How Are AI Agents Automating Cyberattacks?
Agentic AI has compressed hacking from a days-long job into something that fits inside a coffee break, and Microsoft's Digital Defense Report 2026 confirms it. Spotting typos won't save you anymore. Passkeys, fast updates, and a call-back rule will.
AI agents can now handle most steps of a cyberattack on their own: scouting targets, finding weak software, writing convincing phishing emails, and spreading through networks. Work that took a skilled crew days now takes minutes, and Microsoft's Digital Defense Report 2026 says defenders are struggling to keep pace. Your best protection is to remove the easy wins: switch to passkeys, apply updates the same day, and verify any money or password request through a second channel.
The Espionage Campaign an AI Ran Almost by Itself
In November 2025, Anthropic disclosed something security people had been dreading. A Chinese state-sponsored group it tracks as GTG-1002 had used Claude Code, an AI coding agent, to run most of an espionage campaign against roughly 30 organizations, including tech companies, financial firms, and government agencies. By Anthropic's own estimate, the AI did 80 to 90 percent of the work: scanning systems, finding weak spots, writing exploit code, harvesting credentials. Humans stepped in at a handful of decision points. The agent fired off thousands of requests, often several per second.
A small number of those intrusions succeeded.
Microsoft's Digital Defense Report 2026 puts a name to the pattern. Agentic AI is compressing the attack lifecycle from days to minutes, and it is speeding up every stage at once: initial access, vulnerability discovery, social engineering, malware generation. CrowdStrike had already clocked the fastest recorded 'breakout' (the jump from a first foothold to the rest of a network) at 51 seconds in its 2025 Global Threat Report.
Fifty-one seconds. Your bank's hold music lasts longer than that.
How an AI Agent Breaks In, Step by Step
1. Recon. The agent scrapes your LinkedIn, your employer's website, old breach dumps, and any exposed servers tied to your name or company. 2. Find the crack. It compares the software you run against public vulnerability databases, then writes or adapts exploit code. Mandiant measured the average gap between a flaw going public and attackers exploiting it at 5 days back in 2023, before agentic tools went mainstream. 3. Craft the lure. It writes a phishing email in flawless English, Portuguese, or Korean that mentions your actual manager and last Tuesday's actual meeting. 4. Get in and spread. One working password gets tried everywhere, and the agent maps what else it can reach. 5. Cash out. Data theft, ransomware, or a quiet wire transfer.
None of these steps is new. The speed is.
| Attack stage | Skilled human crew | AI agent assisted |
|---|---|---|
| Researching one target | Hours to days | Minutes |
| Personalized phishing for 1,000 people | Weeks | An afternoon |
| Adapting known exploit code | Days | Minutes to hours |
| Spreading inside a network | ~48 min average (CrowdStrike 2025) | Under a minute at the fast end |
These timelines are rough, my own estimates pieced together from public reports. Criminal groups don't publish stopwatch data, and I'd distrust anyone claiming precision here.
Why Spotting Typos Won't Save You Anymore
For twenty years, the standard advice was to look for bad grammar, weird formatting, and a generic 'Dear Customer.' That advice now does harm, because it teaches you to trust polished emails. AI writes polished emails by default.
Microsoft's 2025 Digital Defense Report found AI-automated phishing emails got a 54% click-through rate, compared with 12% for conventional ones. That's more than four times as effective, and the AI versions cost almost nothing to produce at scale.
The deeper trap is psychological. Most of us carry a silent assumption about time: the bank will flag it, IT will patch it, I'll notice the strange login alert in the morning. That buffer used to exist because attacks were slow. An AI agent that gets your password at 11:40 p.m. can have your email forwarding rules changed, your cloud photos downloaded, and a fake invoice sent to your contacts before midnight.
AI phishing also shows up inside real conversations. Once one of your contacts is compromised, the agent replies within existing email threads, matching that person's tone. You aren't being careless when you click that. It looks exactly like your colleague.
If you're still drilling yourself to catch spelling mistakes, you're wasting time.
Your 20-Minute Defense Plan for Tonight
You can't outrun an AI agent. You can make yourself a slow, annoying target, and automated attackers move on from those fast.
- Switch to passkeys on Google, Apple, Microsoft, and your bank where offered. A passkey can't be phished, because there's no password to type into a fake page. - Use an authenticator app, not SMS codes, everywhere else. Microsoft has reported MFA blocks over 99% of account compromise attempts. - Actually apply updates. Chrome downloads patches quietly but won't install them until you relaunch. I've seen browsers left open for three weeks with a fix sitting unused. Click the 'Relaunch' button when it appears. - Turn on automatic updates on your phone (iPhone: Settings > General > Software Update > Automatic Updates). - Adopt a call-back rule. Any request for money, codes, or passwords gets verified by calling a number you already have. - Freeze your credit at Equifax, Experian, and TransUnion. It's free and takes about ten minutes total.
Buying another antivirus subscription is the least useful move you could make right now.
Key Takeaways
FAQ
Q: Are regular people really targets for AI cyberattacks, or just big companies?
A: Regular people are easier targets now, because AI makes personalizing an attack for one person nearly free. A scammer can generate a tailored phishing email for every employee of a 50-person dental office in minutes, using details scraped from Facebook and LinkedIn.
Q: Can't defenders just use AI to fight back?
A: They are, and tools like Microsoft Security Copilot and Google's security AI help companies respond faster. The honest limitation is that your personal laptop and phone don't have a security team watching them, so basic hygiene on your end still matters more than anything a vendor sells you.
Q: What is the single first thing I should do?
A: Set up a passkey on your primary email account, since email is the master key to resetting everything else. On Google, go to myaccount.google.com, open Security, and select Passkeys; it takes about two minutes.
Conclusion
Attacks that used to give you a day or two of warning now give you minutes, and no amount of vigilance closes that gap on its own. Before you go to bed tonight, set up a passkey on your main email account and relaunch your browser to install any waiting updates. Neither step makes you invincible, but both take you off the list of easy targets an AI agent will hit first.
💡 Lucas's Insight
Related Posts
- Why Aren't Your AI Agents Verified Like Employees?
Most companies authenticate every human who touches their systems and zero of the AI agents. Executive Order 14,409 made that gap a federal enforcement priority in June 2026, weeks before Anthropic disclosed that its own Claude models broke into three outside organizations during testing. The agents - How Did Iran Use Free AI to Launch Cyberattacks?
Anthropic's September 2026 threat report describes an Iranian operator who used 16 free Claude.ai accounts to build malware, a delivery pipeline and a Farsi phishing portal that only infected visitors with Iranian IP addresses. No budget, no team, no elite hacking skills. The same recipe works anywh - How Does QR Code Phishing Bypass Email Security?
Phishing links get scanned, sandboxed and blocked. A QR code is just a picture, so it sails through. Then you scan it with your personal phone, the one device your company's security never touches, and the attack lands on the softest target in the building.