Google Cloud Report: Cyber Attackers Are Fully Embracing AI

According to Google Cloud's "Cybersecurity Forecast 2026," artificial intelligence is driving an accelerating arms race between cyber attackers and defenders.

The forecast, produced by Google Cloud's security leaders and experts on the frontlines, outlines the trends they expect to define cybersecurity in the year ahead.

The report warns that adversaries are fully embracing AI, moving from experimental to routine use of the technology to "enhance the speed, scope, and effectiveness of operations." Google predicts that attackers will leverage AI across the entire lifecycle of cyber campaigns, scaling and automating attacks at unprecedented speed. Prompt injection attacks — where AI models are manipulated to execute hidden commands — are called out as a critical and growing threat. The report anticipates "a significant rise in targeted attacks on enterprise AI systems" as these vulnerabilities are exploited.

AI-enabled social engineering is also expected to intensify, including voice-based phishing that uses cloned voices to impersonate executives or IT staff. Google warns these AI-generated interactions will make phishing campaigns far harder to detect and defend against.

On the defensive side, the forecast envisions widespread adoption of AI agents that reshape security operations. It describes an emerging "Agentic SOC," where analysts direct AI systems that correlate data, summarize incidents, and draft threat intelligence. To keep pace, identity and access management models will need to evolve so that AI agents are treated as independent digital actors with their own managed identities.

Traditional cyber crime remains a major concern. Ransomware, data theft, and multifaceted extortion are expected to continue as the most financially disruptive categories, with attackers increasingly targeting third-party providers and exploiting zero-day vulnerabilities. The report also identifies new risks to virtualization infrastructure, calling it a "critical blind spot" where a single compromise could disable hundreds of systems in hours.

Nation-state cyber operations are projected to expand and diversify. Russia is expected to shift focus toward long-term strategic goals; China will continue high-volume, stealthy attacks on edge devices; Iran will blend espionage, disruption, and hacktivism; and North Korea will pursue financially motivated campaigns alongside espionage and IT-worker operations. Google urges organizations to prepare for these threats through proactive monitoring and AI-enhanced defenses.

For the full "Cybersecurity Forecast 2026" report, visit Google Cloud's Threat Intelligence site here.

About the Author

David Ramel is an editor and writer at Converge 360.

Featured

  • abstract quantum computing glowing circuits

    Nvidia Unveils 'Ising' Quantum AI Model

    Nvidia has announced a new family of open source AI models, dubbed "Ising," designed to accelerate quantum computing by improving calibration and error correction.

  • Dana Brunson facilitates a roundtable discussion with research and higher education IT leaders

    Internet2: Closing the Access Gap for Research Cyberinfrastructure

    Internet2's Research Engagement Team brings CIOs and other campus technology leadership together with research computing and data facilitators, forming a community that enables research cyberinfrastructure at institutions of all types and sizes.

  • Digital cyberspace with particles and Digital data

    Report: AI Is Moving Faster than Data Trust

    AI agents are already in use or pilot at most organizations, but data visibility, governance and precision recovery capabilities have not kept pace, according to Veeam's new Data & AI Trust Gap report.

  • Abstract futuristic digital network with glowing padlock icons

    Microsoft Intros New Agentic AI Security Multi-Model Defense System

    A new multi-model agentic AI security system built by Microsoft's Autonomous Code Security team helped researchers find 16 new vulnerabilities across the Windows networking and authentication stack, the company anounced in a recent security blog post.