All Articles

Cyber Security · September 2026

Encrypted malware detections jumped 1998% in three months

Attackers are hiding malware inside encrypted traffic at a scale nobody expected. Here's what changed, whether your firewall can see it, and what to do this week.

WatchGuard's latest Internet Security Report shows encrypted evasive malware detections up 1998% quarter over quarter. That's not a typo. Attackers are wrapping threats in the same encryption that protects your banking and email, and most firewalls let it sail through unchecked. If your firewall isn't inspecting encrypted traffic, you're running blind on most of what crosses your network.

Why attackers moved to encryption

Encryption is everywhere now. Your browser, your apps, your phone, all wrap data in HTTPS by default. That's good for privacy and terrible for visibility.

Attackers noticed. If they bury malware inside an encrypted connection, most firewalls treat it like any other secure request and wave it through. No inspection, no alert, no block.

The result is a 1998% jump in encrypted evasive malware in one quarter. Threats that used to get caught at the perimeter now walk in with a padlock icon.

Does your firewall inspect encrypted traffic

Most small and mid-sized businesses run a firewall. Not all of them inspect HTTPS traffic. Some models can't. Others can but the feature is turned off because it slows things down or nobody set it up.

If you don't know the answer, assume it's off. Check your firewall admin panel or ask whoever installed it. Look for terms like HTTPS inspection, SSL inspection, or deep packet inspection.

If the feature exists but isn't running, you're missing the majority of threats. The report shows encrypted attacks now outnumber everything else combined.

What this looks like in practice

You won't see a warning. An employee clicks a link in an email, visits a compromised site, or downloads a file that looks fine. The firewall logs the connection as encrypted and moves on.

A week later ransomware locks your file server, or someone logs into your bank with stolen credentials, or a client calls because they got a weird invoice from your domain.

The attack arrived days ago. Without inspection, the firewall had no chance to stop it and no log entry to trace it.

What to do this week

First, find out whether your firewall inspects encrypted traffic. If it does and it's running, you're already ahead of most businesses.

If it doesn't, or if your firewall is five years old and struggles with modern encryption standards, it's time to replace it. Newer models handle inspection without killing performance.

Second, check your endpoint protection. The report also shows blocked endpoint attacks up 1078%. That means threats are bypassing perimeter defences and getting caught on the device itself. If your firewall misses something, your endpoint agent is the last line.

Third, don't assume this is someone else's problem. The WatchGuard data comes from real small and mid-market customers. The 1998% increase hit businesses your size, not just enterprises with security teams.

When to call someone

If you're not sure what your firewall does, or if turning on HTTPS inspection sounds complicated, call someone who does this daily. It's a one-hour conversation and a config change, not a forklift upgrade.

If your firewall can't inspect encrypted traffic at all, plan a replacement in the next sixty days. The gap is too wide to ignore, and the cost of waiting is higher than the cost of new hardware.

You don't need to become a security expert. You need to know whether your firewall can see what's crossing your network, and if it can't, you need to fix that before the next quarterly report shows another four-digit percentage increase.

Sources

See our security services

Get started today

Have an IT Question?

Our team is ready to help, whether you need advice on cybersecurity, cloud strategy, or AI readiness.