Cloud and software-as-a-service environments have emerged as the primary targets for cyber-threat actors in 2026, according to a new report published by Darktrace on August 3. The cybersecurity firm noted that the first half of 2026 saw attackers continue moving away from malware and vulnerability exploitation toward compromising identities. This shift makes "trust" the new attack surface, the report states.

While threat actors primarily targeted account credentials in 2025, attacks during the first six months of 2026 have expanded to include email authentication, cloud entitlements, software supply chains, AI gateways, remote administration tooling, and non-human identities. Roughly two-thirds of phishing emails sent in H1 2026 passed DMARC email validation protocols, the report found. More than a third—37%—of phishing attacks contained a high volume of text in the first half of 2026, up from 32% in the same period in 2025. Additionally, 39% of phishing featured novel social engineering techniques, and VIP users were targeted in 25% of observed attacks. ClickFix social engineering, a technique designed to trick users into running malicious code themselves, remained a common attack vector from 2025.

The researchers highlighted several cases where attackers exploited trusted digital supply chain infrastructure used by victims in H1 2026, including threat actors in April hijacking Axios—a JavaScript library downloaded over 100 million times a week—to spread remote access trojans. "Increasingly, attackers do not need to bypass trust controls in these environments; they inherit them through compromised identities, delegated access, and legitimate administration tools," the researchers wrote. In one case, a single compromised SaaS account led to malicious activity across email, SaaS, and network layers, such as inbox rule changes and the launch of phishing attacks. The report noted that this type of attack is difficult to detect because none of the indicators were decisive in isolation, but together represented a clear intrusion.

The growing use of AI in enterprises has significantly expanded opportunities for cyber attackers, Darktrace found. Threat actors are leveraging AI tools to launch attacks at scale, demonstrated by the use of AI-generated malware exploiting the React2Shell vulnerability, in which an attacker used a large language model to produce working exploit code and deploy it at scale. In July, the world's first fully AI-generated ransomware campaign, dubbed JadePuffer, was highlighted by security researchers, where an agentic threat actor exploited a vulnerability in an internet-facing server before launching a fully automated ransomware attack. "AI is accelerating the path from vulnerability disclosure to operational exploitation," the Darktrace researchers wrote. The report also noted that attackers abused legitimate blockchain infrastructure to distribute infostealers, including AMOS and Phexia, with such services frequently used by users with limited security resources and often enabling malicious actors to reach a far wider victim base. Organizations face a challenge where traditional authentication and validation systems no longer provide adequate protection against sophisticated attackers who can inherit trust through compromised credentials rather than breaking through security controls directly. Enterprises will need to rethink security architectures that were designed for perimeter defense when threats now operate from within trusted environments.