Skip to Main Content
Publications

Cybersecurity Awareness Month 2026: Cyber Threats Hiding in the Shadows

October is Cybersecurity Awareness Month. It is also the month when we traditionally talk about things that go "boo" in the night. Unfortunately, when it comes to cybersecurity, there is plenty to keep business leaders awake.

Most cyber threat conversations still center on two familiar villains: ransomware and business email compromise (BEC). And for good reason. Both remain significant threats, and we continue to see organizations lose substantial amounts of money or experience significant operational disruption from both. The FBI's 2025 Internet Crime Report pegged total reported cybercrime losses at $20.877 billion – a 26 percent increase over the prior year – with BECs alone accounting for roughly $3 billion. But focusing only on ransomware and BECs in 2026 is a little like locking the front door while leaving the windows open.

The threat landscape is changing quickly. Artificial intelligence (AI) is making old attacks better. Cybercriminals are finding ways around traditional multifactor authentication (MFA). Stolen credentials and session tokens can provide access without an attacker ever "hacking" the network in the traditional sense. Employees, vendors, cloud applications, and even AI tools themselves are creating new paths into an organization.

Here are some of the threats businesses should be thinking about this Cybersecurity Awareness Month.

AI Is Making Social Engineering Much More Convincing

Employees have spent years learning the telltale signs of phishing: awkward language, misspellings, strange formatting, or an email that simply does not sound like the supposed sender. AI is rapidly making that advice obsolete.

Generative AI (GAI) allows attackers to create polished, highly personalized communications using information readily available online. An attacker can learn who your CFO is, identify a vendor you use, understand the terminology of your industry, and generate a convincing email in seconds. AI can also help attackers operate across languages and rapidly customize attacks for particular employees or job functions. In most cases, the result is not a brand-new kind of cyberattack but something more dangerous: a far more convincing version of an old one.

Businesses should update security awareness training accordingly. "Look for bad grammar" is no longer much of a cybersecurity strategy. Employees should instead be trained to recognize unusual requests, independently verify changes to payment instructions, and slow down when a communication creates urgency or asks them to bypass normal procedures.

Seeing – and Hearing – Is No Longer Believing

Deepfakes and AI-generated voices take that problem one step further. Imagine receiving a Teams call from someone who looks and sounds like your CEO directing an urgent transaction, or a voicemail from a senior executive explaining why normal approval procedures need to be bypassed. The face looks right, the voice sounds right, and the request may even reference real company information – and none of it is real.

Voice cloning and synthetic video are increasingly useful social-engineering tools because they attack something businesses have historically relied upon as a security control: familiarity. Organizations must establish verification procedures for high-risk transactions and sensitive requests that do not depend solely on recognizing someone's voice, face, email address, or telephone number. For particularly sensitive transactions, a second communication channel or predefined verification procedure can make the difference between stopping an attack and explaining one afterward.

MFA Is Important. It Is Not Magic.

Few pieces of cybersecurity advice are repeated more often than a simple one: turn on MFA. That advice still holds true – but attackers have adapted.

Modern phishing kits increasingly target authentication tokens and active sessions rather than simply stealing a username and password. Adversary-in-the-middle attacks can place an attacker between a user and a legitimate login page, allowing the attacker to capture credentials and session information and potentially defeat traditional MFA protections. Other attacks manipulate legitimate authentication workflows and trick users into authorizing access themselves.

The important lesson is not that MFA does not work. It is that MFA should be a layer of security, not the entire security strategy. Organizations should consider phishing-resistant authentication where appropriate, monitor unusual authentication activity, restrict legacy authentication, review conditional access policies, and ensure that incident response procedures address compromised sessions and tokens – not merely password resets.

Your Identity May Be the New Perimeter

Many modern cyber incidents no longer begin with an attacker "breaking into" a corporate network. They begin with an attacker becoming someone the network already trusts. A stolen credential, compromised cloud account, hijacked session, malicious Open Authorization (OAuth) activity, or compromised privileged account can allow an attacker to move through cloud environments while appearing, at least initially, to be a legitimate user.

That makes identity security increasingly central to cybersecurity. Businesses should know who holds privileged access and should regularly review dormant or unnecessary accounts. Equally important is the ability to act fast – applying least-privilege principles, monitoring anomalous logins, and disabling accounts or revoking active sessions the moment something looks wrong.

Infostealers: Small Malware, Big Problem

Another threat receiving increased attention is information-stealing malware, or "infostealers." Infostealers are designed to quietly harvest valuable information from an infected device – including usernames, passwords, browser cookies, authentication tokens, cryptocurrency information, and other sensitive data. Those credentials can then be sold or used to gain access to corporate environments.

The initial infection may occur on a company device. But it may also occur on an employee's personal computer where corporate credentials have been stored in a browser. This is one reason cybersecurity can no longer be viewed exclusively as protecting the corporate network. Endpoint security, credential management, browser security, remote-access practices, and employee cyber hygiene increasingly overlap.

The Employee You Hired May Not Be Who You Think

Remote work has also created a particularly unusual cyber risk: fraudulent employees.

Threat actors – including numerous incidents associated with North Korean remote IT worker schemes – have used stolen or fabricated identities to obtain legitimate employment with U.S. companies. AI-generated photographs, fabricated résumés, identity documents, voice-changing technology, and remote-access tools can make these schemes increasingly difficult to identify. Once hired, the attacker does not need to defeat your firewall (you probably gave them credentials).

Organizations hiring remote technical personnel should consider whether existing background checks, identity verification, device-management practices, access controls, and onboarding procedures are sufficient for this new environment. Human resources (HR) and cybersecurity teams may need to work together in ways they did not five years ago.

Your Vendors Are Part of Your Attack Surface

Businesses have spent significant resources securing their own environments while simultaneously becoming more dependent on cloud providers, software as a service (SaaS) platforms, managed service providers, payment processors, and other technology vendors.

Attackers understand the math. Compromising one service provider may provide access to dozens, hundreds, or thousands of downstream organizations. Third-party risk management therefore cannot end when the contract is signed. Organizations should understand what information vendors hold, what systems they can access, how that access is authenticated, what happens if the vendor is compromised, and, critically, how quickly the organization will learn about an incident. Cybersecurity due diligence and contractual protections are becoming increasingly important components of vendor management.

This is an area where a focused outside review often pays for itself. We regularly help clients evaluate vendor risk, strengthen contractual cybersecurity protections, and pressure-test how quickly they would actually learn about a third-party breach.

AI Is Not Just Helping the Attackers – It Is Creating a New Attack Surface

Businesses are rapidly deploying AI tools, copilots, agents, and AI-enabled applications. That creates tremendous opportunity. It also creates new security questions.

What information are employees entering into AI systems? Which AI applications have access to corporate data? What can an AI agent actually do once connected to company systems? Can it send an email, retrieve files, modify records, access customer information, or interact with another application? What happens if the AI system receives malicious instructions embedded in a document, website, or other data source?

Prompt injection, excessive permissions, insecure integrations, sensitive-data leakage, and "shadow AI" are increasingly part of the cybersecurity conversation. The goal is to govern AI, not to ban it. Start by inventorying approved AI tools, establishing acceptable-use requirements, and understanding what data those systems can access. From there, evaluate third-party AI providers and apply the security principles you already trust – least privilege, access controls, logging, monitoring, and incident response – to every AI deployment.

What Should Businesses Do Now?

The biggest mistake organizations can make this Cybersecurity Awareness Month is treating cybersecurity awareness as an annual training exercise. Use October to run through a short readiness self-assessment. If you cannot answer these questions with confidence, you have found your starting point:

  • When was your incident response plan last updated – and have you actually tested it through a tabletop exercise?
     
  • Does your plan address cloud-account compromise and stolen authentication tokens, or was it written primarily for ransomware?
     
  • Do employees know how to verify unusual financial requests, and have you evaluated deepfake scenarios?
     
  • Do you know what AI tools your employees are using, and have you reviewed privileged accounts and vendor access?
     
  • Do you know who you would call at 2:00 a.m. on a Saturday if your systems suddenly went down?
     
  • And importantly, does everyone who will make decisions during an incident – information technology (IT), legal, executive leadership, communications, HR, insurance, and outside vendors – know their role before the incident occurs?

Because the worst time to figure out your cyber incident response plan is while you are living through it.

Don't Wait Until Something Goes Bump in the Network

Cyber threats will continue to evolve. The good news is that organizations do not have to predict every new attack technique to prepare for them. Strong identity controls, thoughtful AI governance, employee training, vendor management, tested incident-response procedures, and good cyber hygiene remain remarkably effective defenses even as the tactics change.

Cybersecurity Awareness Month is a good reminder to take another look at those defenses – preferably before an attacker tests them for you.

Baker Donelson's Cybersecurity and Incident Response Team regularly works with businesses to proactively assess cybersecurity risks, develop and test incident response plans, conduct tabletop exercises, evaluate emerging AI and technology risks, conduct cyber due diligence on vendors, and address cybersecurity regulatory requirements. And when an incident does occur, our team assists clients in all industries and across the country through the investigation, containment, forensic analysis, privilege considerations, regulatory and notification requirements, communications, insurance issues, and resulting enforcement actions and litigation.

If you have questions about your organization's cybersecurity preparedness, emerging cyber threats, or how to respond to an active cyber incident, please contact the authors Matt White, AIGP, CIPP/US, CIPP/E, CIPT, CIPM, PCIP and Alex Koskey, CIPP/US, CIPP/E, PCIP, or any member of Baker Donelson's Cybersecurity and Incident Response Team. We'd be happy to schedule a cybersecurity readiness review or an incident response tabletop exercise for you. And if you are facing an active incident right now, do not wait – our team is available around the clock to help you respond.

Email Disclaimer

NOTICE: The mailing of this email is not intended to create, and receipt of it does not constitute an attorney-client relationship. Anything that you send to anyone at our Firm will not be confidential or privileged unless we have agreed to represent you. If you send this email, you confirm that you have read and understand this notice.
Cancel Accept