Executive Concern Grows Over AI-Enabled Identity and Sector Threats in 2026
Security leaders are increasingly prioritizing AI-enabled threats, particularly those targeting identity systems, while acknowledging gaps in readiness. The Identity Underground’s 2026 Annual Pulse survey reported that 54% of executives rank AI-enhanced identity threats as their top concern for 2026, but only 3% say they are “very prepared.” Respondents cited legacy infrastructure and manual processes as key blockers, with 82% saying legacy systems actively create identity risk; NTLM was highlighted as a common weakness (61%) that can enable lateral movement, alongside rapid growth in non-human identities (e.g., API keys, service accounts) that many organizations cannot fully inventory.
In the health sector, Health-ISAC’s 2026 Global Health Sector Threat Landscape similarly elevated AI-driven attacks as the leading concern for 2026, alongside supply chain vulnerabilities, drawing on sector reporting such as its ransomware events database and indicator-sharing/alerting programs. Separately, CSO Online’s “CISO predictions for 2026” package is broader, aggregating multiple forward-looking items (including AI and cybercrime themes) rather than detailing the same identity-focused survey findings or the Health-ISAC health-sector report.

Get ahead of threats like this
Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
How this story unfolded
2 events from the most recent confirmed update back to the earliest known activity.
Identity Underground report highlights AI identity preparedness gap
A report from The Identity Underground found that more than half of executives ranked AI-enhanced identity threats as their top concern for 2026, while only a small minority felt highly prepared to defend against them. The report attributed the gap to legacy identity infrastructure, manual processes, and growing challenges around non-human identities and outdated authentication such as NTLM.
Health-ISAC publishes 2026 health sector threat report
Health-ISAC released its Annual Threat Report for the health sector, providing its 2026 assessment of the cyber threat landscape affecting healthcare organizations.
Related entities
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Sources
2 references tracked. Mallory keeps watching after this page renders.
See the full picture, correlated to your attack surface.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.


