Our analysts have been tracking a significant jump in Augur predictions and confirmations through 2026. Examining the data across 2024, 2025, and the first five months of this year, a clear pattern emerges: year-on-year growth is accelerating. Third-party confirmations, which occur when traditional threat research independently verifies a malicious actor Augur had already flagged, rose 22% from 2024 to 2025 and are on pace for a 65% jump in 2026. In more than ten years of identifying malicious infrastructure, we have not seen growth at this rate. One factor that appears to be driving this acceleration is the rapid adoption of AI by threat actors, enabling faster development, operationalization, and iteration of attack campaigns. So let’s take a look at what the broader research community is saying about how AI is affecting the cybersecurity landscape and what trends we’re seeing in our Augur data.
The AI Acceleration
The cybercriminal ecosystem has undergone a fundamental shift. What once required nation-state resources, sophisticated phishing campaigns in multiple languages, rapid weaponization of newly disclosed vulnerabilities, large-scale credential attacks, and surgical target selection based on financial intelligence can now be executed by modestly skilled actors armed with little more than a jailbroken large language model and a dark web subscription.
The evidence is unambiguous and comes from the most authoritative sources in the industry.
- CrowdStrike's 2026 Global Threat Report documents an 89% year-over-year increase in attacks by AI-enabled adversaries.
- Microsoft flagged increased use of AI by nation-state threat actors for spear phishing, résumé swarming, and deepfakes (MDDR 2024).
- The Verizon DBIR 2026 found that the median time-to-click on AI-crafted phishing lures dropped to under 60 seconds.
- in February 2025, Google's Threat Intelligence Group confirmed that more than 57 distinct threat actor groups had attempted to misuse its Gemini AI platform, not to invent new attack categories, but to do what they already did, faster and at greater scale
The acceleration is measurable at every stage of the attack chain. AI is compressing the time from initial compromise to lateral movement: CrowdStrike now records a fastest-ever eCrime breakout time of just 27 seconds, down from over two minutes in 2023, a 98% reduction in just three years. IBM's X-Force Index found a 71% increase in cyberattacks using valid credentials, as AI-powered credential stuffing and brute-force tooling renders traditional password-based defenses increasingly ineffective. The UK's National Cyber Security Centre warned as early as January 2024 that AI would "almost certainly" raise the volume and impact of cyberattacks through 2025 and 2026, a forecast that, by every available metric, has proven accurate. AI has not merely enhanced the capabilities of sophisticated threat actors; it has democratized them, collapsing the gap between a nation-state and an opportunistic criminal with a laptop.
What Augur is Seeing
The threat intelligence data Augur has collected over the past two and a half years appears to reflect (at the network level) precisely the trends the industry researchers have been documenting at the behavioral level. Augur's confirmed threat IPs grew 21.8% from 2024 to 2025, and the first five months of 2026 are tracking at more than double the monthly average of the prior year, a trajectory that seems to correlate with the 89% increase in AI-enabled adversary activity reported by CrowdStrike, and with the NCSC's January 2024 forecast that AI would drive measurable growth in attack volume through 2025 and 2026.
The simultaneous increase in newly predicted threat IPs (from 3.7 million in 2024 to 4.7 million in 2025, with 2026 on pace to exceed 6.4 million) could be explained in part by the democratization of attack tooling described across the IBM, Google, and Verizon research: more actors, operating more campaigns, generating more malicious infrastructure than at any point previously recorded.
Taken together, these trends don't establish a direct causal link, but they do suggest that what the research community is observing in attacker behavior may be leaving a measurable footprint in global threat telemetry.
The Numbers
If we take 2024 as a baseline (Augur's yearly numbers showed variability over the years, but the trend, in general, has been slow growth), then we can see in 2025 and 2026 (so far) as outliers, indicating some new factor/s driving the rapid expansion of threat infrastructure and its use in campaigns. And although we cannot say anything definitive yet, there does seem to be a significant correlation between threat actors' adoption of AI tooling and the rapid growth in Augur predictions and third-party confirmations of the predicted malicious IPs.
TABLE 1: Newly Predicted Threat IPs – Yearly Totals & Trend
TABLE 2: Confirmed Threat IPs – Yearly Totals & Trend
As you can see in the tables above, both predictions (when Augur’s ML identifies new hosting infrastructure and blocks IPs) and confirmations (when third-party researchers document and report a vulnerability) have grown quite dramatically over the 3-year span.
IPs predicted to be used for use in malicious activities grew more than 50% over that period (far more than any other 3-year span). The growth in confirmations has been even more dramatic, with an 87% increase over those same 3 years.
What Does it All Mean and Why Should I Care?
Whether or not the major uptick in the commissioning of malicious infrastructure can be incontrovertibly tied to the rapid growth in the use of AI by state-sponsored threat actors and cybercriminal gangs, one critical observation can’t be dismissed. Augur’s Predictions over the last 3 years clearly show both a steep increase in the commissioning of malicious infrastructure. And the confirmations, which grew at an even higher rate, demonstrate that the infrastructure is being operationalized more intensely than ever before.
So, whether the root cause is an AI acceleration or not, the net observable effect is that the acceleration in cyberattacks is putting SOCs under pressure. It's clear that the old playbook, traditional reactive security, and legacy threat intelligence are no longer sufficient defense. Preemptive Cybersecurity and Predictive Threat Intelligence are no longer just interesting emerging technologies; they are foundational tools in a modern security stack.



