Cybercrime has evolved into an industrialised criminal economy powered by frontier AI, specialised criminal services and hidden infrastructure, according to a new report from Infoblox, a leading platform for preemptive security and critical network services.
The 2026 Threat Landscape Report, drawn from trillions of DNS queries and billions of underground criminal transactions, found that attackers are now operating faster, scaling more efficiently and evading traditional defences than in previous years. Infoblox Threat Intel said the shift is compressing the time defenders have to respond and exposing the limits of conventional detect-and-respond security strategies.
Disposable infrastructure drives cybercrime scale
The report examined cybercrime across four dimensions: the industrialised services powering attacks at scale, the hidden infrastructure enabling evasion, the evolving lures reaching victims, and the expanding attack surfaces opening new footholds inside enterprises.
- Nearly 25 percent of 120 million newly observed domains were high or critical risk, reflecting the scale of disposable infrastructure fuelling modern cybercrime.
- Traffic distribution systems (TDSs) were the single most prevalent threat, impacting more than 95 percent of networks.
- 88 percent of threat-related domains were observed in only one customer environment, and 44 percent were active for just a single day.
- 65 percent of Infoblox Threat Defense customers queried domains associated with residential proxy networks, which attackers use to disguise malicious activity as legitimate consumer traffic.
- Scam-related domains rose 62 percent year-on-year, driven primarily by brand impersonation, identity theft and financial fraud.
The findings point to a growing reliance on short-lived, weaponised domains designed to outpace defenders, rather than more sophisticated attack techniques.
Sophisticated capabilities now widely accessible
“This year’s report documents the cybercrime machine, a globally connected criminal economy where frontier AI, specialised criminal services and hidden infrastructure have transformed how attacks are created, purchased and deployed,” said Dr Renée Burton, vice president, Infoblox Threat Intel. “The most important shift is not that attackers have become more sophisticated. It’s that sophisticated capabilities have become widely accessible, changing the pace of cybercrime and challenging security strategies built primarily around detection and response.”
Infoblox said the report underscores the need for organisations to rethink long-held assumptions about how cyberthreats emerge, spread and can be disrupted, as specialisation and shared criminal infrastructure continue to lower the barrier to entry for attackers.



Share your thoughts