IBM 2026 X-Force Threat Index: AI-driven attacks are escalating as basic security gaps leave enterprises exposed

IBM 2026 X-Force Threat Index: AI-driven attacks are escalating as basic security gaps leave enterprises exposed

IBM has released the 2026 X-Force Threat Intelligence Index, revealing that cybercriminals are exploiting basic security gaps at higher rates, accelerated by Artificial Intelligence tools that help attackers identify weaknesses faster. IBM X-Force observed a 44% increase in attacks that began with the exploitation of public-facing applications, largely driven by missing authentication controls and AI-enabled vulnerability discovery.

Some of the key highlights include:

  • Active ransomware and extortion groups surged 49% year on year, marking ecosystem fragmentation, while publicly disclosed victim counts rose roughly 12%.
  • Large supply chain and third-party compromises nearly quadrupled since 2020, as attackers increasingly exploit environments where software is built and deployed or Software-as-a-Service integrations.
  • Vulnerability exploitation became the leading cause of attacks, accounting for 40% of incidents observed by X-Force in 2025.

Mark Hughes, Global Managing Partner Cybersecurity Services IBM, said: “Attackers aren’t reinventing playbooks, they’re speeding them up with AI. The core issue is the same: businesses are overwhelmed by software vulnerabilities. The difference now is speed. With so many vulnerabilities requiring no credentials, attackers can bypass humans and move straight from scanning to impact. Security leaders need to shift to a more proactive approach, using agentic AI-powered threat detection and response to identify gaps and catch threats before they escalate.”

AI’s mounting identity problem

Infostealer malware led to the exposure of over 300,000 ChatGPT credentials in 2025, signalling that AI platforms have reached the same credential risk as other core enterprise Software-as-a-Service solutions.

Compromised chatbot credentials create AI-specific risks beyond simple account access. Attackers can manipulate outputs, exfiltrate sensitive data or inject malicious prompts. This underscores the need to assess enterprise-wide AI adoption and enforce strong authentication and conditional access controls.

In 2025, X-Force observed a 49% increase in active ransomware groups compared to the prior year, as smaller, transient operators whose low-volume campaigns complicate attribution. This trend is accelerated by collapsing barriers to entry as threat actors reuse leaked tooling, rely on established playbooks and increasingly tap Artificial Intelligence to automate operations. As multimodal Artificial Intelligence models mature, X-Force expects adversaries to automate complex tasks such as reconnaissance and advanced ransomware attacks, driving faster-moving, more adaptive threats.

Pressure on supply chains poised to grow

X-Force identified a nearly 4X increase in large supply chain or third-party compromises since 2020, mainly driven by attackers exploiting trust relationships and CI/CD automation across development workflows and Software-as-a-Service integrations. With Artificial Intelligence-powered coding tools accelerating software creation and occasionally introducing unvetted code, the pressure on pipelines and open-source ecosystems is expected to grow in 2026.

This rise is also attributed to the blurring line between nation-state and financially motivated actors. As tactics and techniques spread across underground forums and Artificial Intelligence streamlines reconnaissance and exploitation, techniques once reserved for nation state actors are now being adopted by financially motivated groups.

Browse our latest issue

Intelligent CISO

View Magazine Archive