Infoblox Releases 2026 Threat Landscape Report, Exposes the AI-Powered Cybercrime Economy Behind Modern Attacks
Key Highlights:
- Nearly 25% of newly observed domains were classified as high or critical risk.
- AI, criminal marketplaces, and hidden infrastructure are accelerating cyberattacks.
- Scam-related domains surged 62% year over year.
- More than 95% of networks encountered traffic distribution systems (TDSs).
Infoblox, a leader in preemptive security and critical network services, has released its 2026 Threat Landscape Report, revealing how cybercrime has evolved into an industrialized, AI-powered economy that enables attackers to launch faster, more scalable, and increasingly evasive cyberattacks.
The report highlights how frontier AI, specialized cybercrime services, and hidden digital infrastructure are transforming the threat landscape, significantly reducing defenders' response time while exposing the limitations of traditional detect-and-respond security models.
Based on trillions of DNS queries, billions of underground criminal transactions, and extensive threat intelligence research, Infoblox identifies four key dimensions shaping modern cybercrime:
- Industrialized cybercrime services that enable attacks at scale.
- Hidden infrastructure used to evade security controls.
- Sophisticated social engineering and phishing lures targeting victims.
- Expanding enterprise attack surfaces creating new entry points for attackers.
Key Findings from the 2026 Threat Landscape Report
- Nearly 25% of the 120 million newly observed domains were classified as high or critical risk, highlighting the widespread use of disposable malicious infrastructure.
- Traffic Distribution Systems (TDSs) were the most common threat, affecting more than 95% of enterprise networks by redirecting victims to malware, phishing, and scam websites.
- 88% of malicious domains appeared in only a single customer environment, while 44% remained active for just one day, demonstrating the growing use of short-lived infrastructure designed to evade detection.
- 65% of Infoblox Threat Defense customers queried domains associated with residential proxy networks, allowing attackers to disguise malicious traffic as legitimate consumer internet activity.
- Scam-related domains increased by 62% year over year, fueled by brand impersonation, identity theft, and financial fraud campaigns.
"This year's report documents the cybercrime machine—a globally connected criminal economy where frontier AI, specialized criminal services, and hidden infrastructure have transformed how attacks are created, purchased, and deployed," said Dr. Renée Burton, Vice President of Infoblox Threat Intel. "The most significant change isn't that attackers have become more sophisticated; it's that sophisticated cyberattack capabilities have become widely accessible, fundamentally changing the speed and scale of cybercrime."
The report concludes that cybercrime has evolved into a highly interconnected ecosystem powered by automation, specialization, and shared infrastructure. As these capabilities become more accessible, organizations will need to adopt proactive, intelligence-driven security strategies that go beyond traditional detection and response to stay ahead of emerging threats.


