Press ReleaseCyber Crime & ForensicTech

The Cybercrime Machine: Infoblox Launches 2026 Threat Landscape Report, Exposes the Automated, AI-Fuelled Economy Behind Modern Cyberattacks

Insights from trillions of DNS queries expose the industrialised criminal ecosystem reshaping modern cybercrime

Infoblox, the leading platform for pre-emptive security and critical network services, today announced the release of its 2026 Threat Landscape Report, revealing that cybercrime has evolved into an industrialised criminal economy that enables attackers to operate faster, scale more efficiently, and evade traditional defences. Frontier AI, specialised criminal services, and hidden infrastructure are accelerating this transformation, compressing the time defenders have to respond, and exposing the limits of traditional detect-and-respond security strategies.

The report examines cybercrime through four dimensions: the industrialised services powering attacks at scale, the hidden infrastructure enabling evasion, the evolving lures reaching victims, and the expanding attack surfaces opening new footholds inside the enterprise. Together, these four perspectives reveal how modern cybercrime operates and what organisations must do to stay ahead of it.

Drawing on trillions of DNS queries, billions of underground criminal transactions, and extensive threat research, Infoblox Threat Intel identified the trends reshaping how modern cybercrime operates, finding that:

  • Nearly 25% of 120 million newly observed domains were high or critical risk, reflecting the massive scale of disposable infrastructure fuelling modern cybercrime.
  • The most prevalent threat, impacting more than 95% of networks, was traffic distribution systems (TDSs), ubiquitous and difficult-to-detect infrastructure that routes victims to targeted malware, phishing, and scam attacks.
  • 88% of threat-related domains were observed in only one customer environment, while 44% were active for just a single day, illustrating the scale of domain weaponisation and the growing reliance on short-lived infrastructure designed to outpace defenders.
  • 65% of Infoblox Threat Defense™ customers queried domains associated with residential proxy networks, which attackers use to disguise malicious activity as legitimate consumer internet traffic, allowing attacks to blend into everyday internet activity and evade detection.
  • Scam-related domains increased 62% year over year, driven by brand impersonation, identity theft, and financial fraud.

“This year’s report documents the cybercrime machine, a globally connected criminal economy where frontier AI, specialised criminal services, and hidden infrastructure have transformed how attacks are created, purchased, and deployed,” said Dr Renée Burton, Vice President, Infoblox Threat Intel. “The most important shift is not that attackers have become more sophisticated. It’s that sophisticated capabilities have become widely accessible, changing the pace of cybercrime and challenging security strategies built primarily around detection and response.”

The report illustrates how cybercrime has evolved from isolated attacks into an interconnected criminal ecosystem fuelled by specialisation, automation, and shared infrastructure. As these capabilities continue to spread, organisations must rethink long-held assumptions about how cyber threats emerge, spread, and can be disrupted.

Read the blog or download the 2026 Threat Landscape Report.

About Infoblox

Infoblox is a leading platform for pre-emptive security and hybrid, multi-cloud networking that delivers enterprise resilience and agility. Trusted by more than 5,700 customers, including the majority of Fortune 100 companies as well as emerging innovators, the company seamlessly integrates, secures, and automates critical network services so businesses can move fast without compromise. Visit infoblox.com or follow the company on LinkedIn.

Media Contact

FINN Partners Singapore: infobloxasia@finnpartners.com

CSA Editorial

Launched in Jan 2018, in partnership with Cyber Security Malaysia (an agency under MOSTI). CSA is a news and content platform focusing on key issues in cybersecurity in the region. CSA is targeted to serve the needs of cybersecurity professionals, IT professionals, Risk professionals and C-Levels who have an obligation to understand the impact of cyber threats.

Related Articles

Leave a Reply

Your email address will not be published. Required fields are marked *