IBM 2026 X-Force Threat Index: AI-Driven Attacks Are Escalating
Basic Security Gaps Are Leaving Enterprises Exposed

IBM has released the 2026 X-Force Threat Intelligence Index, revealing that cybercriminals are exploiting basic security gaps at dramatically higher rates, now accelerated by Artificial Intelligence (AI) tools that help attackers identify weaknesses faster than ever. IBM X‑Force observed a 44% global increase in attacks that began with the exploitation of public-facing applications, largely driven by missing authentication controls and AI-enabled vulnerability discovery.
Some of the key highlights of the IBM report include:
- Active ransomware and extortion groups surged (49%) year over year, marking ecosystem fragmentation, while publicly disclosed victim counts rose roughly 12%.
- Large supply chain and third-party compromises nearly quadrupled since 2020, as attackers increasingly exploit environments where software is built and deployed or SaaS integrations.
- Vulnerability exploitation became the leading cause of attacks, accounting for 40% of incidents observed by X-Force in 2025.
In Asia-Pacific, attackers frequently employed malware (45%), spam (15%), legitimate tools (15%), and server access (10%) as their primary actions on objective. Exploitation of public-facing applications (50%) and valid accounts (30%) remained the leading initial access vectors, highlighting vulnerabilities in regional digital infrastructure. Key impacts included data theft (14%), brand reputation damage (14%), and credential harvesting (7%), with manufacturing (65%), finance and insurance (17%), and transportation (7%) among the most targeted sectors.
“Attackers aren’t reinventing playbooks, they’re speeding them up with AI,” said Mark Hughes, Global Managing Partner for Cybersecurity Services at IBM. “The core issue is the same: businesses are overwhelmed by software vulnerabilities. The difference now is speed. With so many vulnerabilities requiring no credentials, attackers can bypass humans and move straight from scanning to impact. Security leaders need to shift to a more proactive approach, using agentic-powered threat detection and response to identify gaps and catch threats before they escalate.”
“Asia-Pacific continues to face a sharp increase in cyber threats, with attackers increasingly leveraging AI and exploiting gaps in basic security. This underscores the scale and sophistication of risks facing critical infrastructure, and highlights the need for organisations to prioritise identity protection, secure configurations, and visibility across cloud and application environments to stay ahead of increasingly automated and adaptive threats,” said Catherine Lian, General Manager and Technology Leader at IBM ASEAN.
IBM Highlights AI’s Mounting Identity Problem
Infostealer malware led to the exposure of over 300,000 ChatGPT credentials in 2025, signaling that AI platforms have reached the same credential risk as other core enterprise SaaS solutions.
Compromised chatbot credentials create AI-specific risks beyond simple account access. Attackers can manipulate outputs, exfiltrate sensitive data or inject malicious prompts. This underscores the need to assess enterprise-wide AI adoption and enforce strong authentication, and conditional access controls.
AI, Leaked Tooling Lower Barriers to Ransomware Ecosystem
In 2025, X-Force observed a 49% increase in active ransomware groups compared to the prior year, as smaller, transient operators whose low volume campaigns complicate attribution. This trend is accelerated by collapsing barriers to entry as threat actors reuse leaked tooling, rely on established playbooks and increasingly tap AI to automate operations. As multimodal AI models mature, X-Force expects adversaries to automate complex tasks like reconnaissance and advanced ransomware attacks, driving faster-moving, more adaptive threats.
Pressure on Supply Chains Poised to Grow
X-Force identified a nearly 4X increase in large supply chain or third-party compromises since 2020, mainly driven by attackers exploiting trust relationships and CI/CD automation across development workflows and SaaS integrations. With AI-powered coding tools accelerating software creation, and occasionally introducing unvetted code, the pressure on pipelines and opensource ecosystems is expected to grow in 2026.
This rise is also attributed to the blurring line between nation-state and financially motivated actors. As tactics and techniques spread across underground forums, and AI streamlines reconnaissance and exploitation, techniques once reserved for nation state actors are now being adopted by financially motivated groups.
More from IBM Study
Additional findings from the 2026 IBM report include:
- Asia-Pacific emerged as the second most‑attacked region. Accounting for 27% of total cases observed by X-Force, its rapid digital expansion and ongoing geopolitical tension makes it an attractive environment for threat actors seeking strategic, financial or disruptive outcomes.
- AI accelerating attacker lifecycle. Attackers are using AI to speed research, analyse large data sets and iterate on attack paths in real time. For example, scam centre syndicates from Southeast Asia are reportedly bringing AI into their operations, combining multi lingual chatbots, automated outreach to target victims worldwide.
- Security fundamentals still lacking. X-Force Red penetration tests reveal persistent weaknesses in credential hygiene and software configuration, with misconfigured access controls as the most common entry point for these engagements.
- Manufacturing tops the target list for the fifth year. The sector accounted for 27.7% of incidents observed by X-Force, with data theft being the most common. Asia-Pacific accounted for 68% of all manufacturing cases observed, and Asia Pacific continues to be the epicentre of manufacturing-related incidents.
READ MORE:
- Read the full IBM X-Force Threat Intelligence Index 2026.
- Sign up for the IBM X-Force Threat Intelligence 2026 webinar on 17 March 2026 at 11 am ET / 18 March 2026 at 12 am SGT.
- Connect with the IBM X-Force team for a tailored review of the findings.
- Read more about the report’s top findings in this blog.



