Industry executives and experts share their predictions for 2026. Read them in this 18th annual VMblog.com series exclusive.
By Andrew Brandt, principal threat researcher; Gina Chow, emerging threat specialist; and Ginny Spicer, threat analyst, Netcraft
Every new year creates an opportunity to look at what’s come before and plan for what’s ahead. 2026 will see a confluence of events that will impact how defenders protect the networks and data entrusted to their care. From elections and sporting events to the sunset of an operating system and new AI threats, cybersecurity professionals will have a lot to contend with (as usual). Here’s what some of the expert team at Netcraft is predicting for the coming year.
Prediction 1: Legacy systems will lead to persistent vulnerabilities in 2026
With Windows 10 reaching end of life in October 2025, many organizations and individuals are expected to resist upgrading, leaving vast numbers of unpatched systems exposed throughout 2026. This will likely lead to a surge in the exploitation of legacy Windows vulnerabilities. Sectors reliant on outdated or specialized infrastructure, particularly in industrial goods and services, will be especially at risk as they often lack the resources or inclination to prioritize regular security updates. – Andrew Brandt, principal threat researcher.
Prediction 2: Seasonal events to drive more crime; 2025 attack hot-spots will grow hotter
Seasonal and event-driven attack patterns – including phishing waves aligned with tax deadlines, the 2026 Winter Olympics and the U.S. midterm elections – are all likely to be exploited for social engineering lures. Additionally, holiday travel and hospitality brands are expected to be impersonated in large-scale scams. The continued rise of scam call operations, fake investment platforms and cross-group collaboration among threat actors is another area of the threat landscape that will see expansion. Growing partnerships between ransomware and hacktivist groups, such as DragonForce and Scattered Spider, highlight the ongoing convergence of ideological and profit-driven cybercrime, a trend that will likely intensify through 2026. – Andrew Brandt, principal threat researcher.
Prediction 3: Industries with downstream impact will remain the prime targets for bad actors
In 2026, industries with broad downstream impact – such as managed service providers (MSPs), insurance and consulting – will remain prime targets for threat actors seeking access to other victims. Fintech, especially segments tied to under-regulated assets and crypto markets, will continue to struggle with maturing their security infrastructure. Meanwhile, logistics, shipping and retail sectors may see phishing lures tied to tariffs or shipping-related themes. – Ginny Spicer, threat analyst.
Prediction 4: New AI vulnerabilities will continue to emerge
As AI systems evolve from chatbots to autonomous agents and agentic browsers, new security and data integrity risks are continuing to emerge. The growing complexity of these systems will likely result in data leakage, workflow manipulation and unintended access to sensitive information. Threat actors may leverage AI agents for reconnaissance, data exfiltration and even automation of some ransomware operations. At the same time, the possibility of manipulating AI agents themselves presents a lucrative opportunity for fraudsters if developers fail to bake in robust protections. – Ginny Spicer, threat analyst.
Prediction 5: Phishing-as-a-Service will gain more traction, fraud detection will get more complicated
Phishing-as-a-Service emerged as a defining shift in 2025, dramatically lowering the technical barrier for cybercriminals and enabling widespread, coordinated phishing campaigns across industries. The trend of “OAuth phishing” also gained traction, where attackers manipulate users into granting malicious third-party app access instead of stealing credentials outright. This represents a new layer of deception and signals a likely expansion to more online platforms in 2026. -Gina Chow, emerging threat specialist.
Defend with diligence
Cybersecurity has never been an easy job, but it’s always been a deeply needed one. These predictions may seem daunting, but we’re convinced that security pros have the right stuff to overcome them. For instance, AI makes cybercrime easier, but it also empowers defenders to stop that crime. As always, a combination of current and emerging tools will enable diligent, vigilant security pros to maintain the upper hand.
##
ABOUT THE AUTHORS
Gina Chow is an Emerging Threat Specialist at Netcraft, tracking how attacker behaviors and social engineering tactics evolve online. Her work focuses on turning behavioral insights into practical strategies to disrupt scams and protect users.
Andrew Brandt is a Principal Threat Researcher at Netcraft, a cyberattack forensics specialist focused on disrupting and deterring threat actors at scale and with velocity, while communicating the nature of those threats to the public.
Ginny Spicer is a Cyber Threat Analyst at Netcraft, where she tracks emerging threat actor tactics and campaigns. Her background is in network analysis and nation-state threat research. She’s the 2026 president of the HTCIA’s Silicon Valley chapter, a board member for the Deep Packet Inspection Consortium, and one of the Internet Society’s 2025 Youth Ambassadors.






