Cyber-enabled fraud has overtaken ransomware as CEOs’ top cyber concern, according to the World Economic Forum’s Global Cybersecurity Outlook 2026, as AI-related vulnerabilities rise and resilience gaps widen across regions and organisations.

Cyber-enabled fraud has overtaken ransomware as the leading cyber concern for chief executives, according to the Global Cybersecurity Outlook 2026 from the World Economic Forum. Fraud and phishing now rank ahead of ransomware in CEO risk perceptions, reflecting the scale and reach of these threats across regions and sectors.

The report, developed in collaboration with Accenture, draws on a survey of 804 global business leaders in 92 countries, including 105 CEOs, 316 chief information security officers and 123 other C-suite executives. It finds that 73% of respondents were directly affected by cyber-enabled fraud in 2025 or knew someone who was.

fraud, phone, google ad

The Forum describes cyber-enabled fraud as a pervasive global threat, highlighting its growing societal and economic impact as it spreads across industries and geographies.

“As cyber risks become more interconnected and consequential, cyber-enabled fraud has emerged as one of the most disruptive forces in the digital economy, undermining trust, distorting markets and directly affecting people’s lives,” said Jeremy Jurgens, managing director at the World Economic Forum.

“The challenge for leaders is no longer just understanding the threat but acting collectively to stay ahead of it. Building meaningful cyber resilience will require coordinated action across governments, businesses and technology providers to protect trust and stability in an increasingly AI-driven world.”

AI-related vulnerabilities accelerating

Artificial intelligence is identified as the most significant force shaping the cyber risk landscape in 2026. AI-related vulnerabilities increased faster than any other cyber risk category in 2025, with 87% of respondents reporting a rise. Looking ahead, 94% of leaders expect AI to be the biggest force influencing cybersecurity in 2026.

The report highlights several specific AI-related concerns. Data leaks linked to generative AI are cited by 34% of respondents, while 29% point to the use of AI to enhance adversarial capabilities. These risks are emerging as AI tools are adopted at speed across organisations, often faster than governance and security frameworks are updated.

Organisations are responding. The share of respondents assessing AI-related security risks rose from 37% to 64% in a single year, indicating how quickly AI has moved from a future consideration to a current cyber priority.

The Forum notes that AI is reshaping both offensive and defensive cyber capabilities, increasing the pace and complexity of the threat environment.

Geopolitical volatility and uneven preparedness

Geopolitics is also redefining cyber risk strategies. Sixty-four per cent of organisations now factor geopolitically motivated cyberattacks into their risk planning. Among the largest enterprises, this rises to 91%, reflecting their exposure to geopolitical disruption and critical infrastructure dependencies.

However, confidence in national preparedness remains uneven. Thirty-one per cent of respondents report low confidence in their country’s ability to manage a major cyber incident affecting critical infrastructure. Regional differences are pronounced, with confidence levels ranging from 84% in the Middle East and North Africa to 13% in Latin America and the Caribbean.

The report links these differences to geopolitical fragmentation and widening gaps in cyber capability between countries and regions.

Supply chains and systemic exposure

Third-party and supply chain risk continues to be cited as a major barrier to cyber resilience. Among large organisations, 65% identify third-party and supply chain dependencies as their greatest challenge, up from 54% the previous year.

The report also highlights increasing concentration risk in digital infrastructure. Incidents at major cloud and internet service providers are cited as examples of how infrastructure-level failures can create widespread downstream impacts across interconnected digital ecosystems.

These findings reinforce the Forum’s view that cyber risk increasingly operates at a systemic level, rather than being confined to individual organisations.

The resilience gap widens

One of the most significant findings in the report is the growing gap between highly resilient organisations and those falling behind. Skills shortages and resource constraints are amplifying systemic risk, particularly as supply chains become more interconnected and opaque.

Smaller organisations are twice as likely as large firms to report insufficient cyber resilience. Regionally, shortages in cybersecurity talent are most acute in Latin America and the Caribbean, where 65% of organisations report insufficient skills to meet their security objectives. In sub-Saharan Africa, 63% of organisations report similar constraints.

The Forum warns that these disparities leave smaller organisations and emerging economies disproportionately exposed, increasing risk not only for those entities but for the wider digital ecosystem they operate within.

Cyber resilience as a strategic requirement

Across the report, the World Economic Forum frames cyber resilience as a strategic requirement rather than a technical function. It links cyber risk directly to economic stability, national resilience and public trust, arguing that the interconnected nature of today’s threats requires coordinated action.

The report calls on leaders to move beyond isolated organisational responses and focus on raising the collective baseline by sharing intelligence, aligning standards and investing in cyber capabilities. The Forum argues that only through coordinated action across governments, businesses and technology providers can organisations keep pace with increasingly interconnected and AI-driven cyber risks.

“The weaponization of AI, persistent geopolitical friction and systemic supply chain risks are upending traditional cyber defences. For C-suite leaders, the imperative is clear; they must pivot from traditional cyber protection to cyber defence powered by advanced and agentic AI to be resilient against AI-driven threat actors,” said Paolo Dal Cin, global lead, Accenture Cybersecurity.

“True business resilience is built by fusing cyber strategy, operational continuity and foundational trust, enabling organizations to swiftly adapt to the dynamic threat landscape.”