The fastest-growing category of breach in 2026 does not begin with malware at all. It begins with a login. Identity has become the primary attack surface, and the credential, the session token, and the trust we place in a familiar face or voice are now the assets adversaries most want to steal. As organisations hardened endpoints and networks, attackers simply walked through the front door using legitimate credentials, bought from access brokers or harvested through increasingly convincing social engineering.
What makes 2026 distinct is the industrialisation of two trends at once. Ransomware has become a service economy with specialised roles and affiliate models, lowering the skill floor for devastating attacks, while generative artificial intelligence has turned deepfakes from a curiosity into an operational tool for fraud. A finance clerk approving a wire on a video call, a help desk resetting multi-factor authentication for a caller who sounds exactly like an executive: these are the incidents defining the year. Defending against them requires shifting from perimeter thinking to identity-centric, zero-trust architecture backed by detection you can actually operate.
Identity Is the New Malware
The attacker who logs in leaves far fewer traces than the one who breaks in. That asymmetry is reshaping every security programme.
- ▸Credentials over exploits: Attackers increasingly log in rather than break in, using valid accounts that evade signature-based defences entirely.
- ▸Session hijacking and token theft: With multi-factor authentication now common, adversaries pivot to stealing session cookies and tokens that let them bypass the second factor after the fact.
- ▸MFA fatigue and push bombing: Overwhelming a user with authentication prompts until one is approved remains stubbornly effective against weak factors.
- ▸The access-broker economy: A mature underground market sells initial access to corporate environments, decoupling the intruder from the eventual ransomware operator.
Mapped to MITRE ATT&CK, this is a decisive shift toward valid-accounts and credential-access techniques, and it is why identity telemetry is now the richest source of detections for most security teams.
Ransomware-as-a-Service Grows Up
Ransomware in 2026 behaves less like a lone criminal and more like a distributed software business, with the resilience that implies.
- ▸Specialisation of roles: Initial-access brokers, operators, negotiators, and launderers now form a division of labour that resembles a legitimate company.
- ▸Double and triple extortion: Beyond encryption, attackers exfiltrate data and threaten publication, then add pressure through customer, regulator, or partner notification and denial-of-service.
- ▸Data theft without encryption: Increasingly operators skip encryption entirely, stealing data and extorting on the threat of disclosure, which is faster and harder to detect.
- ▸Targeting of backups and identity systems: Modern playbooks specifically hunt backup infrastructure and directory services, because owning identity means owning everything.
For regulated entities, the extortion calculus is now entangled with disclosure duties under NIS2, GDPR breach notification, and DORA for financial firms, meaning a ransomware event is simultaneously a security, legal, and reporting crisis.
Deepfakes Enter the Attacker Toolkit
Synthetic media has crossed the threshold from novelty to weapon, and it targets the one control most organisations still lean on: human judgement.
- ▸Voice cloning for vishing: A few seconds of audio can produce a convincing clone used to authorise payments or coax credentials out of a help desk.
- ▸Live video deepfakes: Real-time face-swapping on video calls has been used to impersonate executives during fraudulent payment approvals.
- ▸Synthetic identities for onboarding fraud: Generated documents and faces defeat weak know-your-customer checks, a direct threat to fintech and any remote onboarding flow.
- ▸Erosion of out-of-band trust: The classic advice to verify by calling back fails when the voice on the line is itself synthetic.
The defensive implication is uncomfortable: human verification is no longer sufficient for high-value actions. Processes must assume voice and video can be faked and require controls a deepfake cannot satisfy, such as callbacks to pre-registered numbers, signed approvals, or multi-person authorisation.
Zero Trust and MDR/XDR: The Structural Response
The architectural answer is zero trust, codified in NIST Special Publication 800-207: never trust, always verify, and assume breach. In practice this means shrinking implicit trust everywhere.
- ▸Phishing-resistant authentication: Move to FIDO2 and passkeys, which bind credentials to origins and defeat both phishing and credential replay.
- ▸Continuous, context-aware authorisation: Evaluate device posture, location, and behaviour on every request, not once at login.
- ▸Least privilege and micro-segmentation: Limit blast radius so a compromised identity cannot reach the whole estate; enforce just-in-time access for privileged roles.
- ▸Identity threat detection and response: Treat the identity provider as a monitored, high-value system with its own detections.
No architecture removes the need to watch for the adversary, which is where MDR and XDR come in. Extended detection and response correlates signals across endpoint, identity, cloud, and email into a single investigation surface, while managed detection and response wraps that technology in a human team that hunts and responds around the clock. The honest trade-off:
- ▸Build in-house: Maximum control and context, but you must staff a round-the-clock team, engineer detections, and retain scarce talent.
- ▸Buy MDR: Immediate coverage and expertise, at the cost of some context and a dependency on the provider; best for organisations that cannot realistically run their own always-on operation.
Detection engineering ties it together: writing, testing, and tuning detections mapped to MITRE ATT&CK, validated with adversary-emulation exercises so you know your coverage before an incident tests it for you.
What to Do Monday: An Identity-First Checklist
A concrete sequence to raise identity resilience quickly:
1. Enrol privileged and high-risk users in phishing-resistant FIDO2 passkeys, and set a deadline to retire SMS and push-approval factors. 2. Shorten session lifetimes and enable token-binding or continuous access evaluation so stolen tokens expire fast. 3. Harden the help desk: require strong, non-voice identity proofing before any MFA reset or account recovery, closing the deepfake vishing path. 4. Add out-of-band, multi-person approval for wire transfers and vendor bank-detail changes, independent of voice or video confirmation. 5. Instrument the identity provider: alert on impossible travel, new-device sign-ins, MFA-method changes, and mass permission grants. 6. Segment and apply least privilege, with just-in-time elevation for administrators and no standing global-admin accounts. 7. Keep backups offline and immutable, then actually rehearse a restore. 8. Stand up MDR or XDR coverage if you lack always-on monitoring, and feed identity logs into it. 9. Run a tabletop for a deepfake-enabled fraud and a data-theft extortion, so decision-makers have rehearsed the choices. 10. Map your detections to MITRE ATT&CK and close the obvious gaps first.
Tunisia, North Africa, and the European Nearshore
For businesses in Tunisia and across North Africa, the identity threat cuts two ways. Locally, small and mid-sized firms and public bodies are attractive ransomware targets precisely because identity hygiene often lags and incident-response capacity is thinner. Multilingual social engineering, in Arabic, French, and English, makes the region fertile ground for the very vishing and business-email-compromise schemes that deepfakes now supercharge.
- ▸A talent opportunity: Detection engineering, identity administration, and security operations are exportable skills. The region can staff MDR and SOC functions for European clients across a favourable time zone and shared working languages.
- ▸Nearshore trust: European firms bound by NIS2 and DORA want partners who understand zero trust and can evidence it. A provider fluent in NIST 800-207, ISO 27001, and GDPR turns proximity into a durable advantage over distant offshore alternatives.
- ▸Data-residency sensitivity: Handling European identity and personal data demands GDPR-grade controls; providers that build these in can serve regulated clients others cannot.
- ▸The home-market case: Adopting passkeys, MDR, and rehearsed response is not just for exporters; it is how regional banks, telcos, and government services avoid becoming the next cautionary tale.
The strategic takeaway mirrors the broader industry: identity discipline is now a market differentiator, and the North African firms that master it will sell security services into Europe rather than merely defending against attacks from it.
Outlook
The next phase of this contest is already visible. Attackers will use generative models to scale personalised social engineering and to defeat weaker biometric checks, while defenders lean on the same technology to triage alerts and hunt at machine speed. Standards keep moving: passkeys will become the default rather than the upgrade, content-provenance efforts will start to give audio and video verifiable pedigree, and post-quantum migration under NIST ML-KEM and ML-DSA will begin reshaping the cryptography beneath every identity protocol. The enduring principle is unglamorous but decisive: assume any single signal can be faked, verify continuously, limit what a compromised identity can reach, and watch relentlessly. Organisations across Europe and North Africa that internalise that mindset in 2026 will be the ones still standing, and still trusted, when the tools on both sides grow sharper still.
