Report | Cyber Security Report, 2026 | Check Point Software
Report | Cyber Security Report, 2026
ANNUALEDITION14thCYBER SECURITYREPORT 2026
01 INTRODUCTION
LOTEM FINKELSTEIN VP Research
INTRODUCTION
In 2025, the threat landscape evolved rapidly, becoming more interconnected and challenging to manage. Our analysis of global telemetry and incidents reveals a fundamental shift, marked by the emergence of new attack surfaces and techniques. Attackers are integrating AI, identity abuse, exposure exploitation, and ransomware into their campaigns. The most significant change is the accelerated pace and scale at which attack opportunities are being executed. Data indicates that attackers are linking access, execution, and impact across various domains, from AI-driven social engineering and automation to the transformation of ransomware into a data-driven extortion economy. Edge devices and exposed infrastructure are increasingly used as launch points. These patterns were consistently observed across regions and industries in 2025, highlighting the swift combination of techniques to create tangible impacts. AI exemplifies this transformation. This report views AI as a force multiplier that enhances targeting, scale, and adaptation in attacker activities, while also influencing risk prioritization and operational responses. Our report is structured around attacker behavior and real-world data. The subsequent chapters delve into where attackers are focusing their efforts, how different techniques reinforce each other, and which exposure patterns most frequently lead to impact. This provides the necessary context to understand the trajectory of the threat landscape and what will be most critical in 2026. I invite you to explore the data and findings presented in this report.
Lotem Finkelstein, VP Research
02 CYBER SECURITY TRENDS
BEYOND EMAIL: MULTI-CHANNEL SOCIAL ENGINEERING
Which attack surface is the easiest to exploit across all organizations? For attackers in 2025, the answer was the human component. In social engineering attacks, threat actors attempt to do just that: achieve compromise by manipulating human victims into providing the initial access for them. In such attacks, threat actors target employees, outsourced personnel, and third-party service providers to gain access to the organization’s systems or sensitive information. Although these attacks are perceived to be less serious than those exploiting software or hardware vulnerabilities, they can be just as damaging as compromises achieved through other means.
For years, phishing emails served as the primary social engineering vector, and organizations became increasingly aware of these threats. However, by 2025, social engineering expanded beyond traditional email-based campaigns, adopting multi-platform, cross-channel, and highly targeted approaches that leverage phone calls, messaging applications, and real-time impersonation. At the same time, attackers have evolved how email and browser-based social engineering attacks are executed, shifting toward interaction-driven techniques such as ClickFix and its variants. These methods guide users through seemingly legitimate workflows designed to bypass security controls and inadvertently execute malware. These approaches have resulted in millions of compromise attempts worldwide and contributed to several high-impact business breaches, resulting in significant financial losses for enterprises globally.
ClickFix: Social Engineering That Shifts Execution to the User
ClickFix emerged as one of the most significant social engineering techniques in 2025. First observed in 2024, ClickFix is an initial access method in which attackers manipulate users into executing malicious actions by presenting them with fraudulent instructions. These instructions, typically delivered through compromised or attacker-controlled websites, malvertising, or brand-impersonation emails, are crafted to resemble routine verification steps such as CAPTCHAs, validation checks, or error fixes. By appearing as legitimate steps required to continue normal activity, users are manipulated into running attacker-controlled content that ultimately delivers malware.
Figure 1: Flowchart of a ClickFix attack
| Step | Action |
|---|---|
| 1. Attacker places ClickFix lure | In a malicious / compromised website |
| 2. Victim visits ClickFix website | Attacker directs the victim to a website hosting a ClickFix lure |
| 3. Attacker delivers malware payloads | Victim follows ClickFix technical instructions |
| 4. Victim runs malicious content | Devised by the attacker leading to compromise |
This technique succeeds by exploiting user trust and the tendency to follow technical instructions. It has proven highly effective due to its simplicity, scalability, and ability to bypass certain security controls, as malicious actions are executed manually by the user rather than delivered through traditional file-based infection chains. As a result, its adoption has accelerated rapidly. In 2025, ClickFix activity increased by approximately 500% compared to the previous year and was observed in nearly half of all documented malware campaigns.
Recent examples include the MonsterV2 infostealer campaign targeting United States residents and a PureHVNC RAT campaign analyzed by Check Point Research. Beyond financially motivated crime, multiple nation-state-sponsored APT groups have also adopted ClickFix as a preferred delivery mechanism.
Voice-Based Social Engineering – The Weapon of Choice for Major Attacks
Voice phishing and impersonation gained significant traction in 2025, proving to be a highly effective means to exploit user trust. In these attacks, threat actors pose as trusted or authoritative figures and, following targeted reconnaissance, use rehearsed scripts to pressure victims to take actions such as resetting credentials, changing MFA codes, or granting network access.
Historically associated with low-complexity consumer fraud, phone-based impersonation has evolved into an enterprise-focused intrusion technique used to gain an initial foothold in large organizations. In 2025, voice-based impersonation became a preferred technique among highly sophisticated threat groups targeting major brands. These actors conducted in-depth reconnaissance, leveraged multiple communication platforms to engage victims, and executed complex, multi-stage social engineering scripts to achieve their goals.
2025 RANSOMWARE ECOSYSTEM
The number of ransomware victims reached record highs in 2025 as the criminal ecosystem underwent rapid reconfigurations. The year began with a large-scale mass-exploitation by Cl0p, a cyber crime group, followed by the sudden disappearance of several major RaaS (Ransomware-as-a-Service) groups, which created opportunities for emerging actors. However, the number of attacks continued to rise, underscoring the resilience of affiliates and the economic incentives that sustain the ransomware model.
2025 was defined by rapid turnover among the top ransomware groups, the rise of actors such as Qilin, and the re-emergence of established brands like Cl0p and LockBit, all against a backdrop of growing global policy debates over ransom payments, reporting mandates, and the limitations of law enforcement disruption. Ransomware operations increasingly incorporate AI into different stages of the attack lifecycle, including malware development, stolen-data analysis, legal and regulatory assessment, and support for negotiation and extortion activities.
Ransomware activity reached unprecedented levels in 2025. Over 7,960 victims were named on data-leak sites operated by double-extortion groups, a 53 percent year-over-year increase.
Navigating the Rapid Evolution of Social Engineering Threats
In 2025, social engineering took center stage as the dominant attack vector across the threat landscape, from scams and opportunistic malware campaigns to the most damaging enterprise compromises. Threat actors expanded their techniques, increasingly leveraging multiple platforms, diverse psychological tactics, and creative technical approaches. Tactics such as ClickFix and voice impersonation proved especially effective, becoming the primary tools for leading malware and intrusion groups.
As noted earlier, the human element remains the weakest link in organizational security. In 2026, social engineering activity is expected to intensify further. Generative AI is lowering the barrier to highly convincing attacks, while the rapid adoption of new tools and solutions provides threat actors with an expanding set of trusted workflows to exploit. As a result, social engineering represents a growing, adaptive threat that organizations must treat as a central security challenge.