The most immediate effect of artificial intelligence on cybercrime may not be the invention of entirely new attacks. It may be the removal of time from familiar ones, giving criminals the ability to develop, test and revise malicious tools before many organizations can recognize that an operation is underway.
Sophos says attackers are increasingly using AI to compress workflows that once required weeks into operations that can become ready within days. Faster development and continuous iteration are shrinking the window available for security teams to identify malicious activity, investigate alerts and contain attackers before systems are compromised.
Sophos released its AI Security 2026 report in Dubai on July 28. The research found that attackers were moving beyond experimentation and integrating AI directly into operational campaigns, turning the technology into a practical force multiplier rather than merely a source of speculative future risks.
Identity has simultaneously emerged as the principal entry point into enterprise networks. Criminals are targeting AI agents, OAuth connections, application programming interfaces and development tools that may possess extensive permissions while remaining poorly governed. The emerging contest is therefore not simply between better models and better security software. It is a race between machine-speed attacks and organizations still relying on human-speed controls.
Attacks move faster
John Peterson, chief technology officer at Sophos, said attackers still require initial access, lateral movement and observable channels through which they can remove data. Those fundamentals have not disappeared simply because AI has entered the workflow.
What has changed, Peterson said, is the speed at which malicious tools can be designed, tested and improved. Sophos described AI as an operational force multiplier capable of shortening development cycles and reducing the time available to defenders.
The report identified several ways the threat environment is changing. AI is accelerating operational readiness, while enterprise AI identities, agents, OAuth tokens, APIs and development tools are becoming valuable targets.
AI-assisted social engineering and deepfakes have also moved into active criminal use. Threat actors are incorporating the technology into underground markets, recruitment, prompt engineering, model jailbreaking, malware-development workflows and commercial criminal services.
At the same time, attackers are increasingly targeting the infrastructure and supply chains used to build and operate AI systems. That broadens the security boundary considerably. Protecting the final model is no longer sufficient when credentials, connectors, repositories and development environments can provide easier routes into the same organization.
Agents build evasion
One of the report’s most significant findings involved a campaign Sophos tracks as STAC6994, which the company described as one of the first demonstrable cases of AI being actively incorporated into cyberattack operations.
The threat actor was running what resembled a software-development operation inside a customer’s network. Approximately 12 AI agents were used to write and test attacks against endpoint-security products, including systems provided by Sophos, CrowdStrike and Microsoft Defender.
The operation produced nearly 80 modules covering more than 70 evasion techniques. Sophos said activity that could have required a human operator approximately one week was completed within several days.
The significance did not come from an entirely unfamiliar attack method. Instead, AI allowed the actor to create multiple variations, test them against several security products and rapidly revise unsuccessful attempts. Coordinated agents could divide work that might otherwise require separate people to write code, test defenses, document failures and prepare new versions.
Sophos also introduced an important note of caution. Its researchers said the campaign’s documentation claimed near-universal endpoint-detection evasion after repeated testing, but the recorded output did not support that claim. Some of the apparent success may therefore have reflected AI-generated exaggeration or hallucination rather than demonstrated bypasses. Sophos’ technical analysis nevertheless shows how agents can materially accelerate the experimentation surrounding an attack.
Sophos said its intelligence collection allowed researchers to remain ahead of the campaign and defeat its attacks before the techniques were distributed more widely. That outcome offers some reassurance, but it also illustrates the scale of the challenge. AI does not need to produce flawless attacks to change cybercrime. It only needs to make experimentation cheaper, faster and more accessible.
Read more: Nvidia launches 40-company Open Secure AI Alliance after Hugging Face hack
Identity becomes target
Sophos identified enterprise AI adoption as the fastest-growing source of new exposure. Coding assistants, autonomous agents and open-weight models can receive privileged access to source code, cloud environments, internal databases and business applications.
That access turns the credentials and permissions surrounding each system into potential entry points. Attackers are therefore targeting the trust layer around AI rather than concentrating exclusively on weaknesses in the models themselves.
AI agents, OAuth connections and API keys may provide persistent access while allowing activity to appear as though it originated from a legitimate enterprise service. Compromised OAuth tokens can allow criminals to enter applications without stealing a conventional password. Exposed API keys may provide direct access to services, data or computing resources.
Poorly governed agents can present an even larger problem when their permissions extend far beyond the task they were created to perform. An assistant intended to summarize documents, for example, may also possess access to shared drives, messaging platforms, customer records or software repositories.
Criminals are consequently compromising AI service credentials, developer tools and exposed infrastructure to establish new pathways into enterprise networks. Sophos said the trend demonstrates that AI security is now an identity, governance and supply-chain issue as much as a question of model behavior.
Deepfakes scale scams
Generative AI is also reducing the cost and effort required to create convincing social-engineering operations. Sophos said AI-assisted scams can be adapted across languages, maintained over long periods and personalized for individual targets.
Deepfake audio, images and video can reinforce false identities or create the impression that victims are dealing with legitimate executives, advisers or organizations. Yet the technology’s role extends beyond producing a fabricated voice recording or a single persuasive email.
One incident highlighted in the report involved a UK-based victim who was drawn into a fraudulent AI-themed investment platform. The operation continued for months and used coordinated messaging and lessons about artificial intelligence to establish credibility. The victim ultimately lost hundreds of thousands of pounds.
The example demonstrates how AI can help criminals maintain a consistent narrative, create apparently educational material and continue personalized conversations until a target transfers money or discloses sensitive information.
Scams may therefore scale without becoming obviously automated. Criminals can use AI to improve language quality, answer questions more quickly and manage multiple victim relationships simultaneously. The technology increases not only the volume of possible fraud but also the patience and consistency with which individual victims can be pursued.
Supply chains exposed
AI development infrastructure is becoming a direct target as companies connect models with software repositories, coding environments, data stores and external tools.
Sophos documented attacks involving compromised developer tools and credential-stealing malware. It also identified growing risks surrounding model weights, the origin and integrity of training data, Model Context Protocol servers and inference infrastructure.
A compromised component could expose prompts, credentials, internal code or information processed by downstream users. The risk becomes more difficult to manage when an organization relies on several model providers, open-source packages and third-party connectors within the same workflow.
AI agents can also take actions automatically through connected tools. A malicious instruction concealed in a document, webpage or compromised service could influence an agent with permission to read files, send messages or modify business systems.
This means the security boundary must extend well beyond the model. Organizations need to assess the infrastructure hosting AI, the identities controlling it, the services connected to it and the software components used during development.
The number of dependencies matters because every connection introduces another trust decision. A company may carefully evaluate a model while overlooking the plug-in, API credential or development package through which an attacker ultimately gains access.
Defenders lose time
Peterson said AI security should no longer be treated primarily as a debate about speculative future systems. The technology is already being absorbed into criminal workflows, social-engineering campaigns, enterprise software development and identity systems.
The immediate challenge is how quickly companies can govern AI use and secure the identities and connections surrounding it. Faster attacks place greater pressure on detection and response. An organization that requires several days to review an alert may face an attacker capable of developing and testing multiple evasion methods during the same period.
Traditional controls also cannot be applied only to human users. Businesses increasingly need inventories of AI agents, service accounts, OAuth connections and API credentials, together with clear ownership and limits on the systems each identity can access.
Removing unused connections and applying the minimum permissions necessary can reduce the potential damage when one component is compromised. Short-lived credentials, stronger secrets management and regular access reviews can also prevent forgotten machine identities from becoming permanent entrances into the organization.
The underlying principle is straightforward. Every AI agent with permission to act should be treated as an operational identity, not merely as a software feature.
Evidence spans customers
The report draws on Sophos X-Ops Managed Detection and Response investigations, SophosLabs analysis, Counter Threat Unit intelligence, AI research and endpoint and network observations.
Those sources cover more than 625,000 Sophos customers worldwide, giving the findings a combination of incident-response evidence, technical analysis and observations from operating environments.
Sophos is headquartered in Oxford, United Kingdom, and provides cybersecurity products and services to more than 625,000 organizations. The company describes its approach as combining agentic AI with human expertise to detect, investigate and neutralize threats.
The report’s central conclusion is that AI is changing the economics and timing of cybercrime before fundamentally replacing established attack techniques. Attackers still need credentials, vulnerable services and access to enterprise systems. AI is allowing them to search for those opportunities, develop tools and adjust operations at a speed many organizations are not yet equipped to match.
That distinction matters. The danger is not dependent on a hypothetical superintelligent system discovering an unprecedented vulnerability. It can emerge from ordinary criminals using commercially available tools to perform familiar work more efficiently.
Identity gap widens
Separate Sophos research provides further evidence that enterprise identity controls are struggling to keep pace with expanding human and machine access.
The Sophos State of Identity Security 2026 found that 71 percent of 5,000 surveyed organizations experienced at least one identity-related breach during the previous year. Affected organizations reported an average of three incidents.
Non-human identities, including API keys, service accounts and AI agents, can outnumber human identities by as much as 100 to one. Weak management of these identities contributed to 41 percent of successful identity breaches, yet only approximately 34 percent of organizations regularly audited or rotated service accounts and other non-human credentials.
The research estimated that rectifying a successful identity breach cost an average of $1.64 million. Smaller organizations were also almost twice as likely as companies with more than 1,000 employees to fail to detect an identity attack.
The figures reveal a structural mismatch. Enterprises are creating machine identities at increasing speed, but the processes used to discover, classify, monitor and retire those identities remain incomplete. An organization cannot meaningfully enforce least privilege if it does not know how many agents or service accounts are operating.

Ransomware confirms shift
Sophos’ State of Ransomware 2026 found that 79 percent of ransomware attacks began with an identity-based approach, replacing exploited vulnerabilities as the dominant initial-access vector.
Multi-factor authentication was deployed in some capacity during 97 percent of incidents in which compromised credentials were identified as the root cause. Sophos said the result showed that MFA alone was insufficient when coverage gaps, weaker methods or poorly protected access points remained.
A separate Sophos analysis of 661 incident-response and managed-detection cases found that MFA was missing where it mattered in 59 percent of incidents. The two findings are not contradictory: one measures whether affected organizations used MFA somewhere, while the other examines whether it protected the particular access point criminals exploited.
Attackers encrypted data in 56 percent of surveyed ransomware incidents, including 16 percent in which information was both stolen and encrypted. Average recovery costs increased to $1.7 million per attack, excluding any ransom payment.
Sophos recommended phishing-resistant authentication, regular reviews of human and non-human identities, stronger exposure management and closer integration between firewall, endpoint, detection and managed-response systems. The broader lesson is that isolated controls create gaps attackers can cross, even when each control appears to exist on paper.
Governance turns operational
The governance challenge extends beyond any single cybersecurity provider. Cisco’s State of AI Security 2026 said 83 percent of surveyed organizations planned to deploy agentic AI, but only 29 percent believed they were genuinely prepared to do so securely.
Cisco warned that rushed adoption was producing increasingly complicated supply chains and autonomous systems without sufficient testing, controls or accountability. The readiness gap suggests that many organizations are granting AI access to important workflows before establishing who owns the system, which data it may use or how its behavior will be monitored.
The NIST AI Risk Management Framework organizes AI risk management around four continuous functions—govern, map, measure and manage—rather than treating security as a final review immediately before deployment.
NIST’s approach requires organizations to identify where AI is being used, understand its permissions and dependencies, assess how risks change over time and respond when models, prompts, tools or operating conditions are modified.
Applied to Sophos’ findings, every AI agent should have a defined owner, limited credentials, monitored behavior and a clear process for removing access when its role changes. Without those controls, faster AI adoption can create precisely the ungoverned identities and connections attackers are learning to exploit.
The new clock
AI is changing the economics of cybercrime before it changes its fundamental objectives. Criminals still want credentials, access, data and money. The difference is that smaller groups can now test more ideas, personalize more scams and revise failing techniques at a pace previously associated with larger operations.
For defenders, the answer cannot be to match every malicious model with another model and assume the problem is solved. Faster detection must be accompanied by disciplined identity management, limited permissions, complete visibility and clear accountability for both human and machine actors.
The decisive cybersecurity advantage may increasingly belong to the side that recognizes and acts first. When attackers can turn weeks of preparation into days, an unreviewed alert, forgotten API key or overprivileged agent is no longer a minor governance weakness. It is time handed directly to the adversary.
Click Here For The Original Source.
