Introducing the 2026 Cloudflare Threat Report (opens in new tab)
Cloudflare’s 2026 Threat Report argues that cyberattacks are shifting from brute-force intrusion toward high-trust exploitation. Attackers increasingly prioritize “Measure of Effectiveness” (MOE)—the greatest operational result for the least effort—using stolen tokens, AI, trusted cloud services, and social engineering rather than costly custom exploits. The report concludes that defenders must focus on identity, integrations, infrastructure resilience, and continuous monitoring of legitimate tools. ## Measure of Effectiveness (MOE) - MOE measures the ratio between an attacker’s effort and the operational outcome. - Threat actors favor: - Stolen session tokens over expensive zero-day exploits. - Reputation-based infrastructure such as LotX over custom servers. - AI-assisted automation over manually written tooling. - The most dangerous actors are those able to combine intelligence and technology into continuous, high-speed operations. ## Eight trends shaping the 2026 threat landscape - **AI-driven attacker operations** - Generative AI supports real-time network mapping, exploit development, and deepfake creation. - Lower-skilled attackers can now conduct more sophisticated, high-impact campaigns. - **State-sponsored infrastructure pre-positioning** - Groups such as Salt Typhoon and Linen Typhoon are targeting North American telecommunications, government, commercial, and IT services. - Their goal is to maintain access that can provide long-term geopolitical leverage. - **Over-privileged SaaS integrations** - Third-party APIs can expand a single compromise across hundreds of organizations. - The GRUB1 breach of Salesloft demonstrates the risks created by excessive integration privileges. - **Weaponized trusted cloud tools** - Attackers use services such as Google Calendar, Dropbox, GitHub, Google Drive, Microsoft Teams, and Amazon S3 to conceal malicious activity. - Legitimate enterprise traffic makes command-and-control communications harder to distinguish from normal use. - **Deepfake-based insider placement** - North Korean operators are using fraudulent identities and deepfakes to place remote IT workers inside Western companies. - These operatives support espionage and illicit revenue generation. - **Session-token theft** - Infostealers such as LummaC2 harvest active authentication tokens. - Attackers can then bypass multi-factor authentication and begin post-authentication activity. - **Internal brand spoofing** - Phishing-as-a-service tools exploit mail-relay blind spots where sender identity is not re-verified. - This enables convincing impersonation messages to arrive directly in trusted user inboxes. - **Hyper-volumetric DDoS attacks** - Botnets such as Aisuru are generating increasingly large distributed denial-of-service attacks. - The speed and scale of these attacks can overwhelm infrastructure before human responders can react. ## Living off legitimate cloud infrastructure - Attackers increasingly avoid known malicious servers and instead use legitimate SaaS, IaaS, and PaaS platforms. - Cloud services can be used to host payloads, redirect victims, deliver malware, or scale campaigns. - Amazon SES and SendGrid, for example, can be abused for phishing and malware distribution. - This “living off the land” approach—or “living off anything-as-a-service”—allows attackers to hide behind the reputation and normal traffic patterns of trusted providers. - Cloud-resource abuse is evolving from opportunistic infrastructure misuse into a deliberate nation-state strategy. Defenders should treat identity tokens, SaaS permissions, cloud activity, and trusted integrations as critical security boundaries. Organizations need least-privilege access, stronger token protection, continuous monitoring, automated DDoS mitigation, and detection that evaluates behavior—not just whether a service is legitimate.