Four Cyber Threats Harboring Big Plans for the Future
SecurityWeek outlines AI, supply-chain, quantum, and geopolitical cyber risks and urges continuous resilience.
A SecurityWeek commentary argues organizations should treat resilience as a continuous objective against four emerging risks. It says AI is speeding reconnaissance, scanning, and phishing, citing a May 2026 deepfake Zoom that impersonated Singapore’s prime minister and defrauded a professional of SGD 4.9 million. A cyberattack on Australia’s Mackay Sugar shut two mills and paused harvesting for 1,300 farms. The piece also warns that post-quantum migration may take five to more than 15 years, and that 2026 Iran-linked attacks damaged US energy, water, and government operations.
- A May 2026 deepfake Zoom impersonating Singapore’s prime minister stole SGD 4.9 million.
- A Mackay Sugar attack shut two mills and paused harvesting at 1,300 farms.
- Post-quantum migration may take 5–15 years; harvest-now-decrypt-later threatens long-lived data.
- Iran-linked hackers damaged US energy, water, and government operations in 2026.
Full article831 words · extracted from securityweek.com · click to collapse
Not unlike the fictional Skynet sending increasingly sophisticated ‘Terminators’ as older versions of the monster failed to achieve their earthly missions, cyberattacks are growing more persistent and automated, further testing an organization’s security maturity. To stay in tune with future risks, it has become imperative to treat resilience as an operational objective in constant flux.
Emerging Threats And Building Resilience
1. Artificial Intelligence
AI is playing both sides of the fence, arming attackers and defenders alike. AI is automating key kill chain components like reconnaissance and vulnerability scanning, compressing time-to-exploit from days to mere hours. Expect phishing emails to be more contextual and convincing; voice and video deepfakes will be more difficult to distinguish from the real thing, as will synthetic identities (fake profiles) built on real and stolen information. This is hardly a case of fear mongering. In May 2026, scammers used AI-generated deepfakes to concoct a Zoom meeting impersonating Singapore’s prime minister, defrauding a business professional SGD 4.9 million.
Mitigate AI-Driven Attacks: Organizations should take stock of existing security tools and consider mothballing those that cannot keep pace with AI-driven attacks. To state the obvious, AI attacks should be addressed with AI defenses, especially AI-based detection capabilities that catch anomalies early, before the attack fully unfolds. Also strengthen incident management, since some attacks will inevitably get through.
2. Third Parties and Supply Chains
A typical organization is supported by a web of vendors, cloud providers, and other close partners. A breach in any one of these parties can have a domino effect on operations. Attackers hide behind backdoors in vendor software and exploit unmanaged apps and APIs. This software is already running inside the organization’s own systems, so the backdoor wears a cloak of trust as opposed to being an external intrusion. Unmanaged APIs exploit a similar opening, as a vendor platform already has permission to access systems directly. The fallout of such an intrusion is not restricted to the primary organization alone. It spreads its tentacles across the larger supply network. This is evident from a cyberattack on Australian manufacturer Mackay Sugar. The direct impact was that it shut down two mills and forced 1,300 farms to pause harvesting.
Strengthen Vendor, Supply Chain Oversight: Set-it and-forget-it vendor relationships should yield to transparency demands backed by continuous monitoring. Build a vendor ranking scorecard based on the sensitivity of the data they manage. Prioritize security resources for high-risk vendors with only the most necessary access privileges. Insist on robust security-centric contracts and hard metrics that track third-party risk exposure and supply chain resilience, rather than relying on periodic reviews and updates.
3. Quantum Computing
Quantum computers capable of breaking widely used public-key encryption such as RSA and ECC are still some years away. But you should be wary of the Harvest Now, Decrypt Later (HNDL) risk with long-lived data such as health records, financial information, and intellectual property. While this is a problem for the future, preparing for this scenario should begin now because post-quantum cryptography (PQC) migration is estimated to take from five to seven years for small enterprises and 12 to 15+ years for large organizations. That’s because the process involves discovering and replacing vulnerable cryptography across applications, infrastructure, hardware, and third-party dependencies rather than simply installing a software update.
Build the Post-Quantum Security Framework: Given the long migration timeframe, organizations with long-lived sensitive data should plan their migration to post-quantum cryptography immediately. Start by mapping how and where encryption is used across the business and prepare a phased roadmap for migrating to quantum-resistant cryptography before this technology becomes mainstream.
Advertisement. Scroll to continue reading.
4. Geopolitics
As global political affairs become increasingly unstable, nation-states and their proxies are threatening critical infrastructure in energy, transport, and finance. Targets include industrial control and operations systems, not just conventional IT networks. In 2026, Iran-affiliated hackers hit U.S. energy, water, and government infrastructure, causing real, operational damage. Those were the direct hits. The slower threat is the viral spread of disinformation, deepfakes, and hybrid campaigns tied to geopolitical conflicts, which have become more challenging to catch.
Geopolitical Resistance: View cyber risk from the business continuity and national-level perspective, and don’t bracket it purely as an IT issue. This calls for regular crisis simulations, improved threat intelligence, and collaboration with external agencies to share indicators of compromise. The framework should also be backed by a printed, physically secured backup of response plans that offer clear guidelines on the steps to take when systems do go down.
Managing the Threats
Understanding these risks is half the job; the real test is the response. Organizations that build a future-ready cybersecurity posture pursue resilience as a core capability on a continuous basis. This means the threats outlined here will not be neutralized with a single tool or policy. The answer resides in the resilience built across technology, governance, operations, and people. Organizations that build resilience will not impossibly avoid every attack but will be best prepared to address threats when they arise.