Google has published a new report, ‘Cloud threat horizons report H1 2026‘, which looks at changes in the cloud threat landscape observed and expected during the first half of 2026 and beyond.
The Google Cloud threat horizons report aims to provide strategic intelligence on threats to not just Google Cloud, but all cloud service providers.
Key findings highlighted in the report include:
Increasing exploitation of third-party, user-managed software-as-a-service as a primary initial access vector
Threat actors are successfully targeting unpatched applications and permissive user-defined firewall rules.
Identity perimeters spanning multiple cloud environments and SaaS platforms targeted with vishing and token theft
Identity compromise underpinned 83% of compromises. Threat actors continued to transition from traditional phishing to voice-based social engineering (vishing), and credential harvesting from third-party SaaS tokens to facilitate large-scale, silent data exfiltration.
Malicious insiders increasingly relying on cloud storage for data theft
Malicious insiders are increasingly using cloud environments controlled by their organizations and personally controlled cloud storage to exfiltrate sensitive data.
Strategic drivers shaping the 2026 cloud landscape
Upcoming events in 2026, including increasingly intensifying geopolitical conflicts, the FIFA World Cup, and US midterm elections, may provide a backdrop for high-volume social engineering and distributed denial of service (DDoS) attacks targeting cloud-hosted media.






