October 2026

Cybersecurity Awareness Month 2026: The Year AI-Driven Attacks Went Mainstream

Cybersecurity Awareness Month 2026

It’s everyone’s favorite time of year: Cybersecurity Awareness Month. So, what’s new with the latest threats? Are we still getting hacked like it’s 2025? And what on earth is going on with AI?

In this article, we’ll take a look at the biggest cybersecurity trends from the last year, examine where these trends could take us over the next twelve months, and offer some key tips and advice to keep your teams secure no matter what the future has in store.

First up, let’s start with a look at the biggest factor driving cyber threats in 2026.

AI is the true force multiplier driving cyber threats in 2026

As we explored last year, AI-driven cyberattacks were already a major threat for individuals and companies in 2025 – but this trend has continued to grow. Now, AI has emerged as the true force multiplier driving a growing number of cyber threats in 2026.

This is a trend individuals and security teams can’t afford to underestimate. With generative AI tools like ChatGPT and Claude, attackers can produce convincing, error-free phishing emails and fake websites at scale, quietly erasing the old tells (bad grammar, unnatural phrasing) that used to help people spot a scam. Voice cloning sharpens the threat further: a few seconds of audio pulled from a voicemail or a social post is now enough to convincingly fake a family member or colleague's voice for a grandparent scam or a CEO-fraud deepfake call.

But there’s a deeper shift at work, too: AI is what turns breach data into personalized attacks at scale. Spear phishing – a lure tailored to one specific person – used to take real human effort, so it was reserved for high-value targets. AI collapses that cost. An attacker can now take a leaked database and auto-generate individually tailored lures for everyone in it, all at once. AI hasn’t invented a new threat, but industrialized an old one, unlocking personalized phishing en masse.

Unfortunately, the rise of highly targeted attacks is leading to more breaches than ever.

Read more: AI Data Leaks: How They Happen, and How the Right DLP Tool Can Help

Nearly half of us have been notified of a breach in 2026

France's national cybersecurity assistance body, Cybermalveillance.gouv.fr, just released its third annual Ipsos barometer on public cyber perception, and the headline number is hard to ignore: the share of French people notified that their personal data was compromised jumped from 30% in 2025 to 45% in 2026. This means nearly one in two people have been notified that their data had been leaked in the past year.

The statistic isn’t a one-off spike, either. The report ties it to a maturing underground market for stolen data, where breach after breach feeds a growing supply chain – one built entirely on other people's information. The report is blunt about where this is heading: by this time next year, the share of data victims could very well be over 50%. And this isn’t just a French problem: the US Identity Theft Resource Center tracked over 1,800 reported data compromises in the first half of 2026 alone, generating 471 million victim notices – more than in all of 2025.

Of course, it isn’t all bad news. Awareness of cyber threats is rising, and respondents in the French study can recognize some threats by name at greater rates than before. But the threats are scaling faster than we can keep up. To bridge that gap, we need to look at them in detail.

Data breaches, phishing, ransomware: the biggest threats facing people and companies today

Here are six of the biggest trends in cyber threats we’ve seen in 2026:

#1. Phishing is still the front door

Fraudulent emails and texts remain the most common attack people encounter from day to day, with 53% of respondents in the French report having encountered at least one in the last year. It may not be glamorous, groundbreaking, or sophisticated, but it's still the number one way attackers get in, because it's the cheapest – and it works.

#2. Data breaches are now a baseline, not an exception

As breach notifications become routine, the real story is no longer the breach itself, but what happens after the breach, with victim data getting sold, aggregated, and reused. Put another way, attackers no longer need to break into your systems if they can just buy the keys online.

In 2026, breaches aren’t just a one-off event – each leak feeds the next attack. Personalized phishing, financial scams, and fake bank-advisor vishing calls are all flow-on symptoms of the breach economy. And while awareness of these downstream scams might be increasing (72% of French respondents are aware of bank vishing, up from 59% in 2024), the growing volume of attacks is outpacing this awareness.

#3. Ransomware is still a huge threat for companies

Personal breaches might be growing in scale, but ransomware is still a top concern for companies, especially in the wake of the recent attacks on Marks & Spencer, Asahi, Vietnam Airlines, and many others. Ransomware-as-a-Service (RaaS) has turned what used to require niche technical skill into a subscription product, lowering the barrier for hackers to launch disruptive attacks.

#4. Mobile is a growing blind spot

Smishing (SMS phishing) has been an established threat for years, but attackers are now getting more creative. For example, QR code phishing, or "quishing," is on the rise because people tend to trust a scanned code more than they'd trust a suspicious link.

#5. Every supply chain is now a potential attack surface

Businesses are more interconnected than ever, and that interconnection cuts both ways. As the Canvas hack in early 2026 demonstrates, compromising a single vendor, partner, or software dependency can be the entry point into hundreds (or in the Canvas hack, even thousands) of downstream organizations at once, with no direct attack on the target required. In the Canvas example, a single compromise generated an estimated 275 million victim notices.

#6. The line between "at home" and "at work" continues to be erased

Breaches and leaks don't respect the boundary between personal and professional. Attackers targeting you with your personal data don't care whether you're reading the message on your couch at home or at your desk in the office. That’s why defenses need to be always-on, because attackers already are.

So, what do these trends from 2026 so far add up to? The results of the French study point to a growing confidence gap, where 79% of respondents are aware of “hacking” as a term, but only 55% of respondents feel adequately informed of how to actually respond to cyber threats when they happen.

Fortunately, there are a handful of practical ways to stay safe.

Five concrete ways to help your teams stay safe

According to the French cyber report, there’s some reason to be optimistic: when people are notified of a breach affecting them, many of them do take action. For example, 59% of respondents report becoming more vigilant about unknown emails, texts, and calls. 53% say they changed their passwords, and 44% say they started monitoring their bank accounts.

This is all promising news – but there’s still plenty of room for improvement. In that spirit, we’ve got five concrete steps anyone can take – either in their personal or professional capacity – to stay one step ahead of today’s cyber threats:

  1. Use a side-channel to verify any unknown emails, texts, or calls – especially if they’re trying to create a sense of urgency or panic. If you’re ever worried you might be dealing with an impersonation, cut off communication and contact the person via a confirmed number.
  2. Take control of your digital footprint to make sure you’re not feeding the scammers. That includes proactively limiting what you’re sharing via social media or company websites.
  3. Proactively change any reused or old passwords, especially anywhere they overlap across accounts. For example, 94% of the 19 billion passwords leaked online between April 2024 and April 2025 were reused or duplicated across multiple accounts.
  4. Use a password manager to make unique, strong passwords the default rather than the exception – or consider passkeys wherever these are available.
  5. Monitor your bank accounts closely so that any unusual or unexpected activity is on your radar as soon as possible.

Looking for some extra help? Read our free checklist on 15 Key Cybersecurity Practices for Every Employee

15 Key Cybersecurity Practices for Every Employee
15 Key Cybersecurity Practices for Every Employee

What to expect in 2027 and beyond: three key trends

Cybersecurity is an especially tough industry to try to predict, but based on the French cyber report, three key trends seem pretty safe:

  1. AI will continue to make every cyber threat hyper-personalized. This trend is already underway, and there’s no reason to think it will fade away in 2027 and beyond – especially as generative AI tools become faster, cheaper, and more efficient. Thankfully, AI is becoming just as essential on defense, powering detection systems focused on data sharing practices and email intelligence that track and catch anomalous behavior faster than any security team.
  2. Data breaches will continue to become larger and more frequent. In the year from April 2024 to April 2025 alone, more than 19 billion passwords were exposed across 200+ breaches, and thanks to password reuse, a single leak can unlock multiple accounts. As attackers automate credential stuffing and infostealer malware spreads, there's little reason to expect those numbers to shrink. Companies can limit the fallout by actively monitoring for leaked credentials and training employees to spot the attacks that lead to breaches.
  3. The line between professional and personal will continue to blur. Thanks to remote work, BYOD, and employees reusing passwords across company tools and personal apps, a breach in someone's personal life can quickly become a company-wide incident. Luckily, security awareness is a habit that carries over: employees who learn good practices at work tend to protect their personal accounts too, which in turn protects the company.

From awareness to action: How Riot can help

If there's one takeaway from this year's data, it's the gap between knowing and doing. More people than ever can name the threats – but the report shows that fewer people feel equipped to actually respond to them. Closing that gap is less about more information, and more about practice: seeing a realistic phishing attempt before a real one lands, and building the right reflexes to help every member of your team pause, verify, and report.

That's where Riot can help. Through bite-sized awareness training, realistic phishing simulations, and proactive monitoring of leaked data and risky sharing, Riot helps teams turn Cybersecurity Awareness Month into habits that last all year.

If you're thinking about what 2027 could bring for your team, we'd love to talk.