What 2026 DBIR Confirms: Attacks Are Living in the Browser
The 2026 Verizon DBIR highlights a significant shift in cyberattacks, with a growing reliance on browser-based activities, particularly the unauthorized use of AI tools like ChatGPT and Gemini. Employees are increasingly using these tools to access and share sensitive data, often bypassing traditional security controls. Furthermore, credential theft via browser exploitation remains a prevalent threat, largely undetected by existing security solutions due to a critical detection gap.
The Verizon 2026 Data Breach Investigations Report (DBIR) reveals a concerning trend: attackers are increasingly leveraging browser-layer attacks. Specifically, the report identifies ‘Shadow AI’ as the third most common insider threat, representing a fourfold increase from the previous year, driven by employees using personal AI tools like ChatGPT for tasks such as pasting internal documents. A significant portion (67%) of users access AI services through personal accounts, and 45% are regular AI users, highlighting a substantial risk. Keep Aware’s telemetry corroborates this, showing over half of AI prompt inputs are sent to personal accounts, and a concerning 23% of sensitive uploads transit through unverified accounts, bypassing corporate DLP policies.
Beyond AI, the DBIR also points to a surge in browser-based credential theft, accounting for approximately 41% of observed threats. Crucially, this activity largely goes undetected by traditional security tools like VirusTotal, Microsoft-themed phishing sites, network proxies, DNS filters, and endpoint agents. Keep Aware’s data confirms this, showing that 63% of Microsoft-themed phishing sites were not flagged. This highlights a critical detection gap, emphasizing the need for browser-native security solutions. Additionally, the report identifies ‘ClickFix’ as an emerging social engineering technique, often originating in compromised websites or LLM chat responses, leading to malware execution on the endpoint.