SECURITYWEEK – The most successful breaches in 2026 are likely to exploit trust, not vulnerabilities. All courtesy of artificial intelligence (AI).
We’re going to explore how AI-assisted social engineering attacks might evolve from 2026 onward, and how cybersecurity could, and perhaps should, adapt to meet the new challenge. The threat is no longer against individuals, nor even businesses, but entire cultures.
Through 2026 and beyond, the quality of deepfake social engineering will continuously improve. Criminal professionalism will also improve. Consider SheByte, a new phishing-as-a-service (PhaaS) platform available on the criminal underground (with subscriptions costing around $200).
“It’s a phishing kit that incorporates AI-generated templates to automate the creation and management of phishing websites at scale. These toolkits are becoming more accessible, and we expect this trend to intensify throughout 2026 because criminal operators are continuing to refine and commercialize these platforms,” explains Kevin Gosschalk, founder and CEO at Arkose Labs.
He continues, “Beyond phishing sites, there are sophisticated toolkits designed specifically for fraud that can perfectly spoof voice and video. These aren’t consumer AI tools like ChatGPT being misused; these are purpose-built criminal products engineered for deception.”

With more than two decades of experience in public relations and journalism, Mike is a strategic communications leader who focuses on media relations and reputation management.