AI Speeds Up Exploitation as Ransomware Groups Fragment
IBM X-Force sees vulnerability exploitation becoming the leading cause of observed attacks while AI accelerates reconnaissance, credential theft and a more fragmented ransomware ecosystem.
X-Force Threat Intelligence Index 2026
THREAT LANDSCAPE · SECBRIEFS ANALYSISExecutive Takeaway
IBM X-Force's 2026 index points to a threat landscape where familiar weaknesses are being exploited faster rather than replaced by entirely new attack models. Exploitation of public-facing applications rose sharply, ransomware groups multiplied, and stolen credentials from AI platforms added another identity exposure path.
For security leaders, the practical message is to shorten the interval between exposure and control. Internet-facing vulnerabilities, weak authentication, software supply chains and AI-service identities now need to be managed as one connected attack surface rather than separate programs.
Key Findings
- 01
Attacks beginning with exploitation of public-facing applications increased 44% year over year.
- 02
Vulnerability exploitation accounted for 40% of incidents observed by IBM X-Force in 2025, making it the leading cause of attacks in its dataset.
- 03
Active ransomware and extortion groups increased 49% year over year while publicly disclosed victim counts also rose.
- 04
IBM observed more than 300,000 AI chatbot credentials exposed for sale, highlighting AI platforms as an enterprise identity target.
- 05
Large supply-chain and third-party compromises were nearly four times higher than in 2020.
- 06
Manufacturing remained the most targeted industry, while North America accounted for 29% of observed cases.
What the Data Says
Public-facing exploitation growth
IBM X-Force reports a 44% year-over-year increase in attacks that began with exploitation of public-facing applications.
Leading initial cause
Vulnerability exploitation accounted for 40% of incidents observed by X-Force in 2025.
Ransomware-group growth
Active ransomware and extortion groups increased 49% year over year, fragmenting the ecosystem.
What It Doesn’t Say / Limitations
The report is based on IBM X-Force incident response, threat intelligence, penetration testing and related telemetry. It is not a random sample of all cyber incidents worldwide, and sector or regional representation reflects the cases and data available to IBM.
Percentages should therefore be treated as directional indicators and tested against each organization's own exposure, technology estate and threat profile.
Why It Matters
The most important shift is operational speed. AI lowers the effort required to discover weaknesses, analyze targets and reuse established playbooks, while defenders still depend on patch cycles, identity controls and manual prioritization.
Organizations that separate vulnerability management, identity security, software supply-chain risk and AI governance can miss the attack paths that connect them. Leadership should measure how quickly exploitable external exposure can be discovered, contained and remediated.
Who Should Care
- CISOs and security leaders
- Vulnerability and attack-surface teams
- Identity and access teams
- SOC and incident-response teams
- Software and DevSecOps leaders
- Boards and risk committees
SecBriefs Assessment
IBM's strongest signal is not that AI has created a new threat universe, but that it is compressing the time available to defend familiar weaknesses. The report reinforces a shift from backlog-based security metrics toward exposure-age, exploitability and identity-path metrics.
The 300,000 exposed AI-chatbot credentials are also a useful warning: enterprise AI adoption creates another credential and data boundary that needs the same rigor as core SaaS platforms.
What To Do Now
- Prioritize internet-facing vulnerabilities by exploitability, reachability and business criticality.
- Apply phishing-resistant authentication and conditional access to high-value and AI-service accounts.
- Inventory AI tools and associated credentials, tokens, plug-ins and data access paths.
- Harden CI/CD and third-party integrations where trusted relationships can become attack paths.
- Track exposure age and time-to-remediation for critical external assets.
- Run ransomware and identity-compromise scenarios that assume faster attacker movement.
X-Force Threat Intelligence Index 2026
- Publisher
- IBM X-Force
- Published
- URL
- https://www.ibm.com/reports/threat-intelligence