IT Brief Canada - Technology news for CIOs & IT decision-makers
Canada
Infoblox warns cybercrime is becoming industrialised

Infoblox warns cybercrime is becoming industrialised

Sun, 2nd Aug 2026 (Today)
Mark Tarre
MARK TARRE News Chief

Infoblox has released its 2026 Threat Landscape Report, which argues that cybercrime is becoming more industrialised through AI and shared criminal infrastructure.

The findings draw on trillions of DNS queries, billions of underground criminal transactions and threat research into how online attacks are created and distributed. They describe a market in which criminal groups can buy tools and services instead of building them from scratch.

Among the headline findings, nearly 25 per cent of 120 million newly observed domains were classified as high or critical risk, pointing to the scale of online infrastructure used to support scams, phishing and malware campaigns.

Traffic distribution systems, or TDSs, were identified as the most widespread threat, affecting more than 95 per cent of networks. They are used to redirect targets to malicious content, including phishing pages, scams and malware.

The report also found that 88 per cent of threat-related domains appeared in only one customer environment. A further 44 per cent were active for just a single day, suggesting attackers are relying heavily on short-lived domains to reduce the chance of detection.

Another strand of activity involved residential proxy networks. Infoblox found that 65 per cent of its Threat Defence customers queried domains linked to such networks, which attackers use to make malicious traffic resemble ordinary consumer internet use.

Rising scams

Scam-related domains rose 62 per cent year on year. Infoblox linked the increase to brand impersonation, identity theft and financial fraud, with AI tools helping to enable more of those operations.

The report presents this as a shift in the economics of cybercrime rather than simply a rise in technical sophistication. In that view, the wider availability of tools and infrastructure is reducing the time and expertise needed to mount attacks.

That matters for defenders because it can make campaigns harder to spot using conventional methods. Short-lived domains, proxy networks and redirection systems allow malicious operators to move quickly and avoid prolonged exposure.

The report breaks the cybercrime landscape into four areas: the criminal services used to run attacks at scale, the hidden infrastructure used to avoid detection, the lures used to reach victims and the attack surfaces that create entry points into organisations. Together, they describe a more connected ecosystem than one associated with isolated hacking campaigns.

One of the main changes, Infoblox said, is the spread of specialist services within criminal markets. Rather than carrying out every stage of an operation internally, attackers can rely on external providers for infrastructure, routing, scam delivery and evasion.

That model mirrors broader digital marketplaces, where participants focus on one part of a supply chain. In cybercrime, the result can be faster turnaround between planning and execution, with lower barriers to entry for less technically skilled actors.

"This year's report documents the cybercrime machine, a globally connected criminal economy where frontier AI, specialised criminal services and hidden infrastructure have transformed how attacks are created, purchased and deployed," said Dr Renée Burton, Vice President, Infoblox Threat Intel.

Burton said the most significant development was the spread of advanced methods beyond a narrow pool of attackers. That change is testing security approaches that depend mainly on finding and responding to threats after they appear.

"The most important shift is not that attackers have become more sophisticated. It's that sophisticated capabilities have become widely accessible, changing the pace of cybercrime and challenging security strategies built primarily around detection and response," Burton said.

The findings add to a wider debate in the cybersecurity sector about whether defensive models are keeping pace with attacks that rely on automation, rapid domain turnover and rented infrastructure. Reports from security vendors often differ in emphasis, but many point to the same broad trend: cybercrime is increasingly organised as a service economy.

In practical terms, the focus on disposable domains and covert routing systems presents a monitoring problem for companies. If a large share of malicious infrastructure is visible only briefly or appears in isolated customer environments, conventional blacklists and standard signature-based tools may miss some of the activity.

Infoblox's data also suggests that internet infrastructure itself remains a key battleground. Domain registrations, DNS traffic and routing behaviour can reveal how campaigns are assembled and delivered, particularly when attackers try to blend fraudulent activity with normal web use.

For businesses, the figures indicate that scams linked to trusted brands and identity theft remain a major source of risk alongside more familiar malware and phishing campaigns. The growth in scam domains shows how criminal operators continue to target consumers and employees through deception as much as through technical intrusion.

Nearly 25 per cent of 120 million newly observed domains were rated high or critical risk, while scam-related domains increased 62 per cent year on year.