In January 2026, George Skaff outlined several trends expected to shape the cybersecurity landscape for SMBs throughout the year.

Rather than predicting specific malware families or threat actors, the focus was on broader shifts in attacker behavior, including AI-driven phishing, deepfake-enabled fraud, supply chain compromises, and the growing challenge of defending organizations with limited security resources.
Five months later, many of those trends have become everyday realities.
Prediction #1: AI-Powered Social Engineering Would Accelerate
George warned that AI would allow attackers to create more convincing phishing campaigns at greater scale.
Since January, AI-assisted phishing campaigns and social engineering attacks have continued to evolve. Threat groups such as Scattered Spider have demonstrated how attackers can successfully target organizations through identity-focused attacks and social engineering rather than relying on sophisticated malware or exploits. Campaigns leveraging AI-generated lures and increasingly convincing impersonation techniques have made phishing attacks more scalable and more effective than ever before.
The trend is particularly concerning for SMBs. According to the OpenText 2026 Cybersecurity Threat Report, phishing attacks increased 206.5% year-over-year, while personalized spearphishing campaigns grew from 56% to 70% of all phishing attacks, reaching 84% by the end of the year. These findings reinforce George's prediction that AI would make phishing attacks more scalable, targeted, and effective.
📊 Related: Our 2026 Cybersecurity Threat Report highlights how attackers continue to evolve their social engineering tactics, leverage AI-driven techniques, and target organizations through increasingly sophisticated phishing campaigns.
Prediction #2: Trust Would Become the Primary Target
George's article emphasized deepfakes, impersonation attacks, and the growing importance of trust as an attack vector.
Five months into 2026, trust-based attacks have become one of the defining cybersecurity stories of the year. Rather than exploiting software vulnerabilities, many of the most significant incidents have relied on social engineering, identity compromise, and the abuse of trusted communications.
Recent campaigns targeting Salesforce customers demonstrated how threat actors can gain access through support impersonation and vishing techniques rather than technical exploits. Similar tactics have been used by groups such as Scattered Spider, which have repeatedly targeted help desks, identity systems, and trusted communications to gain legitimate access to victim environments.
These incidents reinforce a key finding from the OpenText 2026 Cybersecurity Threat Report: attackers increasingly rely on identity compromise, social engineering, and trusted communications rather than traditional exploits. As the report noted, “attackers did not need new exploits, they weaponized trust.”
Attackers aren’t breaking in - They’re logging in.
🎙️ Podcast: listen to Scattered Spider's Evolution: One Industry at a Time to see how modern threat actors are succeeding through identity attacks and social engineering rather than malware.
Prediction #3: Supply Chain Attacks Would Continue Growing
George highlighted software supply chain risk as a major concern, warning that attackers would continue targeting trusted software ecosystems and distribution channels.
Five months into 2026, that prediction has proven accurate. Rather than attacking organizations individually, threat actors increasingly focus on compromising trusted software, open-source projects, and widely used packages that can provide access to thousands of downstream users.
Several incidents throughout the year reinforced this trend, including malicious npm package campaigns, the worm-like npm compromise, and other software supply chain attacks that abused trusted development and distribution channels. Campaigns such as GlassWorm and TrapDoor further demonstrated how attackers continue to exploit trust within the software ecosystem to maximize reach and impact.
By compromising a single trusted source, threat actors can potentially affect thousands of organizations simultaneously, making supply chain attacks one of the most efficient and scalable attack methods available today.
📖 Related: Read our coverage of the npm Supply Chain Attack to learn how attackers compromised trusted software packages and what organizations can do to reduce risk.
Prediction #4: SMBs Would Need Outside Security Expertise
George predicted that SMBs would increasingly rely on managed security services and MDR providers as cyber threats became more sophisticated and difficult to manage internally.
Five months into 2026, that prediction has proven accurate. Organizations continue to face cybersecurity skills shortages, alert fatigue, increasingly complex attack techniques, and limited internal security resources.
The challenge is particularly evident among SMBs. According to the OpenText 2026 Cybersecurity Threat Report, infection rates among medium-sized businesses increased 39% year-over-year, while small businesses experienced a 28% increase. These findings highlight the growing pressure SMBs face as cyber threats become more sophisticated and difficult to manage with limited internal resources.
For many SMBs, building and maintaining a fully staffed security operations team simply isn't realistic. As a result, managed security services, MDR, and trusted technology partners continue to play a critical role in helping organizations improve security outcomes without adding headcount.
📘 Learn More: Explore our Interactive MSP Playbook to see how SMBs and MSPs are navigating today's cybersecurity challenges, staffing shortages, and evolving threat landscape.
What Surprised Us
What stood out most wasn't the emergence of a new ransomware family or a groundbreaking attack technique. It was how effectively threat actors continued to exploit trust.
From Scattered Spider's identity-focused attacks to Salesforce-related vishing campaigns, ClickFix social engineering scams, and software supply chain compromises, many of the year's most significant incidents relied on manipulating people rather than defeating technology.
As our 2026 Cybersecurity Threat Report observed, attackers did not need new exploits. They weaponized trust.
The lesson from 2026 so far isn't that attackers are inventing entirely new techniques. It's that they're becoming dramatically better at abusing trust. Whether through AI-generated phishing, deepfake impersonation, social engineering, or supply chain compromises, the common thread remains the same: attackers are finding new ways to appear legitimate.