Cybercriminals Are Changing Tactics: What Businesses Need to Know in 2026

Cybersecurity threats are not simply becoming more numerous. They are becoming harder to distinguish from legitimate activity.

That is one of the clearest messages in the Huntress 2026 Cyber Threat Report. The report examines threat activity observed during 2025 and shows attackers increasingly relying on stolen credentials, legitimate remote-management software, trusted Microsoft tools, social engineering and AI-assisted techniques rather than obviously malicious software.

For businesses, that changes the cybersecurity conversation. Protecting an organization is no longer just about stopping a suspicious attachment or blocking a piece of malware. Increasingly, the challenge is determining whether the person signing in, running a remote-management tool or issuing a PowerShell command is actually supposed to be doing it.

Hear From Our
Happy Clients

Read Our Reviews

Attackers Are Learning to Look Like Legitimate Users

One of the most important themes in the report is the growing use of legitimate credentials and legitimate software.

Instead of always attempting to “break in” through obvious malware, attackers are increasingly obtaining valid usernames, passwords, session tokens and other authentication information. Once inside, their activity can initially look remarkably similar to that of a real employee or IT administrator.

Huntress describes identity threats involving rogue applications, infostealers, business email compromise, suspicious VPN activity, OAuth abuse, session and token hijacking, and mailbox manipulation.

That creates a significant challenge for small and midsized businesses.

A firewall cannot necessarily determine that the person entering the correct username and password is a criminal. And if an attacker successfully takes over an authenticated session, even multi-factor authentication may not be enough by itself to stop what happens next.

This is why businesses need to think beyond passwords. Strong identity security should include multi-factor authentication, monitoring for unusual logins, limiting administrative privileges and maintaining visibility into what authenticated users actually do after they connect.

Remote Management Software Has Become an Attractive Target

Remote monitoring and management tools, or RMMs, are enormously useful for IT departments and managed service providers. They allow technicians to remotely support computers, install software, troubleshoot problems and manage systems.

Unfortunately, those same capabilities are attractive to cybercriminals.

The report describes attackers increasingly using legitimate RMM applications for persistence and remote control. Because these programs are designed to perform administrative tasks, malicious use can blend into ordinary IT activity rather than immediately looking like malware.

Huntress recommends organizations maintain an inventory of approved RMM software, detect unexpected installations, restrict access to high-value systems and review logs for suspicious activity.

The lesson for businesses is important: trusted software is not automatically trustworthy activity.

Businesses should know which remote-access products are authorized, who is allowed to use them and where they should be installed. An unfamiliar remote-management application appearing on an employee computer should never be dismissed as “probably something IT installed.”

Cybercriminals Are Changing Tactics

Ransomware Has Not Disappeared — It Has Become More Deliberate

Ransomware continues to be a major threat, but the Huntress findings suggest attackers are becoming more selective.

Rather than immediately encrypting everything they can find, many ransomware operators spend more time establishing access, stealing credentials, disabling security controls and exfiltrating data before deploying ransomware.

The report says ransomware represented a relatively small percentage of observed incidents in 2025, but the average time between initial compromise and ransomware deployment increased compared with the previous year. Huntress attributes this in part to attackers prioritizing extortion, data theft and more deliberate operational preparation.

That additional time is both a danger and an opportunity.

It gives attackers more time to explore the network, but it also gives defenders a larger window in which unusual behaviour could potentially be detected before encryption begins.

This is one reason businesses should not think of ransomware protection as simply having a backup.

Backups remain essential, but organizations also need endpoint detection, identity monitoring, network segmentation and security monitoring capable of spotting the activity that happens before the ransom note appears.

Healthcare, Education and Manufacturing Remain Attractive Targets

Cybercriminals do not restrict themselves to huge corporations.

Huntress reported that healthcare and education together accounted for 37% of the incidents it observed in 2025, with healthcare becoming the most targeted industry. Manufacturing also became a significant target, accounting for 17% of observed incidents.

There is a straightforward reason these industries are attractive: disruption is expensive.

A hospital cannot simply stop providing medical care. A manufacturer can lose enormous amounts of money when a production line stops. A school or municipality may have limited IT resources while still maintaining large amounts of sensitive information.

Attackers understand those pressures.

But the same principle applies to almost every business. If losing access to your systems for several days would seriously disrupt operations, those systems have value to an attacker.

Phishing Is Still Working Because It Exploits People, Not Software

Despite enormous advances in security technology, phishing remains effective.

Modern phishing also does not necessarily look like the poorly written scam messages people learned to recognize years ago.

The report describes phishing campaigns using familiar business themes such as document requests, invoice notifications, voicemail notifications and file-sharing alerts. Microsoft remained the most commonly impersonated brand in the phishing activity Huntress analysed.

These attacks succeed because they exploit normal workplace behaviour.

An employee receives what appears to be a Microsoft 365 notification. Someone is asked to review a document. An invoice needs attention. A voicemail is waiting.

The attacker does not necessarily need to exploit a technical vulnerability if they can persuade an employee to hand over access.

Security awareness training therefore remains important, but training must reflect the threats employees are actually seeing today. Telling people to simply “look for spelling mistakes” is no longer enough.

Employees should be encouraged to question unexpected login requests, unfamiliar QR codes, unusual document-sharing notifications and messages that create unnecessary urgency.

Artificial Intelligence Is Giving Attackers a Productivity Boost

Artificial intelligence is also changing cybercrime, although perhaps not in the Hollywood-style way people sometimes imagine.

According to Huntress, AI abuse during 2024 largely centred on creating phishing messages, but activity observed in 2025 expanded into more sophisticated uses. The report discusses deepfakes, AI-assisted coding, cloned phishing websites, automated reconnaissance and malicious instructions presented through trusted AI platforms.

The larger concern is speed and scale.

Cybercriminals can use AI to research targets, create convincing communications, modify code and automate portions of an attack. Huntress argues that AI can lower the skill barrier for inexperienced attackers while helping experienced operators accelerate their campaigns.

That does not mean every cyberattack is suddenly being run by an autonomous AI system.

It means attackers now have another productivity tool.

And defenders have less time to react.

What Should Businesses Do?

The findings in the report reinforce an important cybersecurity principle: effective protection works best when it is layered.

There is no single product that solves every problem.

Businesses should consider combining several protections:

  • Require MFA for email, VPNs, administrative accounts, remote-management platforms and backup systems.
  • Keep operating systems, applications, firewalls and internet-facing services patched.
  • Use endpoint detection and response rather than relying exclusively on traditional antivirus.
  • Monitor Microsoft 365 and other cloud identities for suspicious logins and account activity.
  • Limit administrative privileges and apply least-privilege access wherever practical.
  • Maintain secure, tested backups that attackers cannot easily modify or delete.
  • Know which remote-access and RMM applications are authorized within the organization.
  • Train employees to recognize modern phishing and social-engineering techniques.
  • Monitor suspicious PowerShell, scripting, credential-access and lateral-movement activity.

These priorities reflect the defensive recommendations highlighted in the Huntress report for organizations preparing for evolving AI-enabled and identity-based threats.

The Biggest Cybersecurity Risk May Be the Activity That Looks Normal

Perhaps the most important takeaway from the 2026 Cyber Threat Report is that businesses can no longer assume an attack will announce itself with an obviously malicious file.

The attacker may have a real password.

They may be connecting through a legitimate VPN.

They may be running software your IT department could legitimately use.

They may even be operating inside an authenticated Microsoft 365 session.

That is why modern cybersecurity increasingly depends on visibility, monitoring and context.

The question is no longer simply, “Did our antivirus detect malware?”

Businesses also need to be asking:

Who is accessing our systems, what are they doing, and would we know if their behaviour suddenly changed?

Cybercriminals are getting better at blending in. The businesses that are best prepared will be the ones capable of noticing when something that looks normal is actually anything but.

Source: Huntress 2026 Cyber Threat Report.

Latest Blog Posts

Read Tech Blog