August 9, 2026
Special Report

AI Is Compressing Cyberattack Timelines And Creating New Attack Targets

Artificial intelligence is rapidly changing the economics and speed of cybercrime, with attackers moving beyond experimentation to operationalize AI across attack development, social engineering and evasion. According to the Sophos AI Security 2026 Report, the most immediate impact of AI on cybercrime is not necessarily the emergence of entirely new attack techniques, but the ability to compress attack workflows from weeks to days.

The report finds that identity is also emerging as a critical initial access vector, with enterprise AI identities, OAuth tokens, agents, APIs and development tools becoming increasingly attractive targets. As organisations deploy AI assistants and coding agents with access to sensitive systems, attackers are increasingly focusing on the credentials, permissions and trust relationships surrounding these technologies.

John Peterson, Chief Technology Officer, Sophos

“Attackers still need initial access, still move laterally, and still exfiltrate through observable channels. What has changed is the clock,” said John Peterson, Chief Technology Officer, Sophos. “For the first time we have observed AI being actively used as an operational force multiplier. While the tools and techniques were familiar, the speed of development, testing and iteration was materially different. That is the AI threat that security teams need to prepare against. It means faster cycles and shorter windows to respond, with greater pressure on defenders to detect and contain activity before impact.”

One of the report’s most significant findings comes from a campaign tracked by Sophos as STAC6994, which the company describes as one of the first provable demonstrations of AI being actively used as an operational force multiplier by a threat actor.

In the campaign, the attacker operated a software development operation inside a customer’s network and used approximately 12 AI agents to develop and test attacks against endpoint security products, including those from Sophos, CrowdStrike and Microsoft Defender. The operation produced nearly 80 modules and more than 70 evasion techniques. What might previously have taken human attackers weeks was compressed into just a few days.

The episode illustrates a fundamental shift in the cyber threat landscape. AI can enable attackers to rapidly develop, test and refine techniques, significantly shortening the time between experimentation and operational deployment. For security teams, that means traditional response cycles may no longer be fast enough.

The report also highlights the growing risks surrounding what it calls “AI identities”. As coding agents, AI assistants and open-weight models are increasingly given privileged access to enterprise systems, they create new pathways for attackers to enter corporate networks.

AI service credentials, OAuth tokens, API keys, developer tools and exposed AI infrastructure are becoming valuable targets. The challenge is compounded by the fact that governance and security controls around these new identities are often less mature than those surrounding conventional employee identities.

This makes AI security an issue that extends beyond model behaviour. It increasingly involves identity management, access governance, software development practices and supply chain security. Organisations will need to understand not only which AI tools their employees are using, but also what permissions those tools have, which systems they can access and how their connections are secured.

The growing use of AI is also making social engineering attacks more scalable and convincing. The report points to the increasing use of AI-assisted scams and deepfakes, which can be produced more cheaply and tailored across languages and geographies.

One case involved an AI-themed investment scam in which a UK-based victim was drawn into a fake AI-powered investment platform through months of AI-themed lessons and coordinated messaging. The victim ultimately lost hundreds of thousands of pounds.

At the same time, AI development infrastructure itself is becoming a target. Sophos highlights attacks involving compromised developer tools and credential-stealing malware, alongside growing supply-chain risks involving model weights, training-data provenance, MCP servers and inference infrastructure.

“This report makes clear that AI security is no longer just about model behavior or speculative future risks. AI is actively being absorbed into criminal workflows and social engineering operations, as well as into enterprise software development and identity systems within legitimate organisations. That means the threat is in the here and now,” said Peterson, adding, “As frontier models continue to advance, the next few months will be defined by how quickly organizations can govern AI use, secure the identities and connections around it, and keep pace with attackers who are capable of rapidly adopting new capabilities.”

The findings point to a growing imbalance between the speed at which enterprises are adopting AI and the pace at which they are building the necessary security and governance frameworks. As AI becomes embedded in software development, business processes and enterprise infrastructure, organisations will need to treat AI-related identities and connections as part of their core cybersecurity architecture.

The Sophos report draws on findings from its X-Ops Managed Detection and Response casework, SophosLabs analysis, Sophos Counter Threat Unit intelligence, AI research, and endpoint and network observations across more than 625,000 customers worldwide.

The message for businesses is clear: the AI security challenge is no longer a distant possibility. Attackers are already incorporating AI into their workflows, while legitimate organisations are creating new AI-enabled identities and access points that can be exploited. The ability to govern these systems, secure their identities and connections, and respond at machine speed could increasingly determine how effectively organisations defend themselves in the next phase of the cyber threat landscape.

Related Posts

Leave a Reply

Your email address will not be published. Required fields are marked *