Industry executives and experts share their predictions for 2026. Read them in this 18th annual VMblog.com series exclusive.
By Mark Wojtasiak, SVP of Research and Strategy, Vectra AI
As organizations move toward a more AI-driven future, so do the adversaries who seek to exploit them. To understand how 2026 will shift the balance of power between attackers and defenders, I sat down with several of my colleagues across Vectra AI – experts who study attacker behaviors, track emerging threats, and steer the evolution of AI-powered defense. Here’s what they had to say about the year ahead.
Ransomware and Extortion Groups Will Continue Operating Like Dynamic Evolving Businesses
“In the year ahead, we expect to see continued evolution in how cybercriminal enterprises operate, especially among ransomware and extortion groups. Ransomware groups and extortion groups are evolving businesses. These groups operate like businesses, although obviously not ethical ones. When one goes dark, its affiliates often find another job with a different group. Tracking them is extremely difficult because there are so many, they share techniques, and they constantly change how they gain access or move laterally. We are also seeing more extortion groups that do not even need to use ransomware anymore. One group might breach an organization, steal sensitive data, and sell it, while another group later buys that data to attack the same victim again. They do not follow a single, scripted attack process but mix and match techniques to fit each target, which makes attribution and disruption hard. The real challenge for defenders is that much of this activity blends seamlessly into legitimate traffic. Organizations need detection that is invisible to attackers and agentless – behavior-focused detection to catch these actors early.” – Lucie Cardiet, Cyberthreat Research Manager
AI is as Convenient to Attackers as it is to Defenders:
“In 2026, the role of artificial intelligence (AI) in cybersecurity will expand dramatically, empowering both attackers and defenders in new ways. It is accelerating both offense and defense, but many organizations still misunderstand the technology and its implications for security. Attackers are already using large language models (LLMs) to automate reconnaissance, craft more convincing phishing content, and generate malicious code faster and with fewer errors. They also use AI to improve targeting and scale social engineering campaigns, reducing the effort and expertise required to launch attacks. At the same time, many organizations are integrating AI-powered tools such as chatbots or business automation platforms that rely on LLMs to process language and data. These integrations can unintentionally expose sensitive information if not properly secured, as seen in the Salesloft Drift breach where attackers exploited trusted connections between systems. Techniques such as prompt injection or LLM hijacking show how these models can be manipulated to perform unauthorized actions or reveal confidential data. Ultimately, not all “AI-driven” technologies are equal and this will continue into the new year.” – Lucie Cardiet, Cyberthreat Research Manager
The Rise of the AI Security Operations Center (SOC)
“In 2026, cyberattackers will double down on social engineering, occasionally with a small generative AI boost, as their primary means of gaining initial footholds in organizations. The trend toward using stolen credentials will persist, with attackers increasingly targeting SaaS-delivered data and applications. As dwell times for ransomware and other serious attacks shrink, defenders will focus on detecting the earliest possible signs of compromise. Yet these early indicators will remain noisy, riddled with false positives that overwhelm already stretched SOC teams battling alert fatigue. The urgency to extract value from this early noisy signal will push organizations to embrace both traditional and generative AI to refine detection, triage, and investigation – fueling the rise of the �AI SOC.’ This shift will be driven not by the desire to reduce cost but by the need for faster, better outcomes. While large vendors will continue to champion platform consolidation, genuine innovation will come from smaller startups experimenting with fringe ideas – some of them may end up redefining the SOC technology landscape.” – Oliver Tavakoli, Chief Technology Officer
2026 AI-Powered Attack Techniques
“Attackers are still not at the point where they will trust AI to run end-to-end autonomous attacks in critical scenarios, but that doesn’t mean it isn’t actively being explored. End-to-end attacks will begin to occur, though most high-profile hacks will only make use of LLMs in highly guard-railed scenarios in order to prevent detection. Remember: Attackers are early adopters! And they aren’t restricted by legal departments concerned with Intellectual Property (IP), Personally Identifiable Information (PII) and data governance. They are exploring the uses of AI in their operations, at rapid scale.” – Sohrob Kazerounian, Distinguished AI Researcher
The Impact of Questionable GenAI and LLM Usage
“As organizations rush to bring AI into every aspect of labor-intensive work, calls to understand and implement solutions in a more careful and responsible manner will be drowned out by short-term efficiency gains. For example, one of the fastest growing application areas of GenAI is in the domain of programming, where new models, tools and workflows are constantly being invented and adopted. Despite being rather impressive, coding agents and AI largely generate bloated and inefficient code relative to more robust and elegant solutions of an even half-decent human developer. The near-term cost-savings of using GenAI over human programmers outweighs the potential long-term risks that may arise from over reliance on AI workers. Over time, code will become increasingly difficult to understand or debug by anything other than an LLM, and organizations will not be prepared to respond to challenges that result from short-term thinking.” – Sohrob Kazerounian, Distinguished AI Researcher
One thing is clear: 2026 will be a defining year for AI in cybersecurity – not just for defenders, but for attackers who are rapidly scaling their capabilities. Ransomware and extortion groups are professionalizing. AI is becoming a force multiplier for both sides. SOC teams are being pushed to adopt intelligent automation faster than ever. And organizations rushing to implement GenAI may be building long-term technical debt without realizing it. As the new year progresses, the organizations that will thrive are those that embrace behavior-based detection, AI-assisted security operations, and a more realistic understanding of how attackers use emerging technologies.
Cybersecurity is evolving – and so must we.
##
ABOUT THE AUTHOR
Mark, also known as Woj, is the Senior Vice President of Product Research and Strategy at Vectra AI. Passionate about cybersecurity and dedicated to simplifying the complex, Woj consistently advocates for cyber defenders in his approach to product development, marketing, and leadership.





