Cybersecurity in the first half of 2026: countering cyber threats requires stronger preparedness and resourcing
The cybersecurity situation in Finland has remained stable in the first half of 2026. Although no major sudden changes took place in the threat landscape, cyber threats have evolved alongside technology and the operating methods used by attackers. The use of artificial intelligence in attacks, the increase in Microsoft 365 account compromises and supply chain risks have become key concerns in particular.
“The first half of 2026 shows that countering cyber threats must be an established part of normal operations. What matters is how well organisations can anticipate, prepare for and adapt to changes,” says Director-General Anssi Kärkkäinen from the National Cyber Security Centre Finland (NCSC-FI) at the Finnish Transport and Communications Agency Traficom.
Microsoft 365 account breaches and phishing are increasing
Microsoft 365 account compromises were among the most visible phenomena in the early part of the year. They have been detected in different sectors in both the public and private sectors. Attackers are increasingly using AiTM (Adversary-in-the-Middle) techniques, which can be used to bypass traditional multi-factor authentication by hijacking users’ session tokens. Compromised user accounts are used in further attacks and phishing campaigns, which extends the impact of the attacks from one organisation to another.
At the same time, various online scams and phishing have continued actively. Criminals use current events, official communications and seasonal topics, such as tax refunds and Black Friday sales, to create credible scam messages in order to steal user credentials and payment information.
“Microsoft 365 account compromises and phishing remain key cyber threats, and the methods used to carry them out have become more difficult to detect than before. Attacks based on bypassing login protections particularly highlight the importance of strong authentication solutions and user vigilance,” says Director-General Kärkkäinen.
AI changes the nature of cyber threats
Artificial intelligence has become one of the most significant factors affecting cybersecurity internationally in 2026. Attackers use artificial intelligence to search for vulnerabilities, automate attacks, conduct reconnaissance and produce credible phishing messages. This speeds up the preparation of attacks and increases their effectiveness.
At the same time, AI systems have become a new target of attacks. Attackers may try to mislead AI solutions by feeding them false or manipulated information, which may lead to incorrect decisions, data leaks or weakened security controls. Supply chain attacks targeting AI systems have also become a new risk factor.
Generative AI has also made scams and social engineering more convincing than before. Attackers can build trust with their target over a long period of time and use AI-generated content in phishing, scams and information influence activities. Advances in deepfake technology further increase the opportunities for spreading false information.
“Although artificial intelligence increases attackers’ opportunities, it also offers major benefits to defenders. Artificial intelligence can be used to detect anomalies, analyse log data, identify threats and find vulnerabilities. However, at least for the time being, artificial intelligence does not replace experts. Its safe use requires continuous monitoring, competence and risk management,” Director-General Kärkkäinen points out.
Cyber attacks exploit even the smallest weaknesses
Malware has remained a key threat, and attackers are increasingly combining phishing, software vulnerabilities and supply chain attacks to spread it.
The number of vulnerabilities detected in software and network devices has grown significantly in recent years. This is particularly affected by advances in the use of artificial intelligence to find vulnerabilities. The exploitation of vulnerabilities has become significantly faster, even during the past year. Exploitation often begins very soon after vulnerabilities are disclosed, or even before disclosure.
The growing number of vulnerabilities also challenges preparedness, as organisations have to use more resources to identify vulnerable systems and patch vulnerabilities.
“Rapidly fixing vulnerabilities, regularly updating systems and devices and taking care of devices throughout their life cycle are key ways to manage risks. Preparing for phishing and continuously monitoring supply chains and systems also strengthen cybersecurity,” Kärkkäinen points out.
Supply chain risks are becoming more prominent as organisations’ dependencies increase. Attackers seek to exploit software suppliers, cloud services and other third parties to gain access to their actual targets. Poorly protected IoT devices also form a growing attack surface that can be used in botnets and denial-of-service attacks, for example.
“As supply chains and digital dependencies grow, the attack surface also expands. A single weakness in a software supplier, cloud service or IoT device can open a path into the entire organisation,” says Director-General Kärkkäinen.
Risks related to network edge devices remain a significant threat to organisations
The information security risk posed by poorly protected network edge devices has become more prominent in recent years, and the NCSC-FI has published several items on the subject. Network edge devices refer to devices that transmit traffic between a person’s or organisation’s own network and the public internet, such as VPN gateways, firewall devices and routers.
The visibility and openness of edge devices to the internet creates a large attack surface for malicious actors. Vulnerabilities and errors in device configurations, together with compromised login credentials, are the most significant factors that expose devices to compromise. State-sponsored threat actors and cybercriminals may also use compromised network edge devices to carry out cyber espionage or denial-of-service attacks, for example.
The latest example of this is the international joint operation to dismantle infrastructure used by Russia’s military intelligence service for cyber espionage. The NCSC-FI participated in the operation in April together with the Finnish Security and Intelligence Service.
Preparedness is decisive
The NCSC-FI emphasises the importance of proactive preparedness. Organisations must identify risks in good time, maintain an up-to-date situational picture and develop their ability to respond to rapidly changing threats. Key measures include quickly fixing vulnerabilities, deploying strong authentication solutions, continuously monitoring systems, developing detection capabilities, training personnel and managing risks related to supply chains and AI systems. Maintaining basic cyber hygiene is the foundation of preparedness.
“Maintaining cybersecurity requires comprehensive risk management, sufficient resourcing, the development of technical protections, strengthening personnel competence and the ability to adapt to a rapidly changing operating environment. Preventing cyber attacks is also considerably less expensive than repairing their impacts,” Kärkkäinen points out.
The importance of cybersecurity is becoming even more pronounced as digitalisation advances and services become increasingly interconnected. At the same time, anticipating cyber threats and preparing for them have become a key part of the operational reliability of organisations and society as a whole.
“The NCSC-FI at Traficom supports the safe functioning of the digital society by providing organisations and citizens with an up-to-date situational picture, alerts and guidance. The aim is to strengthen society’s ability to prevent, detect and manage cyber threats in cooperation with different actors,” says Director-General Kärkkäinen.
Enquiries: Traficom media service, tel. +358 29 534 5648