Comcast 2026 Cybersecurity Report: AI Accelerates Threats and Expands the Attack Surface

A new Comcast Business cybersecurity report examines 79.3 billion security events and finds AI accelerating cyberattacks while expanding the enterprise attack surface beyond traditional network boundaries.

Key Highlights

  • The report finds AI compressing the time between vulnerability exposure and exploitation, while making phishing, drive-by compromises and other attacks faster and easier to execute at scale.

  • Stolen credentials, hijacked sessions, browser attacks and the rapid growth of non-human identities—including AI agents and APIs—are giving attackers new ways to move through enterprise environments.

  • Unmanaged devices in homes, businesses and third-party environments—including routers, cameras and other connected devices—can be compromised and used as residential proxies, creating risks that traditional perimeter security may not see.

Comcast Business has released its 2026 Cybersecurity Threat Report, examining 79.3 billion cybersecurity events detected across its cybersecurity customers between March 1, 2025 and February 28, 2026.

The fourth annual report finds that artificial intelligence is accelerating virtually every stage of the threat landscape—from the speed at which attackers gain initial access to the identities and infrastructure they exploit once inside an organization.

The report also highlights a narrowing window between exposure and impact. AI-assisted coding tools can enable attackers to develop new exploits before patches become available, while many of the underlying attack techniques remain familiar. Phishing and drive-by compromise continue to account for the largest volumes of activity, but automation and AI are making those attacks faster and less expensive to execute at scale.

79.3 Billion Cybersecurity Events

Among the report's findings:

  • 47.9 billion initial-access events and 5.2 billion resource-development events, illustrating the scale of automated attacks probing organizational perimeters and the infrastructure attackers build to support their operations.

  • 288.9 million active scans, demonstrating the persistent effort by adversaries to identify vulnerable devices and systems.

  • 25.4 billion phishing events and 21.9 billion drive-by compromise events, making them the two highest-volume techniques recorded in the data set.

  • 5.8 million attempts to gain covert access to employee browsers, including attacks involving malicious extensions, browser synchronization and session theft.

  • 57,000 DDoS events, with botnets generating hyper-volumetric traffic designed to disrupt digital services.

Taken together, the activity represents an average of roughly 2,514 cybersecurity events every second.

Identity Becomes a Primary Battleground

As organizations increasingly rely on cloud services, APIs, automation and AI agents, identity has become a central component of the attack surface. Stolen credentials and hijacked sessions can allow attackers to move through networks using legitimate access rather than attempting to circumvent traditional security controls.

The growing number of non-human identities presents an additional challenge. AI agents, APIs and other automated systems can carry significant permissions (no employee would be granted), creating new potential paths into enterprise environments.

That makes identity protection increasingly dependent on continuous monitoring and behavioral analysis rather than one-time authentication.

"Attackers have stopped needing to break in," said Noopur Davis, Chief Information Security and Product Privacy Officer, Comcast Corporation. "They get in with stolen credentials, then move through the network the way an employee would. The hard part is no longer just keeping them out. It is also seeing them once they are in and preventing their lateral movement."

The Attack Surface Extends Beyond the Enterprise

The report also points to an increasingly difficult-to-map portion of the corporate attack surface: devices outside an organization's direct control.

Routers, cameras, streaming devices, point-of-sale terminals and other connected equipment in homes and businesses can be compromised and incorporated into residential proxy networks. Attackers can then rent access to those networks, allowing other users to route activity through seemingly legitimate residential connections.

Researchers at the Comcast Threat Research Lab tracked this infrastructure and identified large clusters of compromised devices forwarding traffic on behalf of outside users.

Because these devices may not be owned, managed or monitored by the organization, conventional perimeter-based security controls may not account for them.

“Many cybersecurity programs are designed around organizational boundaries, but cyber risk does not respect those boundaries,” said Amit Verma, Chief Technology Officer, Comcast Business. “Today’s threats often emerge from remote employees’ home offices, supplier networks, other third-party networks, and unmanaged devices. Effective defense requires visibility into network activity across that broader environment, so organizations can identify and respond to a risk wherever it originates.”

Network-Level Security Takes on a Larger Role

The report argues that organizations facing machine-speed attacks need security capabilities capable of detecting and responding to threats in real time.

Comcast says more than 1.2 billion devices connect across its network, where the company identifies, filters and blocks an average of 30 million cyber threats each day. The company's security approach extends across residential and business environments.

Expanded Data Set Changes How the Numbers Should Be Read

The 2026 report is based on an expanded telemetry set analyzed through a new threat analytics platform. Comcast notes that the figures reflect both the expanded data set and an updated methodology.

As a result, the totals in the 2026 report should not be directly compared with totals published in previous annual reports.

Source: Comcast Business


Stay Connected with ISE Magazine 

Subscribe to our newsletters and magazine for the latest telecom insights, explore the current issue for in-depth features and strategies, and register for upcoming webinars to learn directly from industry leaders.

This piece was created with the help of generative AI tools and edited by our content team for clarity and accuracy.
Sign up for our eNewsletters
Get the latest news and updates