AI is speeding up cyberattacks, Sophos report warns
- Cyberattack, Cybersecuirty, Sophos
-
Photo courtesy of Pixabay
Cybercriminals are increasingly using artificial intelligence to shorten attack timelines and target poorly governed AI accounts, credentials, and systems, according to Sophos.
The cybersecurity firm’s AI Security 2026 Report found that attackers are moving beyond experimenting with AI and are now incorporating the technology into active cybercrime operations.
Rather than creating entirely new forms of attack, AI is helping threat actors develop, test, and deploy familiar techniques more quickly, reducing processes that previously took weeks to only a few days.
“Attackers still need initial access, still move laterally, and still exfiltrate through observable channels. What has changed is the clock,” Sophos Chief Technology Officer John Peterson said.
“For the first time we have observed AI being actively used as an operational force multiplier,” he added.
Sophos said the faster attack cycles give security teams less time to detect, investigate, and contain malicious activity before damage occurs.
The report also identified enterprise AI identities, including agents, OAuth tokens, application programming interface keys, development tools, and service credentials, as increasingly valuable targets.
As companies give AI assistants and coding agents wider access to internal systems, attackers are attempting to compromise the credentials and permissions connected to these tools.

Courtesy of Sophos
Sophos warned that governance and security controls are not keeping pace with the rapid adoption of AI in the workplace.
The company said criminals are creating new entry points into corporate networks by targeting OAuth tokens, exposed AI infrastructure, developer tools, and credentials used by AI services.
This makes AI security an issue involving identity management, governance, and software supply chains, rather than only the behavior or security of AI models.
The report highlighted a campaign tracked as STAC6994, in which a threat actor allegedly used around 12 AI agents inside a customer’s network to develop and test attacks against endpoint security products.
According to Sophos, the operation produced nearly 80 modules and more than 70 evasion techniques targeting security tools from Sophos, CrowdStrike, and Microsoft Defender.
The use of AI reportedly reduced a development process that could have taken human operators several weeks to only a few days.
Sophos said its intelligence gathering allowed it to identify and block the techniques before they were deployed more widely.
The report also found that AI-assisted social engineering and deepfake technology are making scams cheaper to produce, easier to scale, and more convincing across different languages.
One case involved a United Kingdom-based victim who was directed to a fake AI-powered investment platform following months of AI-themed lessons and coordinated messages. The victim eventually lost hundreds of thousands of pounds, according to the report.
Sophos also warned that AI development infrastructure is being targeted through compromised developer tools and credential-stealing malware.
Other emerging risks include attacks involving model files, training data, Model Context Protocol servers, and the infrastructure used to operate AI systems.
“AI security is no longer just about model behavior or speculative future risks,” Peterson said.
“AI is actively being absorbed into criminal workflows and social engineering operations, as well as into enterprise software development and identity systems within legitimate organizations,” he added.
The report was based on Sophos X-Ops Managed Detection and Response cases, SophosLabs analysis, Counter Threat Unit intelligence, AI research, and endpoint and network observations involving more than 625,000 customers worldwide.
