Google Cloud Report: Cyber Attackers Are Fully Embracing AI

According to Google Cloud's "Cybersecurity Forecast 2026," artificial intelligence is driving an accelerating arms race between cyber attackers and defenders.

The forecast, produced by Google Cloud's security leaders and experts on the frontlines, outlines the trends they expect to define cybersecurity in the year ahead.

The report warns that adversaries are fully embracing AI, moving from experimental to routine use of the technology to "enhance the speed, scope, and effectiveness of operations." Google predicts that attackers will leverage AI across the entire lifecycle of cyber campaigns, scaling and automating attacks at unprecedented speed. Prompt injection attacks — where AI models are manipulated to execute hidden commands — are called out as a critical and growing threat. The report anticipates "a significant rise in targeted attacks on enterprise AI systems" as these vulnerabilities are exploited.

AI-enabled social engineering is also expected to intensify, including voice-based phishing that uses cloned voices to impersonate executives or IT staff. Google warns these AI-generated interactions will make phishing campaigns far harder to detect and defend against.

On the defensive side, the forecast envisions widespread adoption of AI agents that reshape security operations. It describes an emerging "Agentic SOC," where analysts direct AI systems that correlate data, summarize incidents, and draft threat intelligence. To keep pace, identity and access management models will need to evolve so that AI agents are treated as independent digital actors with their own managed identities.

Traditional cyber crime remains a major concern. Ransomware, data theft, and multifaceted extortion are expected to continue as the most financially disruptive categories, with attackers increasingly targeting third-party providers and exploiting zero-day vulnerabilities. The report also identifies new risks to virtualization infrastructure, calling it a "critical blind spot" where a single compromise could disable hundreds of systems in hours.

Nation-state cyber operations are projected to expand and diversify. Russia is expected to shift focus toward long-term strategic goals; China will continue high-volume, stealthy attacks on edge devices; Iran will blend espionage, disruption, and hacktivism; and North Korea will pursue financially motivated campaigns alongside espionage and IT-worker operations. Google urges organizations to prepare for these threats through proactive monitoring and AI-enhanced defenses.

For the full "Cybersecurity Forecast 2026" report, visit Google Cloud's Threat Intelligence site here.

About the Author

David Ramel is an editor and writer at Converge 360.

Featured

  • Abstract futuristic digital network with glowing padlock icons

    Microsoft Intros New Agentic AI Security Multi-Model Defense System

    A new multi-model agentic AI security system built by Microsoft's Autonomous Code Security team helped researchers find 16 new vulnerabilities across the Windows networking and authentication stack, the company anounced in a recent security blog post.

  • Profile silhouette of a person thoughtfully touching their chin, overlaid with transparent data visualizations and digital interface elements suggesting artificial intelligence and analytics.

    The Institutional Knowledge Shift Is Reshaping Higher Ed IT

    Higher education IT leaders are navigating a quiet but consequential transition: Experienced team members are retiring or leaving for private-sector roles, and the teams replacing them are smaller, newer, and often stretched thin. The result is a structural shift in how technology decisions are made, executed, and sustained.

  • laptop displaying a red padlock icon sits on a wooden desk with a digital network interface background

    Malware Turns Microsoft 365 Calendar Into Covert Attack Vector

    Security researchers at Group-IB have uncovered a Windows malware strain that turns Microsoft 365 calendars into covert channels for receiving commands and stealing files from targeted organizations.

  • person typing on a touch screen schedule plan calendar

    DOJ Extends Deadline for ADA Title II Compliance

    Institutions working to meet the Americans with Disabilities Act Title II regulations for digital accessibility have received a temporary reprieve: The United States Department of Justice has published an interim final rule to push back the compliance deadline by one year.