Cybersecurity 2026

USA Trends and Developments Contributed by: Brock Dahl, Beth George, Timothy Howard and Megan Kayo, Freshfields

realistic deep fakes that are extremely difficult to dis - tinguish from the actual individual. This allows a threat actor to appear to be a trusted individual requesting or approving actions taken by personnel. As a result, individuals authorised to access systems may do so in a manner that furthers threat actors’ campaigns. Once threat actors have gained a foothold in the envi - ronment, they can use AI tools to identify valuable data, such as personal data, proprietary customer data, or IP, much faster than humans would be able to. With the aid of AI tools, threat actors can quickly steal this data and launch extortion attempts against companies far faster than was previously possible. Additionally, threat actors can use AI tools to iden - tify systems with recently discovered vulnerabilities that can be exploited before target companies have a chance to remediate (and sometimes, even before a patch is available). These are examples of how threat actors are leverag - ing AI tools to improve and expedite certain steps in a cyber-attack. However, there have also been reports of AI agents being used by threat actors to launch cyber-attacks with minimal human involvement. For example, threat actors believed to be associated with China were able to circumvent safeguards built into an AI agent by impersonating penetration testers, iden - tifying vulnerabilities to help companies strengthen their security controls. In this way, the threat actors were able to bypass the model’s safeguards and attempted to infiltrate several companies. The extent of human involvement was the threat actor confirm - ing that the AI agent should proceed at a handful of junctures; otherwise, the agent proactively executed the attacks. In a display of commendable transpar - ency, the AI developer whose platform was abused publicly reported the activity to raise awareness of the current threat. Quantum Computing Threatens Present-Day Encryption Methodologies While agentic AI is a tool currently leveraged by threat actors, quantum computing poses a significant, long- term threat to current cryptography methods, which are an integral component of any security program. The primary risk today is the “harvest now, decrypt

later” attack, in which adversaries capture and store encrypted data today with the expectation of decrypt - ing it once a cryptanalytically relevant quantum com - puter is built. This poses a significant risk for organisations that are securing sensitive data with cryptography that is cur - rently difficult to crack, but that quantum computing will be able to decrypt in the future. Legal frameworks mandating “state-of-the-art” or even “reasonable” security measures may be interpreted as requir - ing stronger encryption methodologies. As a result, organisations would be wise to develop a strategic roadmap for migrating to post-quantum cryptography. Organisations operating in regulated sectors, such as healthcare covered entities and financial services, where the security of protected health information and digital ledgers is mandated by regulation, could sig - nificantly increase compliance and business risk with advances in technology. A Turbulent Geopolitical World Driving State- Sponsored Cyber-Attacks If new technologies help explain how cyber-attacks are evolving, the current volatile geopolitical land - scape helps explain why nation-states and their affili - ated groups are increasingly launching cyber-attacks to achieve geopolitical objectives. For example, sanc - tioned regimes, such as North Korea, Russia and Iran, have operationalised cybercrime as a way to circum - vent international sanctions, generate revenue, and fund their military programs, as well as attack critical infrastructure and disrupt operations of their adver - saries. In other countries, such as China, corporate espionage is the driving force behind stealthy, perva - sive cyber-attacks. An especially prolific example of state-sponsored cybercrime for financial gain is the campaign out of North Korea to infiltrate companies, posing as highly- skilled outsourced IT workers. Using stolen or fabri - cated identities and leveraging AI tools to generate deepfakes during the interview process, these indi - viduals have been contracted to provide remote IT services at numerous companies. Once hired, these IT workers may possess legitimate, trusted access to an organisation’s crown jewels, such

475 CHAMBERS.COM

Powered by