- Статьи
- Internet and technology
- From all sides: what fraudulent schemes to expect in the fall of 2026
From all sides: what fraudulent schemes to expect in the fall of 2026
In the autumn of 2026, Russians can expect a number of cyber threats related to the current agenda, experts have warned about this. Attackers, in particular, can use tax and fine issues in their schemes, the beginning of the school year — electronic diaries, documents, tuition fees and clubs, as well as the heating season and utility bills. Read the Izvestia article about what cyber threats to expect in the fall of 2026, how dangerous they are and how to protect yourself from them.
What schemes can be expected in the arsenal of scammers in the fall of 2026
Attackers traditionally use topics in their attacks that are particularly relevant to people and businesses at a particular moment, Dmitry Galov, head of Kaspersky GReAT (Kaspersky Lab's Global Threat Research and Analysis Center) in Russia, said in an interview with Izvestia.
"In the summer of 2026, we discovered threats related to fake applications for finding cheap fuel or buying gasoline coupons, as well as a large—scale fraudulent campaign in which attackers created AI sites for non—existent water parks and amusement parks in Russian cities," the expert says.
According to him, in the fall, attackers may start using more relevant topics: for example, issues of taxes and fines, the beginning of the school year — electronic diaries, documents, tuition fees and clubs, as well as the heating season and utility bills.
Another dangerous period will be the second decade of September, which accounts for voting in the elections to the State Duma, according to a data analyst at the Coordination Center for domains .RU/.Russian Federation Evgeny Pankov. At this time, fraudulent schemes disguised as election reports may appear.
"A separate reason is the autumn sales and preparations for Black Friday, offers of airline tickets and vacation travel, corporate conferences and employee training,— says Dmitry Galov. — In addition, phishing messages about New Year's Eve corporate parties, gifts, purchases and seasonal vacancies may appear by the end of autumn.
Which organizations can become targets of cyber attacks in the autumn season
In the fall of 2026, public sector organizations, financial companies, telecom and industrial enterprises will remain the main targets for cyber attacks, Maxim Alexandrov, an expert on Security Code software products, believes. Moreover, hackers are interested not only in financial gain or the destruction of IT infrastructure, but also in corporate secrets.
— As previously noted by the experts of the Security Code, in more than 40% of targeted attacks in the first quarter of 2026, attackers set one of their goals to steal official correspondence, corporate data and technological documentation, — says the interlocutor of Izvestia.
Attacks are especially dangerous for organizations in critical industries, adds Sergey Tunchik, head of the Information Security sector at the Digital Economy League. Medical facilities remain one of the priority targets: due to their high sensitivity to downtime, they are more likely to agree to a buyout. Infrastructure organizations (energy, transport, manufacturing) are under no less pressure — they account for about a third of all ransomware attacks.
In turn, Dmitry Galov predicts that in the upcoming autumn season, Russian organizations will continue to be threatened by complex targeted cyber attacks, such as the HelloNet campaign with previously unknown sophisticated tools, which Kaspersky Lab experts discovered earlier this year. Large organizations from the government, industrial, energy, transport, logistics, and educational sectors in Russia have faced it.
"One of the most striking trends in both the Russian and global threat landscape is attacks on supply chains, that is, software developers," adds the expert. "By compromising such an organization, attackers gain access to a large number of its customers.
What tools will cybercriminals use in the fall of 2026?
The most popular techniques of cybercriminals on the eve of autumn 2026 are attacks through contractors, phishing campaigns through mail and messengers, as well as DDoS attacks, Maxim Alexandrov says in an interview with Izvestia. At the same time, the main tool is social engineering, which will play a leading role in the coming months.
"Among the technical trends, it is worth highlighting the increasing influence of artificial intelligence (AI), which is used to automate various stages of an attack, as well as an increase in the number of attacks related to compromising legitimate software, for example, for remote control," says the expert.
He calls another trend the widespread use of exploits for various popular products that are not updated within the perimeter of the Russian IT infrastructure. In turn, Evgeny Pankov notes that in the fall we should expect not the appearance of fundamentally new ones, but improvements to already known schemes.
For example, phishing attacks created with the help of AI will be more accurate and widespread, and deepfakes will be even more difficult to distinguish from real audio and video materials. In addition, qualified specialists in psychology and finance will increasingly be involved in the development and implementation of social engineering schemes, which will create more convincing deception scenarios and increase the potential damage to users, the expert predicts.
"Probably, the first truly high-profile incident may occur in the near future, where an autonomous AI agent will perform malicious actions with minimal human involvement," adds Sergey Tunchik. — In 2026, the trend towards the use of generative AI for illegal purposes was finally consolidated.
How to protect yourself from current cyber threats in the fall of 2026
The classic set of measures will continue to form the basis of cybersecurity in the coming months. According to the Director of the Ural Center for Security Systems (UCSB) Research Center According to Denis Komarov, these include network protection, vulnerability management, backup, and monitoring of security events.
"The introduction of AI technologies has not turned the world of cyber attacks upside down, but it forces us to take it into account in our threat model," the source tells Izvestia. — At the same time, the attacker does not necessarily go through AI. He can steal an account, exploit a VPN gateway vulnerability or ordinary phishing, and only then use AI to develop an attack.
Therefore, the classical framework remains the basis, and AI-specific measures only complement it, the expert notes. At the same time, Zero Trust and the minimization of rights become a cross-cutting principle, and this principle applies to both models and agents. An AI agent with access to APIs, files, and tools turns a successful attack on the model into actions in the infrastructure, so it needs minimal rights, isolation of the execution environment, management of tool calls, and a person in the loop for critical decisions.
The attackers' goals remain unchanged: they still seek to obtain the user's credentials and payment information, confirmation codes, access to his device, or convince him to transfer money on his own - only scenarios change, says Dmitry Galov. To protect users from these threats, it is important to adopt an integrated approach. In particular, it is necessary to set unique passwords for different services, store them in a password manager, enable two-factor authentication, install updates to the operating system and applications in a timely manner, and use a security solution on all devices regardless of the operating system.
"Modern cyber threats can affect users of any platform, while the level of security largely depends not only on the built—in protection mechanisms, but also on the digital habits of the person himself,— concludes the Izvestia interlocutor.
Переведено сервисом «Яндекс Переводчик»