Ivan Milenkovic, Vice President, Cyber Technology Risk at Qualys
AI is further changing the economics of ransomware by allowing threat actors to operate faster and at greater scale. For now, much of its impact is about accelerating established techniques rather than creating entirely new forms of attack.
of a compromise that begin hours or days earlier with stolen credentials, compromised or hijacked sessions, social engineering attacks, vulnerable edge devices accessible on the Internet, or abuse of legitimate remote access solutions.
“ Threat actors are also moving faster using AI, automation, and extortion to supplement their ransomware campaigns and are forcing organisations to adapt to the machine speed at which attacks can occur. To defend against today’ s ransomware, multiple cybersecurity disciplines need to mature, be integrated, and tested to ensure they operate in concert versus in departmental or technical silos.”
But identity is only part of the initial access story. Software vulnerabilities and exposed edge infrastructure are becoming equally significant.
Ivan Milenkovic, Vice President, Cyber Technology Risk at Qualys, said:“ For 19 years, stolen credentials led Verizon’ s table of initial access vectors. This year, they were overtaken by exploitation of software vulnerabilities, which accounted for 31 % of breaches. That shift matters because much of the exploitation is happening at the perimeter. NCC Group found corporate VPNs and Internet-facing edge devices were the most exploited entry points in the first half of 2026, while recent incidents have shown attackers exploiting critical vulnerabilities before patches were even available.
“ We have spent a decade telling boards to patch faster, but that advice now has a mathematical ceiling. Qualys Threat Research Unit found that half of the high-profile weaponised vulnerabilities it studied were exploited before public disclosure, while in 88 % of cases the average organisation patched more slowly than attackers exploited.
Mandiant’ s research points in the same direction, with weaponisation increasingly arriving ahead of the fix.”
From ransomware to enterprise extortion
The ransomware business model itself is also changing. Encryption remains a powerful weapon, but attackers increasingly recognise that stolen data, operational disruption and damaged reputations can provide just as much leverage.
Vibin Shaju from Trellix said:“ Ransomware has shifted from simple file encryption to aggressive multi-tiered extortion, where operators exfiltrate sensitive organizational data, threaten public exposure, and actively hunt for and destroy recovery infrastructure, to eliminate fallbacks. Consequently, resilience strategies for regional enterprises can no longer rely solely on basic data restoration; security teams must implement robust data loss prevention( DLP), isolate critical OT / IT environments while monitoring, and sharing threat intelligence with each other through unidirectional paths, and maintain immutable backup vaults capable of surviving deliberate security degradation attacks.”
Haber added:“ In years past, decoding an encryption key used to be the solution for remediating a ransomware attack. Today, decoding encryption can help retrieve information, but since the real goal of ransomware operators is extortion, they increasingly steal data before encrypting systems. They then threaten public disclosure, contact customers or employees that their data has been leaked, disrupt performance of production environments, and deliberately attack backup and recovery infrastructure to circumvent data recovery.
“ In some incidents, encryption may not even be necessary if the threat actors have exfiltrated sensitive intellectual property, customer information, credentials, regulated data, etc. as a part of their extortion campaign. The business model is therefore evolving from ransomware( files held hostage via encryption) towards“ enterprise extortion as a service” – bad actors are looking for whatever creates maximum economic, regulatory, operational or reputational pressure to convince organizations to pay the ransom.”
AI accelerates the ransomware machine
AI is further changing the economics of ransomware by allowing threat actors to operate faster and at greater scale. For now, much of its impact is about
38 WWW. INTELLIGENTCISO. COM / MIDDLE-EAST