predictive threat intelligence

CYBER PERSPECTIVES:

Threat Predictions

& Confirmations

Accelerate Sharply in 2026

Our analysts have been tracking a significant jump in Augur predictions and confirmations through 2026. Examining the data across 2024, 2025, and the first five months of this year, a clear pattern emerges: year-on-year growth is accelerating. Third-party confirmations, which occur when traditional threat research independently verifies a malicious actor Augur had already flagged, rose 22% from 2024 to 2025 and are on pace for a 65% jump in 2026. In more than ten years of identifying malicious infrastructure, we have not seen growth at this rate. One factor that appears to be driving this acceleration is the rapid adoption of AI by threat actors, enabling faster development, operationalization, and iteration of attack campaigns. So let’s take a look at what the broader research community is saying about how AI is affecting the cybersecurity landscape and what trends we’re seeing in our Augur data.

The AI Acceleration

The cybercriminal ecosystem has undergone a fundamental shift. What once required nation-state resources, sophisticated phishing campaigns in multiple languages, rapid weaponization of newly disclosed vulnerabilities, large-scale credential attacks, and surgical target selection based on financial intelligence can now be executed by modestly skilled actors armed with little more than a jailbroken large language model and a dark web subscription. 

The evidence is unambiguous and comes from the most authoritative sources in the industry. 

  • CrowdStrike's 2026 Global Threat Report documents an 89% year-over-year increase in attacks by AI-enabled adversaries
  • Microsoft flagged increased use of AI by nation-state threat actors for spear phishing, résumé swarming, and deepfakes (MDDR 2024).
  • The Verizon DBIR 2026 found that the median time-to-click on AI-crafted phishing lures dropped to under 60 seconds
  • in February 2025, Google's Threat Intelligence Group confirmed that more than 57 distinct threat actor groups had attempted to misuse its Gemini AI platform, not to invent new attack categories, but to do what they already did, faster and at greater scale

The acceleration is measurable at every stage of the attack chain. AI is compressing the time from initial compromise to lateral movement: CrowdStrike now records a fastest-ever eCrime breakout time of just 27 seconds, down from over two minutes in 2023, a 98% reduction in just three years. IBM's X-Force Index found a 71% increase in cyberattacks using valid credentials, as AI-powered credential stuffing and brute-force tooling renders traditional password-based defenses increasingly ineffective. The UK's National Cyber Security Centre warned as early as January 2024 that AI would "almost certainly" raise the volume and impact of cyberattacks through 2025 and 2026, a forecast that, by every available metric, has proven accurate. AI has not merely enhanced the capabilities of sophisticated threat actors; it has democratized them, collapsing the gap between a nation-state and an opportunistic criminal with a laptop.

What Augur is Seeing

The threat intelligence data Augur has collected over the past two and a half years appears to reflect (at the network level) precisely the trends the industry researchers have been documenting at the behavioral level. Augur's confirmed threat IPs grew 21.8% from 2024 to 2025, and the first five months of 2026 are tracking at more than double the monthly average of the prior year, a trajectory that seems to correlate with the 89% increase in AI-enabled adversary activity reported by CrowdStrike, and with the NCSC's January 2024 forecast that AI would drive measurable growth in attack volume through 2025 and 2026. 

The simultaneous increase in newly predicted threat IPs (from 3.7 million in 2024 to 4.7 million in 2025, with 2026 on pace to exceed 6.4 million) could be explained in part by the democratization of attack tooling described across the IBM, Google, and Verizon research: more actors, operating more campaigns, generating more malicious infrastructure than at any point previously recorded.

Taken together, these trends don't establish a direct causal link, but they do suggest that what the research community is observing in attacker behavior may be leaving a measurable footprint in global threat telemetry.

The Numbers

If we take 2024 as a baseline (Augur's yearly numbers showed variability over the years, but the trend, in general, has been slow growth), then we can see in 2025 and 2026 (so far) as outliers, indicating some new factor/s driving the rapid expansion of threat infrastructure and its use in campaigns. And although we cannot say anything definitive yet, there does seem to be a significant correlation between threat actors' adoption of AI tooling and the rapid growth in Augur predictions and third-party confirmations of the predicted malicious IPs. 

TABLE 1: Newly Predicted Threat IPs – Yearly Totals & Trend

Year Predicted IPs Monthly Ave. YoY Change
2024 3,732,987 311,082
2025 4,711,159 392,597 +26.2%
2026 (Jan–May actual) 2,673,366 534,673 +122.4% vs. Jan–May 2025
2026 (projection) ~6,416,100 534,673 ~+36% vs. full-year 2025

TABLE 2: Confirmed Threat IPs – Yearly Totals & Trend

Year Confirmed IPs Monthly Ave. YoY Change
2024 347,910 28,993
2025 423,726 35,310 +21.8%
2026 (Jan–May) 291,122 58,224 +125.2% vs. Jan–May 2025
2026 (projection) ~698,700 58,224 ~+65% vs. full-year 2025

As you can see in the tables above, both predictions (when Augur’s ML identifies new hosting infrastructure and blocks IPs) and confirmations (when third-party researchers document and report a vulnerability) have grown quite dramatically over the 3-year span. 

IPs predicted to be used for use in malicious activities grew more than 50% over that period (far more than any other 3-year span). The growth in confirmations has been even more dramatic, with an 87% increase over those same 3 years.

What Does it All Mean and Why Should I Care?

Whether or not the major uptick in the commissioning of malicious infrastructure can be incontrovertibly tied to the rapid growth in the use of AI by state-sponsored threat actors and cybercriminal gangs, one critical observation can’t be dismissed. Augur’s Predictions over the last 3 years clearly show both a steep increase in the commissioning of malicious infrastructure. And the confirmations, which grew at an even higher rate, demonstrate that the infrastructure is being operationalized more intensely than ever before.

So, whether the root cause is an AI acceleration or not, the net observable effect is that the acceleration in cyberattacks is putting SOCs under pressure. It's clear that the old playbook, traditional reactive security, and legacy threat intelligence are no longer sufficient defense. Preemptive Cybersecurity and Predictive Threat Intelligence are no longer just interesting emerging technologies; they are foundational tools in a modern security stack.

The Augur Difference. Let Us Prove It To You.

Experience firsthand the benefits of preemptive cyber defense with a quick proof of value (POV). We can have you up and running in less than a day, and after 30 days, get an Augur report detailing:

  • Threats Augur identified
  • Advance warning timelines
  • Data-driven insight on alert reduction and improved SOC efficiency

Click here to talk to an Augur specialist now.