Q2 2026 Threat Report: Same Adversaries, Faster Tooling


KasadaIQ tracked 27 threat predictions through Q2 2026. Nine advanced and none were refuted, all clustering around AI adoption, credential markets, and bot economics, while the adversaries' underlying motivations stayed the same.

KasadaIQ

1. Q2 2026 Threat Report: Same Adversaries, Faster Tooling

The Q2 2026 Quarterly Threat Report from KasadaIQ tracked 27 predictions through the quarter. Nine moved, none were refuted, and the movement clustered exactly where an accelerating market would put it: AI adoption, credential markets and the economics of bot operations. The predictions that advanced describe a market getting cheaper and faster to enter, not one changing its fundamental character.

That is the finding that ties the whole quarter together. AI is changing how adversaries work, not who they are or why they do it. In every section of the report, the same population of adversaries kept doing familiar work with better tooling.

Q2 2026 prediction tracker: 27 tracked, 9 moved, 18 held steady, 0 refuted

The economics make the case directly. A newcomer can become fully operational in the bot ecosystem for $400 to $500, roughly 94% of the operators KasadaIQ can classify rent their capability rather than build it, and clean residential proxies now sell from $0.30 per gigabyte, which means IP reputation no longer separates malicious traffic from legitimate. In one public demonstration this quarter, an AI model defeated a commercial licensing system in under five hours for $3.88 in API credits. The barrier to entry is now financial far more than technical.

The criminal account market shows the same theme from a different angle. KasadaIQ tracked 6,076 active sellers against 6,189 the previous quarter, with 97.6% carrying over, so the population held steady even as observed sales volume fell. The market did not shrink; it concentrated on thinner, higher-value inventory, and average prices rose across most industries. The tooling tracked that shift. Among roughly 77 malicious configurations analyzed this quarter, the most complex one captured 24 distinct account fields on login, appraising an account's resale value rather than simply confirming access.

Criminal marketplace activity for legitimate AI accounts told a parallel story. What looked like a spike last quarter has consolidated into a steady, high-volume market, with more than 14,000 AI account sales in Q2, close to 94% of them ChatGPT products, priced from $7 to $60 depending on access and duration.

Even the FIFA World Cup fit the pattern. Fraud tracked the official ticketing calendar rather than the match schedule, with inventory staying dormant until each on-sale opened and established operators redirecting standing tradecraft toward the tournament. The event served as a lure for existing fraud rather than a source of new fraud.

Underneath all of it is a human decision, which is where the report closes. The Spotlight applies a 70-year body of fraud research to the operators behind the tooling and finds that their motivation and rationalization have barely moved, even as AI reshapes their capability.

The report covers each of these in depth. The through line for defenders is that calibrating to this quarter's tooling means missing next quarter's. The durable signal is the motivation and rationalization that do not change.

Download the report: Access the report

2. The Psychology of a Fraud Enabler: AI Re-Equipped an Old Adversary, It Did Not Create a New One

Cybersecurity gets treated as a technology problem. The attacks are technical, the defenses are technical and the vendor language is technical. Every attack, though, starts with a person deciding to act. This quarter KasadaIQ built a model for that decision and applied it to a live adversary community, to see what AI is actually changing about the people behind the tooling.

The model is the Fraud Enabler Diamond. It adapts more than 70 years of fraud research, starting with Donald Cressey's 1953 study of why people commit fraud, into a frame for a different kind of actor: the external operator who does not commit the fraud but builds and sells the capability that lets others do it. Their relationship to the victim is commercial supply rather than betrayed trust, so the classic models needed reframing. The Diamond has four elements: motivation, opportunity, capability, and rationalization.

The Fraud Enabler Diamond: motivation, opportunity, capability, rationalization

Motivation is the set of forces that make selling capability worth the risk: economic pressure, lifestyle costs, status, and ego. Across both cohorts KasadaIQ observed, one established over years and one arriving with AI in 2026, this looked the same. Operators describe services that pay their rent and more, and frame legitimate six-figure tech jobs as not worth their time.

Opportunity is the structural conditions that let an operator work without consequence: a widening attack surface, weak security on targets, structured deniability, and favorable legal conditions. This is where AI is genuinely changing the picture. The attack surface has expanded with enterprise adoption of agentic AI, and the community's 2026 engagement concentrated heavily on AI, anti-bot techniques, and monetization.

Capability is what the operator brings to act on that opportunity: skill, tooling, and the network behind it. This is the second element AI moved, and it is where the two cohorts diverge most. The established cohort runs on deep technical skill built through long practice and high-trust networks. The emerging cohort produces high output through LLM-assisted development, wider but shallower community reach, and tooling aimed straight at the seam where AI meets verification.

Rationalization is the publicly available set of arguments an operator uses to reconcile the work with their self-image: grey-zone framing, no direct link to victims, an us-versus-them stance toward defenders, and the absence of KYC treated as a feature of the trade rather than a choice. Like motivation, this held steady. One cohort keeps its disclaimer architecture quiet inside trusted channels; the other builds it in public behind commercial frontage. The underlying argument is identical.

Line the four elements up and the pattern is clear. AI moved opportunity and capability. Motivation and rationalization did not move, and they have not moved in 70 years. The operator entering the market today is recognizable as the same kind of person Cressey described in 1953, with faster tooling and a wider surface to work.

That is the practical value of the Diamond. Defenders who calibrate to a cohort's capability will miss the next cohort, because capability is the element that keeps turning over. Defenders who calibrate to the motivation and rationalization shared across both will keep pace.

Download the report: Access the report

3. A Market of Buyers, Not Builders

In a public demonstration this quarter, researchers pointed a commercial AI model at a piece of protected software and defeated its licensing system in under five hours, for $3.88 in API credits. The work ran on a maturing open-source toolchain that wires AI directly into reverse-engineering platforms, with projects drawing thousands of users. The model did the grinding analytical work that would cost a skilled human days, while a person framed the task, pointed the tooling, and used the result.

Read that number as the headline for the quarter's clearest trend. The barrier to online fraud is now financial far more than technical, and the cost of capability is what collapsed. The going rates are modest and well understood inside the market; a fully equipped newcomer can set themselves up for $400 to $500 with no development of their own.

Underneath the price list is a two-tier structure. A thin frontier tier produces the genuinely hard capability, the bypass, the proxies, and the credentials. A services layer rents that work downmarket as cheap, off-the-shelf product. Roughly 94% of the operators KasadaIQ can classify sit in the second tier as buyers rather than builders. Solver-API subscriptions are the clearest example. They package sophisticated bypass work and rent it cheaply, compressing the capability gap on established defenses even while frontier reverse-engineering stays exclusive and expensive.

The infrastructure is commercializing evasion in ways that reach into consumer devices. Researchers showed how a proxy provider's SDK, embedded in ordinary consumer apps, turns a user's phone or smart TV into an exit node for scraping traffic sold on to the AI industry. User consent is technically present but poorly informed. The result is a deep, renewable pool of residential IP addresses that look exactly like real customers.

None of this points toward a single sophisticated adversary. It points toward a broad, well-supplied buyer market, which changes what effective defense looks like. Friction-only strategies assume that enough resistance will make an operator give up, and that assumption only holds when the work is barely worth doing. When a single rented operation pays for rent and more, friction gets absorbed as a cost of doing business.

The leverage sits elsewhere. With most operators renting rather than building, breaking solutions faster than they can be re-rented degrades service across the entire buyer tier at once. One broken solver strands every customer relying on it. Frequent challenge resets raise the maintenance burden on the sellers who supply the market. Beyond that, the durable pressure sits at the infrastructure, legal, and payment-rail layers, where the cost of doing business can be raised in ways that friction alone cannot.

Download the report: Access the report

Defeats threats 
not your customers

Start deploying today