What I’m seeing right now on the dark web tells me the next major attack wave is not a question of if. It is a question of how ready you are when it arrives.

I monitor dark web/underground ecosystems for a living. I have been doing it for nearly two decades. What I am going to describe in this article is not a forecast based on trend extrapolation or vendor data. It is based on what I am watching happen right now this week, this month inside the underground communities where tomorrow’s attacks are being planned, staffed, and tooled.

The short version: the conditions for a significant surge in cyberattacks targeting both corporate revenue and critical infrastructure are converging toward Q1 2027. The workforce is being recruited now. The tools are being built now. The economic pressures driving the recruitment are intensifying, not easing. And AI is making the entire pipeline faster, cheaper, and accessible to people who would not have qualified as threat actors twelve months ago.

Here is what that looks like from the inside.

New groups are forming every week