In 2026, New Threats Are Emerging on 6 Platforms. Here's What Security Teams Need to Know.
Risk intelligence and executive protection teams can respond to threats more effectively by monitoring fringe platforms where they originate

Security teams use online monitoring to help them predict where and how online activity may materialize into physical threats, but many of the tools available were designed to monitor major platforms that have since become less relevant. When online threats are first detected on a major platform, they are frequently a late signal, as threats have often been developing for months in unmonitored fringe communities on alternative platforms before entering the mainstream.
In 2026, threat actors exist in a wide range of fringe communities on numerous alternative platforms, from which many threats now originate. Security teams detect these threats as early as possible, as once they appear on major platforms, the window for an effective response has often already closed. Open Measures’ platform was designed to close this gap, giving security teams broader visibility for
To help security, risk intelligence, and executive protection teams detect threats earlier and respond more quickly, below are six platforms to monitor in 2026, all available through our platform.
1. Telegram: A Primary Marketplace and Communication Hub for International Cybercriminals
Despite a surge of enforcement on Telegram after founder Pavel Durov’s arrest in 2024, cybercrime syndicates have not left the messaging platform; instead, they have continued to flourish, developing new strategies to evade moderation.
In 2025, our researchers mapped one cybercriminal syndicate’s activity on Telegram as an operational template for similar groups. In 2026, our researchers confirmed that this networked structure remains alive and well for brokers of stolen accounts, with fourfold increases of keyword-matching activity from 2025 to 2026 in identified channels. As Telegram has increased support for automation and bot automations, these networks have proven only more resilient.
For corporate and private security teams alike, Telegram is likely to be a primary protective intelligence source for preventing insider recruitment, ensuring the physical security of executives and personnel, and defending against corporate cyberattacks across industries (including – but not limited to – payment processing, social media, e-commerce, gaming, and artificial intelligence).
2. Soyjak.party: Automated AI Doxxing Tools Lowering the Technical Barrier to Online Harassment
Soyjak.party is a fringe imageboard site known for hosting communities dedicated to “worshipping” mass shooters, which researchers have tied to successive shootings and bombings in 2024 and 2025, and for its numerous targeted harassment campaigns known as “raids.” While the site’s users have primarily targeted private individuals, they’ve recently developed tools that collapse the usual effort required to do so. Our researchers have already observed these tools beginning to spread off-platform, suggesting they could soon be used against targets deemed “higher value.”
In July, our researchers showed that Soyjak.party users had developed several AI-powered doxing tools since October 2025, among them a “fully autonomous” tool for assembling a given target’s private identifying information (PII) into a complete “dox report” using previously breached account information from breach databases. While breach databases sometimes contain only partial or outdated PII on a given target, we also identified Soyjak.party users combining various old data fragments (eg, IP geolocations, birthdays, family members) to successfully identify and attack new targets.
While executives and corporate personnel can use online data removal tools to protect their privacy and mitigate against online attacks, these tools do not remove access to previously breached data or prevent users from combining fragmented data into newly usable PII. While AI-doxxing remains largely limited to Soyjak.party thus far, the platform is still useful for security teams for monitoring these attack techniques before the spread elsewhere, and to identify pre-attack signals.
3. Scored/patriots.win: Dedicated User Base Crowdsourcing, Identifying, and Attacking Political Targets
Scored is a Reddit-style forum whose largest community is c/TheDonald (or “patriots.win”), a successor to the banned Reddit community r/TheDonald. Though overall activity on Scored peaked in 2020-2021, Similarweb data from July 2026 shows the site’s global ranking has quietly grown, with 92% of its traffic from the US and each site visits averaging 10 minutes (three times that of the average site visit on Truth Social), suggesting an unusually dedicated user base.
Our researchers previously examined Scored activity ahead of the January 6 insurrection and identified elevated activity, including posts discussing attacks against journalists and planned infrastructure attacks. Additionally, we observed users deanonymizing political and business figures using OSINT techniques to coordinate campaigns and attacks against them. Unlike sites like 4chan and Soyjak.party, where discussion threads are automatically archived upon hitting a certain post limit, threads on Scored are persistent and searchable, with upvotes from dedicated users increasing their visibility and keeping threats active. Ahead of the upcoming US election, security and safety teams are likely to benefit from monitoring Scored for advance warning of similar demonstrations and attacks.
4. TikTok: Attack Surface for Coordinated Campaigns Targeting Minors by State-Aligned Actors
Though TikTok is primarily a popular video streaming platform, the extensive metadata it collects from users have made it a growing vector for a wide range of targeted influence operations. We’ve previously reported on domestic influence operations on TikTok, but recent investigations have revealed Russian, Chinese, and Iranian state interests’ operations on the platform as well.
Examples of successful recent state operations on TikTok include Russian campaigns to sway elections in Romania in 2024 and Moldova in 2025 (with follow-on attempts to mobilize protests in 2026) as well as PRC influence campaigns targeting US audiences. Various reports have shown TikTok is an initial surface for persuasion, with viewers often funneled to platforms like Telegram for “tasking.” Recent actions downstream of Russian and Iranian operations include a 17-year-old committing arson in Vilnius in 2024 and alleged reconnaissance operations by Dutch teens in 2025, both resulting in arrests.
While the FBI recently debunked claims that TikTok campaigns drove a spike in retail crime among teens in 2025 and 2026, narratives of state actors using the platform to influence teens are well documented and worth monitoring for security teams.
5. FashFront: Fascist Vetting and Recruitment into Organized Violence and Infrastructure Attacks
FashFront, a small but concentrated neo-Nazi forum, emerged in 2025 as a place for self-described “fascists to network.” Previously identified as part of the now-defunct Terrorgram network, the site remains active as a space for vetting and recruiting users and funneling them into more private forums for planning and executing hate crimes and terroristic attacks.
According to a 2026 study, 31 of the 38 attacks on US infrastructure between 2020 and mid-2025 were organized by far-right actors. Likewise, on FashFront, users have previously been observed posting the coordinates and addresses of dozens of US electrical substations. As recent reports suggest the site’s influence may be growing, monitoring the site may provide helpful early warning signals for security and supply chain teams.
6. Disqus: An Underestimated Resource for Identifying Cross-Platform Threats
On its own, Disqus, a third-party platform for commenting on news blogs, is the largest platform of its kind, integrated into hundreds of fringe sites. Across all Disqus-enabled sites, users comment from only one username, and each comment is date-stamped and geolocatable. As a result, each user leaves a persistent, complete, and sometimes decades-long comment history behind them that security teams can analyze. As one Swedish research team demonstrated in 2013, these data trails can help analysts identify cross-platform threats much more easily.
While Disqus is unlikely to help analysts identify threat actors on its own, the platform’s data features offer an unusually extensive look at individual actors’ online activity across many different sites. Though fringe sites are beginning to disintegrate from Disqus for security reasons, the platform’s full archive of more than 270 million comments remains searchable in Open Measures’ platform.
In order to interrupt and disrupt emerging threats, security teams protecting executives, supply chains, and political figures need immediate alerts. While monitoring major platforms can provide a pulse, responding to time-sensitive situations often requires a broader field of view. With Open Measures’ platform, security teams can access additional insights from fringe platforms to fill in crucial context when they need it most.
Identify online risks with the Open Measures platform.
Organizations use Open Measures every day to track trends related to networks of influence, coordinated harassment campaigns, and state- backed info ops. Click here to book a demo.
