3 MIN READ
Halfway through 2026, the threat landscape has done its usual trick of mutating faster than the people defending it expected. The first half gave us three patterns worth noticing: supply chain attacks still lead, identity attacks crossed a threshold, and AI became both a weapon and a target. None of those three are new. All three accelerated in ways the industry did not fully price in at the start of the year.
What follows is the short version of the mid year review. The full report runs longer. This is the working version a defender actually has time to read.
What broke in the first half
Supply chain compromise stayed at the top of the list, with three named incidents in six months. Each one used a different vector (managed service provider, software update, open source package), and all of them produced downstream breaches that outlasted the original compromise by months. The lesson: when the vendor gets popped, the customer gets popped too, and the lag between the two is now measured in quarters, not days.
Identity driven breach crossed a threshold as the dominant entry point. The session token, the OAuth refresh, the federated identity, all of it sits outside what the traditional MFA covers. Attackers who learn to phish a session, or to mint a token through a misconfigured identity provider, walk past the front door without tripping the alarm.
AI assisted attack scaled in ways the defenders did not have time to absorb. Social engineering, reconnaissance, phishing, deepfake voice: the work that used to require a team of humans now runs with a single operator and a good prompt. The result is volume. The same crew that could run ten convincing phishing campaigns a month can now run a hundred, and the median quality has climbed.
What worked in the first half
Network segmentation that actually contained lateral movement showed up as the difference between a contained incident and a front page one. The breaches that hit segmented environments in the first half had a markedly lower blast radius than the breaches that hit flat networks. Segmentation is not a new idea. It just keeps paying.
Immutable backup that actually restored was the other quiet winner. The ransomware variants that did the worst damage in the first half targeted the backup first, which means the backup that writes once and cannot be modified was the difference between recovery and ransom payment.
Threat intelligence that arrived in time gave the defenders a real edge. The teams who subscribed to the right feeds, shared indicators with the right communities, and automated the enrichment ran ahead of the attacker more often than the teams who tried to do the analysis in house.
What to watch in the second half
Post quantum cryptography migration will hit a wall in the back half. The federal deadlines are here, the enterprise migration sits behind, and the gap sits widening. Anything protected today with a long shelf life (medical records, legal documents, government archives, anything an attacker wants to harvest now and decrypt later) is on the clock whether the enterprise has a plan or not.
AI agent compromise will produce the first set of named incidents. The agents that enterprises deployed in the first half run on a thinner security model than the human users, with the permissions the human users would not have and an audit trail the enterprise cannot easily reconstruct. The attacker who learns to pivot through an agent is going to find a much wider blast radius than the one who pivots through a human account.
Deepfake assisted fraud will hit the wire transfer at scale. The first half produced a handful of high profile cases. The second half will produce more, with smaller targets and lower profile, which means the case will be harder to detect before the money moves.

The bottom line
Segmented networks, immutable backups, threat intelligence worth a damn. The defender who runs flat, who relies on the backup the ransomware can touch, who tries to do the analysis in house, is the one whose name ends up on the next disclosure. The second half of 2026 will test the same pattern in three new ways, and the laggards will be the ones paying for it.
Sources & Further Reading
All claims in this article are sourced from primary documentation, vendor advisories, and reputable security researchers.
Spotted an error? Email the editor. Corrections are issued with a visible correction note.
Editorial standards. Every article on humanrequired.org is reviewed by a human editor before publication. AI may assist with drafting or research; final editorial control is human. Read the full standards.



