Opens in a new tab
vmblog logo 2024 wht (updated)

Navigating AI-Driven Attacks in 2026: Four Shifts Security Leaders Can't Ignore

Share: 

David Marshall | Published: December 23, 2025

vmblog-2026-prediction-series   

Industry executives and experts share their predictions for 2026.  Read them in this 18th annual VMblog.com series exclusive. 

By Beth Miller, Field CISO, Mimecast 

In 2025, cyberattacks shifted into overdrive. Today’s phishing emails can pretty much dupe anyone – even the savviest technologists in the techiest organizations. Automated attacks scale so fast, companies can lose upwards of $25 million in a half hour. Even malware doesn’t sit still; it scoots away from cyber tools like a fly who’s spotted a swatter. 

The main driver behind these advanced and evolving threats? Unsurprisingly, AI. While AI is revolutionizing organizational operations by automating routine tasks, increasing productivity, and accelerating innovation, it’s also creating new opportunities for attackers. Today, it’s not just technology that’s at risk; it’s also the people who rely on it. With AI, both skilled hackers and newcomers can exploit vulnerabilities in systems and manipulate humans more easily. Attackers no longer need years of experience; now, with a basic understanding of certain AI tools, they can launch sophisticated attacks that target both technology and the individuals who use it. 

Heading into 2026, innovation will accelerate on both sides of the cybersecurity spectrum. Here are four predictions for what we can expect from AI-powered cyberattacks and cyber resilience in the coming year, along with strategies to prepare. 

The ‘Zero-Click Attack’ Will Become the ‘Zero-Human Attack’ 

Up until this point, we’ve been worried about zero-click attacks on humans. However, 2026 will be the year that AI-to-AI attacks go mainstream. Malicious AI agents will target your legitimate AI agents, exploiting their APIs, MCP connections, and SDKs. Imagine an attacker’s AI agent manipulating a company’s customer service chatbot to exfiltrate customer data-without any human in the attack chain. 

What’s especially concerning is that, in this new era, failures may not trigger any alerts at all; they could simply fail silently. This is even more dangerous than alert fatigue, where security teams are overwhelmed by noise and risk missing real threats. Here, the risk is that there’s no noise at all-the signal is missed entirely, and organizations remain unaware of the breach until it’s too late. 

Looking forward, security teams will need to collaborate closely with HR and Legal teams to develop administrative responses for AI agents-just as they do for employees or contractors. This means establishing clear protocols for investigating, suspending, or even terminating rogue AI agents, and ensuring compliance and legal oversight are part of the response process. 

Training security teams to recognize and respond to machine-initiated threats will be essential, as the zero-human attack era demands new skills, new partnerships, and a new approach to risk. 

Learning the Benefits & Pitfalls of AI Adoption 

As AI-driven attacks evolve, the need for defenders to use AI to fight AI will only become clearer. According to IBM’s 2025 Cost of a Data Breach Report, organizations using AI-driven security saw breach lifecycles 80 days shorter and costs $1.9 million lower than those without AI defenses. The advantage is real-but so are the risks.  

Organizations that integrate AI into their defenses will have the advantage, while those that don’t risk falling behind as attacks proliferate and evolve. 

But as organizations adopt AI for other business cases, breaches in these AI systems will potentially impact entire supply chains, and the volume and complexity of threats will likely lead to greater burnout across security teams. AI systems often connect deeply into business operations and supply chains. Breaches in these tools can ripple outward, potentially compromising multiple partners and vendors. This complexity, along with relentless attack volume, is pushing security teams toward burnout. 

The adoption of AI is not just a security risk – it is a business risk. Sustainable and responsible AI adoption requires multidisciplinary team support. Managing these risks cannot fall solely on the shoulders of security teams. Instead, multiple internal stakeholders-including business leaders, IT, legal, and operations-must understand the risks and actively support risk management strategies. This collaborative approach ensures that AI adoption aligns with organizational goals and risk tolerance, and that risk mitigation is embedded across all relevant functions. 

Organizations must ensure responsible AI adoption by vetting vendors’ security practices, conducting regular supply-chain risk assessments, and providing ongoing human training to adapt to AI-driven threats. 

The AI Investment Reckoning Brings a Security Nightmare 

By 2026, most of today’s AI startups won’t survive, leaving behind troves of sensitive data and weak security controls. These dormant or failed companies will become prime targets for attacks, and third-party partners could inadvertently inherit significant risk. Partners and customers may unknowingly inherit risk when integrating with or acquiring failed ventures’ assets. The rapid AI gold rush has created a security bubble, and the coming year will be a reckoning as organizations confront the hidden liabilities of defunct AI vendors. 

Proactively, companies should audit their AI vendors’ data retention and offboarding practices, ensure contractual rights to data deletion, and monitor for exposure of their information if a vendor shuts down. In addition, companies should work with vendors that are committed to ethical AI practices and proper governance, specifically seeking partners that are ISO 42001 certified. Building resilience into third-party risk management is not negotiable.

Under Pressure, Overexposed: The Human Factor, Insider Threats, and the Rise of Shadow AI

As organizations cut headcount and raise productivity expectations, employees are stretched to the breaking point. Stress, burnout, and mental fatigue are at all-time highs; a Sophos study found 69% of cybersecurity professionals report increased burnout compared to the previous year, and 50% expect to burn out in the next 12 months. This, combined with the ongoing talent shortage, creates a perfect storm of employee distraction for threat actors to exploit.

This pressure cooker environment is a breeding ground for mistakes – falling for phishing, mishandling sensitive data, or even intentionally exfiltrating information.

But there’s a new twist: the rise of shadow AI. Employees, seeking shortcuts or personal advantage, are increasingly using unsanctioned AI tools, sometimes training personal models on proprietary data and taking them when they leave. The attack surface is multiplying. By mid-2026, enterprises may face ten times as many rogue AI agents as unauthorized cloud applications.

Meanwhile, attackers are recruiting insiders directly, and outsourcing to lower-cost regions introduces new risks. To reduce these risks, organizations must implement clear policies on AI tool usage, monitor unauthorized AI activity, and educate staff about the dangers of shadow AI. Regular security awareness training and robust insider risk programs are crucial, especially as attackers actively recruit insiders and as outsourcing introduces new threats.

The future of security will be defined by how well organizations manage this convergence of human and AI risk.

Looking Ahead 

In the year ahead, AI-boosted cyberattacks should get more sophisticated, and security teams will too. In 2026, security teams should double down on AI-driven detection, strengthen controls over autonomous agents, and invest in continuous training for both humans and machines. Organizations that rethink their strategies today will be best positioned for growth-and resilience-in the defining year ahead. 

## 

ABOUT THE AUTHOR 

Beth Miller 

Beth Miller is a Field Chief Technology Officer at Mimecast, with over 20 years of experience turning risk management challenges into opportunities for innovation and growth.  She specializes in reframing risk as a driver of collaboration, strategic partnerships, and measurable business outcomes, helping organization thrive in uncertainty.