Gen report reveals attackers are moving closer to the systems people trust

Gen report reveals attackers are moving closer to the systems people trust

New research finds cybercriminals are increasingly exploiting trusted digital experiences rather than relying on obvious malware or technical exploits.

Gen has published its H1 2026 Threat Report to help people understand what cyberthreats are emerging and what risks are shaping digital life.

A common thread runs through the report: attackers are moving closer to the trusted parts of digital life. Not only are they sending malicious links or dropping malware, they are also abusing context, sessions, workflows, brands, update systems, advertising platforms and delegated authority.

 The Threat Report’s central finding is a shift in how attacks work. The most effective threats in the first half of 2026 did not rely on technical exploits or obvious deception, they succeeded because they were hard to distinguish from normal digital life. Scams arrived through hotel booking platforms, referencing a real reservation.

WhatsApp accounts were compromised not through stolen passwords but by tricking people into approving an attacker’s browser as a linked device. Fraud flowed through real, verified financial accounts whose owners were recruited on social media with promises of quick cash. And AI agents, running with permissions the user had already granted, were stopped before executing a reverse shell.

“The most effective attacks in the first half of 2026 didn’t look like attacks,” said Vita Santrucek, Chief Technology & Development Officer at Gen. “They arrived through booking platforms, family message threads, software update channels and AI agent workflows – all places people already trust. As attackers blend into everyday digital experiences, protection has to move closer to the moments where confidence is earned, exploited or broken.”

Browse our latest issue

Intelligent CISO

View Magazine Archive