Artificial intelligence (AI) is expected to make cyberattacks faster, more scalable, and harder to detect in 2026 as both sophisticated and less-skilled cybercriminals adopt the technology, according to CrowdStrike’s 2026 Global Threat Report.
The report said threat actors will use AI for social engineering, malware development, intelligence gathering, and other technical activities. Less-skilled attackers can use AI to make up for limited technical knowledge, although mistakes in AI-generated output can also expose flaws.
More advanced attackers are expected to use AI to speed up malware development, trick victims, and maintain access to compromised systems. CrowdStrike said attackers with more resources could increasingly use agentic AI, which can perform tasks with little human supervision.
For businesses, the growing use of AI also means more systems that need protection. As organizations put AI into everyday operations, their attack surface will expand to include AI models, training data, AI agents, and the technology suppliers behind them.
CrowdStrike said limited visibility into how AI systems operate could create security gaps that attackers can exploit.
Ransomware also remains a major business threat. CrowdStrike said financially motivated cybercrime groups were the primary eCrime threat in 2025, causing business disruptions, recovery costs, and lost revenue for victims.
The ransomware business has remained resilient despite law enforcement actions and conflicts among cybercriminal groups. CrowdStrike expects the threat to continue in 2026, with attackers increasingly using voice-based scams, known as vishing, to break into software-as-a-service (SaaS) applications and steal data.
These attacks can be particularly damaging because SaaS platforms often contain business data and provide access to other systems once an account is compromised.
Targeted attacks linked to governments also remained active in 2025, with attackers using stealthier methods, cloud-based techniques, and AI to pursue intelligence and geopolitical objectives.
Russia-linked groups are expected to continue targeting Ukrainian organizations and NATO member states for intelligence. China-linked groups are expected to maintain a high level of activity, with telecom, financial services, and logistics organizations among their targets.
North Korea-linked groups are expected to continue focusing on military intelligence, cryptocurrency theft, and activities that generate revenue for the regime.
Cloud systems are also becoming a bigger target. CrowdStrike said government-linked attackers are using stealthier ways to gain initial access, while financially motivated criminals are focusing on maintaining access and obtaining higher-level privileges.
The report expects more attackers to target cloud environments in 2026, including attempts to exploit broad access to cloud accounts and identities.
Attackers are also continuing to exploit software vulnerabilities, including newly discovered “zero-day” flaws. Once technical details or proof-of-concept code become publicly available, attacks can spread more widely as more cybercriminals gain the ability to exploit the same weakness.
For Philippine businesses, the trends highlight a growing need to secure not only computers and networks but also cloud accounts, employee identities, SaaS platforms, AI tools, and third-party technology providers. Organizations increasingly relying on cloud services and AI need visibility into who can access these systems and what those systems are allowed to do.

