ExtraHop’s 2026 Global Threat Landscape Report reveals how rapid AI adoption is reshaping the cyber threat landscape, exposing organisations to new attack vectors while leaving security teams struggling to keep pace. The research highlights rising AI-related security incidents, prolonged attacker dwell times and the growing need for real-time network visibility to strengthen cyber defence.
ExtraHop, a leader in modern network detection and response (NDR), has released the 2026 ExtraHop Global Threat Landscape Report, exposing the reality of modern cyber defence in the age of AI.
The comprehensive analysis examines an environment where rapid AI adoption has unlocked new entry points for adversaries and accelerated their velocity, while security teams still struggle to keep pace, unable to uncover hidden threats while drowning in prolonged dwell times and escalating alert noise.
While defenders look to AI to counter these attacks, the findings reveal that security operations centres (SOCs) still rely heavily on manual intervention and maintain a primarily reactive posture.
AI infrastructure emerges as prime cybersecurity target
When asked which attack surfaces represent the biggest cybersecurity risk to their organisation, more than half (55%) of respondents cited AI agents, agentic infrastructure and Gen AI applications.
Concerns over AI risks were validated as a majority (85%) of respondents identified security incidents, data exposures or near misses where the root cause of the incident was an AI system. Examples include:
- AI-enhanced external attacks (40%)
- Compromised AI identity and session theft (38%)
- Third-party vendor/supply chain breach where a vendor’s integrated AI or agent mishandled data or created a vulnerability (36%)
- Shadow AI exposure (35%)
- Agentic/API Logic failure (31%)
LockBit and RansomHub lead global cyber detections as AI scales enterprise attacks
LockBit and RansomHub were the two threat groups most detected within enterprise networks for the second year in a row.
In contrast, APT41 detections fell year on year by 50%.
Dominating groups like RansomHub are known to use AI to maximise the speed and volume of their attacks, compared to state actors like APT41 that limit AI to supportive tasks, preserving a human-led approach.
Top five threat actors detected:
- LockBit
- RansomHub
- Lazarus Group
- DarkSpectre
- Midnight Blizzard (also known as APT29, Nobellium or Cozy Bear)
Dwell times surge as adversaries outmanoeuvre detection
Threat actors are maintaining a prolonged, quiet presence within enterprise networks, leaving organisations to find out they are compromised only after the damage is done.
- Adversaries had access to enterprise networks for nearly two and a half weeks on average before being detected in ransomware incidents.
- Forty-nine percent of organisations did not detect the threat until after data was stolen, up from 31% last year.
- Fourteen percent were unaware of an attack until they received a ransom demand, compared to 6% last year.
Prolonged dwell times often parallel a highly complex threat environment where critical alerts are obscured. When asked what delayed a critical alert from being detected or investigated, respondents cited several key factors:
- Attackers used encrypted channels to bypass detection (41%)
- Attacker activity mirrored legitimate, authorised workflows and processes (38%)
- Adversaries used valid, high-privilege account permissions (34%)
- Alert fatigue caused the initial detection to be deprioritised (30%)
- Undetermined baseline behaviour enabled anomalous actions to go undetected (27%)
Threat actors trade max payouts for more payouts
While the average ransom payment dropped year on year, down to US$2.8 million from US$3.6 million in 2025, the frequency of payments rose sharply. According to this year’s respondents, 83% of victims paid a ransom, compared to 70% previously.
Downtime per incident averaged almost 30 hours. Across the cybersecurity industry, the mounting financial and operational toll of this business disruption is widely recognised as a primary reason why organisations ultimately choose to pay.
AI security tooling falls short of ‘Machine-Speed’ promise
While many organisations are turning to AI and agentic security operations, the majority of respondents reported needing mid-to-high levels of manual intervention across the entire threat lifecycle:
- Detection (42%)
- Alert triage (43%)
- Investigation (49%)
- Response (47%)
Because of these persistent manual demands, strategic security initiatives are frequently sidelined. The report found that SOC analysts are limited to spending just 44% of their time on proactive efforts like threat hunting and detection engineering, leaving the bulk of their hours dedicated to reactive triage and manual data gathering.
AI implementations are occasionally adding to this noise rather than clearing it. Nearly a third (30%) of respondents stated that AI-generated alerts have produced false positives that have negatively impacted their overall investigation timelines.
“When you look at the big picture of modern cyber-risk, the thread connecting every major challenge, from missed detections and prolonged dwell times to AI false positives, is a fundamental lack of situational awareness or ground truth,” said Raja Mukerji, Co-founder and Chief Scientist, ExtraHop.
“As threat actors leverage AI to scale their operations, defenders are countering with automated operations that don’t have the context required to make definitive decisions. The network bridges this critical gap, revealing exactly how threats are moving and communicating so security teams have the full picture. Until we enrich our security tooling and AI agents with deep, real-time network context, attackers will continue to have the upper hand.”

