• Home  
  • Sophos: AI accelerates cyberattacks as threat actors weaponize automation
- AI

Sophos: AI accelerates cyberattacks as threat actors weaponize automation

Artificial intelligence is rapidly transforming cybercrime, enabling threat actors to execute attacks in days instead of weeks, according to the latest AI Security 2026 Report from Sophos. The report found that AI’s most immediate impact is not the creation of new attack techniques but the acceleration of existing cyberattack workflows. Attackers are increasingly using AI […]

Artificial intelligence is rapidly transforming cybercrime, enabling threat actors to execute attacks in days instead of weeks, according to the latest AI Security 2026 Report from Sophos.

The report found that AI’s most immediate impact is not the creation of new attack techniques but the acceleration of existing cyberattack workflows. Attackers are increasingly using AI to speed up reconnaissance, testing, malware development, and evasion tactics, placing greater pressure on security teams to detect and respond before attacks succeed.

One of the report’s most significant findings involves a campaign tracked as STAC6994, where threat actors reportedly used around 12 AI agents to develop and test attacks against endpoint security platforms, including Microsoft Defender, CrowdStrike, and Sophos products. The operation generated nearly 80 attack modules and more than 70 evasion techniques, reducing development time from weeks to just a few days.

Sophos also highlighted the emergence of AI identities, OAuth tokens, AI agents, APIs, and developer tools as high-value targets for cybercriminals. As enterprises increasingly deploy AI-powered assistants and coding agents with privileged access to business systems, attackers are exploiting weak governance and compromised credentials to gain entry into corporate environments.

The report further revealed that identity-based attacks have become the primary initial access vector (IAV), reflecting a broader shift in cybercriminal tactics. Threat actors are targeting AI service credentials, OAuth connections, and exposed AI infrastructure to infiltrate enterprise networks.

Beyond enterprise environments, AI-powered social engineering and deepfake technologies are making online scams more convincing, scalable, and cost-effective. Sophos cited cases where AI-driven investment scams used coordinated messaging and AI-themed content to deceive victims into fraudulent platforms, resulting in significant financial losses.

The cybersecurity firm also warned that AI development infrastructure, including developer tools, model supply chains, training data sources, and inference systems, is becoming an increasingly attractive target for attackers.

Based on data from Sophos X-Ops, SophosLabs, the Counter Threat Unit (CTU), and telemetry gathered from more than 625,000 customers worldwide, the report underscores the growing need for organizations to strengthen AI governance, secure digital identities, and protect AI-enabled environments against rapidly evolving threats.


Email Us

For inquiries, press releases, and partnership request, get in touch with us at: info.aitimes.ph@gmail.com.

Contact: 0956-344-3286

AI Times  @2026. All Rights Reserved.