One of the most dangerous trends is the shift from corporate focused attacks to attacks targeting individuals. The goal is identity theft, manipulation, and financial fraud.

Deepfake technologies are becoming a central weapon. Synthesized voices, video calls, and fabricated identities allow attackers to infiltrate corporate systems with unprecedented credibility.

In the past three years alone, deepfake based attacks have increased by more than 2000 percent, and an estimated 82.6 percent of all phishing emails are now generated by AI.

One of the most striking incidents involved criminals using a deepfake video to join an online meeting while impersonating the leadership of a Hong Kong bank. The attack resulted in a loss of twenty five million dollars.

Outlook: A Turning Point Is Coming, but Not Immediately

Despite the grim forecast, Tobac believes that hackers’ advantage will be temporary. Several major cybersecurity players, including Palo Alto Networks, have already described 2026 as a pivotal year when defensive AI begins to catch up with offensive AI.

If these predictions are correct, a new cyber era may begin — one in which autonomous defensive systems identify threats before a human even becomes aware of the attack.


 
 
 
 
  • Archive