Free PDF download

2026 Threat Report

Artificial intelligence is now on both sides of the fight. See how AI helps attackers, how it helps defenders, and the ten things every Australian business should fix in the next 90 days.

No email gate. Download now and share it with your board or IT committee.

What is inside the report

Nine pages written for business owners, IT managers and board members — no scare tactics, just facts and a clear plan.

AI on both sides

How attackers use deepfakes, AI-written phishing and self-rewriting malware — and how defenders use 24/7/365 SOC, behavioural EDR and automated triage to fight back.

Seven public incidents

Arup's $25m Hong Kong deepfake, Anthropic's AI-orchestrated espionage disclosure, MGM Resorts' $100m help-desk breach, Change Healthcare's $22m ransom and more.

The 2026 landscape in figures

1 in 4 breaches start with stolen credentials. Minutes from phishing click to mailbox takeover. And the hours attackers actually work while most businesses sleep.

90-day action list

Ten practical fixes: MFA everywhere, an AI use policy, tenant-contained AI, payment call-back rules, immutable backups, behaviour-based EDR and a 2am escalation path.

What Unicorn IT does

Managed IT plans from $89 per user per month with proactive monitoring, patching, SentinelOne endpoint protection and Guardz 24/7/365 MDR on Silver and Gold.

Built for Australian business

Local support, clear SLAs, server management plans from $250 per month, and after-hours critical support starting at $200 per hour.

Real incidents, real numbers

The report walks through breaches that made headlines — and the patterns that connect them.

  • Arup — US$25m lost to a deepfake video call in Hong Kong
  • Anthropic — AI agent orchestrated espionage against ~30 organisations
  • MGM Resorts — ~US$100m impact from a help-desk impersonation
  • Change Healthcare — US$22m ransom and months of disruption
  • Samsung — staff pasted source code into a public AI chatbot
  • Air Canada — chatbot gave bad advice, airline held liable
  • Optus / Medibank — ~10m and ~9.7m people affected

The three questions every board should ask

  1. 1

    Can we spot a breach at 2am? Most attacks happen outside business hours. The report explains what 24/7/365 monitoring actually looks like.

  2. 2

    How fast can we stop it? Minutes matter. See the timeline from first phishing click to full mailbox takeover.

  3. 3

    Are our backups really safe? Immutable, tested backups are the difference between a bad day and a business-ending ransom.

Get the report now

No form to fill in. Download the PDF, read it on your commute, and share it with your leadership team.