[Blog](/blog)

Show links

Resources

[Blog](/blog)

[Breaches](/breaches)

[eBooks, reports, & more](/resources)

[Events](/events)

[News](/news)

[Cybersecurity](/category/cybersecurity)

Show links

Categories

[Attack Surface Management](/category/attack-surface-management)

[Company News](/category/company-news)

[Compliance and Regulations](/category/compliance-and-regulations)

[Cybersecurity](/category/cybersecurity)

[Data Breaches](/category/data-breaches)

[DevOps](/category/devops)

[Human Cyber Risk](/category/human-cyber-risk)

[Risks and Vulnerabilities](/category/risks-and-vulnerabilities)

[Third-Party Risk Management](/category/third-party-risk-management)

[Vendor Risk Management](/category/vendor-risk-management)

[Cybersecurity Predictions for 2026: Human Risk, AI Data Leaks, and the Next Big Breach](/blog/cybersecurity-predictions-2026-human-risk-ai-data-leaks)

Publish date

July 2, 2026

{x} minute read

# Cybersecurity Predictions for 2026: Human Risk, AI Data Leaks, and the Next Big Breach

[Get a demo](/contact-sales)

[Free trial](/demo)

[Download the PDF guide](#)

[Free trial](/demo)

Written by

[Greg Pollock](/team/greg-pollock)

Director of Research and Insights

Greg is a CISA-certified cybersecurity researcher who holds multiple patents for data leak detection. His findings have been featured in The New York Times, Forbes, and Wired.

Reviewed by

[Kaushik Sen](/team/kaushik-sen)

Chief Marketing Officer

Kaushik has a background in software engineering, enterprise solution architecture, and data analytics. He brings a unique, data-driven perspective to cybersecurity education.

Table of contents

Free resource

###

[Download now](#)

Looking back at 2025, two mega-trends from the past have continued: First, data breaches remained a constant and continued to trend upward; and second, there was once again a headline disaster no one anticipated. 

The first point needs no elaboration; data breaches are like air pollution—an accepted nuisance that only occasionally becomes so severe that we wonder why we live like this. For the second point, I gesture toward the major incidents of recent years. MoveIt. Crowdstrike. Snowflake. Now, Salesforce. By definition, we were not prepared for these problems. On their own, these are each singular disasters, but over the course of years, a pattern has emerged. Something big is going to happen, again. 

Looking ahead to 2026, we aim to identify the sweet spot of events that are likely yet unexpected. Anything that is obviously correct is not interesting; that’s the domain of statistical regression, not strategic extrapolation. These four predictions may not be right, but hopefully they at least make you see our present a little differently.  

## 1. We are on the cusp of a renaissance in human risk management

There are two trends in the threat environment that will drive innovation in human risk management. First, we have the rise of [advanced persistent insider threats](https://www.anthropic.com/news/detecting-countering-misuse-aug-2025). We aren't talking about a rogue employee with a gambling debt; we are talking about state-level adversaries with long-running campaigns who have [already been successful in infiltrating](https://www.microsoft.com/en-us/security/blog/2025/06/30/jasper-sleet-north-korean-remote-it-workers-evolving-tactics-to-infiltrate-organizations/) scores of Fortune 500 companies. 

Second, there is good evidence that security awareness training needs to be rebuilt from the ground up. Employees, heck, everyone, including your kids and parents,need education about information technology risks. But [mandatory checkbox training does not improve security outcomes](https://cs.uchicago.edu/news/new-study-reveals-gaps-in-common-types-of-cybersecurity-training/). How could it? If that's actually how human behavioral modification worked, everyone who saw an ad for Jenny Craig would have lost ten pounds. 

Instead, decades of scientific research eventually gave us something that does work: Ozempic and next-generation GLP-1s. We need an Ozempic for cybersecurity. And like the long arc of research that delivered GLP-1s, the size of this market means that we’ll eventually we'll get it. 

## 2. The total compromise of US infrastructure can’t be swept under the rug 

Speaking of data breaches at big organizations, the last year has seen the discovery of several cases where APTs had access to systemic US infrastructure for months or years. "There's a good chance this espionage campaign has stolen information from nearly every American," said [the deputy assistant director for the FBI](https://www.theregister.com/2025/08/28/fbi_cyber_cop_salt_typhoon/) about the Salt Typhoon campaign that compromised around 200 organizations, including the U.S.’s principal telcos, AT\&T and Verizon. 

While it's certainly better to have the attackers out, it's hard to believe the fallout has been fully remediated. The attackers didn’t just steal some collection of data; they were able to intercept virtually any communication for years. Just this year, attackers were able to use credentials stolen from Gainsight in one attack to launch another campaign on Gainsight’s customers. When we play that pattern out to everyone in America, it feels like we have not heard the last of this breach. 

Although that may be overstating the real impact. Year over year, data breaches have been increasing. The future may be much like the past: an ever-increasing number of data breaches and identity thefts. Perhaps the biggest change will be that we can no longer act surprised. 

## 3. Platform power success stories are tomorrow’s targets

An influential business strategy to emerge from Web 2.0 was the idea of [platform power](https://stratechery.com/2015/aggregation-theory/)—that by aggregating some otherwise disparate resource, a business could offer sufficient value to everyone who wanted that resource to also extract some portion of the value for themselves. Google’s search engine is the epitome of this pattern: everyone wants to find things on the internet, Google is the product through which users do that, and thus Google is able to take a tiny cut of the total value of internet traffic (which happens to total billions of dollars). 

The businesses that have succeeded as platforms, through which large amounts of value pass, have also created enticing targets for attackers. In years past, we saw the beginnings of this year in[ Cl0p attacks on file transfer appliances](https://cyberscoop.com/clop-cleo-file-transfer-software-breach-fin11/). These are not platforms with the prestige of Google, but they are gateways through which large amounts of value, in the form of sensitive data, pass. 

In 2025, we saw the attack pattern expand to one of the great tech platform companies: Salesforce, the largest provider of software for managing customer sales information. Through various means (social engineering, stolen credentials, and third-party integrations) hackers pilfered Salesforce instances throughout the year. 

The throughline from MoveIT to Salesforce is platform power. Despite very different tactics (zero-day vulns versus social engineering and stolen creds), these attacks share a common form. By aggregating value, companies have benefited themselves, but they have also created a treasure map for attackers. 

## 4. AI will keep leaking data, but not the way you think. 

2025 has been filled with regular announcements of new methods to compromise the integrity of AI tools. That will continue because there is no way to stop it. The premise of AI tools is that they accept arbitrary inputs, and the premise of productivity tools is that they can read and/or write to important data sources. If you allow arbitrary inputs into a system that can execute code…Well, I can’t help you there. But that’s not even the real problem. 

While AI vulnerabilities will surely be weaponized at scale in the near future, we will also continue to see the problem we already have: AI systems leaking data the old-fashioned way. We think of AI models as the transmission method from inappropriate sensitive inputs to leaked data in outputs, but the actual vector for AI leaks is system misconfiguration. 

Multiple AI chat apps have leaked user conversations from [Elasticsearch](https://hipaatimes.com/ai-chatbot-apps-leak-user-prompts-and-tokens-in-massive-data-exposure) databases or [Kafka](https://cybernews.com/security/ai-girlfriend-app-leak-exposes-400k-users/) brokers. There was also the [Deepseek database](https://www.wiz.io/blog/wiz-research-uncovers-exposed-deepseek-database-leak) left without a password. Or, in 2023, the Microsoft exposure from a [misconfigured cloud storage bucket](https://www.wiz.io/blog/38-terabytes-of-private-data-accidentally-exposed-by-microsoft-ai-researchers). All of those are classic, pre-AI problems that continue to be the most common method for AI data leaks. 

Plus, you have all the new AI-supportive technologies, which also allow misconfigurations leading to the exposure of sensitive data: [Langflow](https://www.upguard.com/breaches/workcycle-tpl-langflow-leak-pakistan), [Flowise](https://www.upguard.com/blog/downstream-data-investigating-ai-data-leaks-in-flowise), [Chroma](https://www.upguard.com/breaches/chroma-my-jedai-canva), [LlamaIndex](https://www.upguard.com/blog/data-leakage-and-other-risks-of-insecure-llamaindex-apps), Streamlit, and [llama.cpp](https://www.upguard.com/blog/llama-cpp-prompt-leak) to name a few. 

AI data leaks will continue to be in the headlines, but the articles will be about misconfigured databases. 

> If AI data leaks are inevitable, guidance is the answer, not blanket bans. The UpGuard AI Security Center provides security teams with a practical path for safe AI adoption. AI Insights help to build understanding of where data is likely moving, an AI Policy Toolkit to set rules people can follow, and an AI Risk Check (coming soon) to vet tools before they're trusted.\
> \
> [Explore the AI Security Center →](https://www.upguard.com/solutions/ai-security)

Free resource

###

[Download now](#)

## Related posts

Learn more about the latest issues in cybersecurity.

Cybersecurity

#### [12 Cybersecurity Horror Stories of 2026 (No Costume Required)](/blog/cybersecurity-horror-stories-2026)

A warning ignored once becomes a headline. Read more about these 12 real 2026 cybersecurity incidents, and the sign each one gave before it made the news.

[](/team/revashni-moodley)

[Revashni Moodley](#)

September 28, 2026

Cybersecurity

#### [Left Unsupervised: 10 Times Access Outlived Its Authorization](/blog/10-times-access-outlived-authorization)

Access granted once shouldn’t mean access forever. Read more on how unmonitored access caused 10 of these real-life breaches and what they taught us.

[](/team/revashni-moodley)

[Revashni Moodley](#)

August 25, 2026

Cybersecurity

#### [Surviving a LockBit Ransomware Attack: The ROI of Visibility](/blog/surviving-a-lockbit-ransomware-attack)

Read how veteran CISO Nick Gicinto saved his alma mater from a LockBit ransomware attack by discarding the standard playbook.

[](/team/nicholas-sollitto)

[Nicholas Sollitto](#)

June 1, 2026

Cybersecurity

#### [Top 10 Security Events of 2025](/blog/top-security-events-of-2025)

Recap the ten most impactful events that reshaped the cybersecurity industry this year and the critical lessons each had to teach us. Read more here.

[](/team/revashni-moodley)

[Revashni Moodley](#)

January 7, 2026

Cybersecurity

#### [Risk Automations: The Shift From Catch-Up to Command](/blog/risk-automations-shift-catch-up-to-command)

Connect intelligence to system execution with Risk Automations, your new resolution layer for risk. Reduce remediation from hours to seconds - read more.

[](/team/revashni-moodley)

[Revashni Moodley](#)

December 1, 2025

Cybersecurity

#### [Shai-Hulud's True Lesson for CISOs: A Crisis of Communication](/blog/shai-hulud-lesson-for-cisos)

Shai-Hulud was driven by a communication crisis between security and engineering. Get a CISO's perspective on how to finally bridge this gap.

[](/team/phil-ross)

[Phil Ross](#)

September 3, 2026

[All posts](/blog)

Experience superior visibility and a simpler approach to cyber risk management

[Get a demo](/contact-sales)

[Free trial](/demo)
