AI SecurityIntermediateThreat7 validated evidence records

AI-Accelerated Cyberattacks

Also known as: AI-enabled attacks, AI-assisted cyber operations

30 sec

Cyber operations in which attackers use AI to increase the speed, scale, personalization, adaptability, or technical capability of reconnaissance, social engineering, exploitation, malware, or evasion.

Know

What is AI-Accelerated Cyberattacks?

AI acceleration does not replace established cyber techniques; it makes many of them cheaper and faster. Threat actors use models and agents to research targets, personalize lures, translate and rewrite content, analyze vulnerabilities, generate or modify code, automate infrastructure, create synthetic personas, and assist post-compromise operations.

Why it matters

CrowdStrike reported an 89% year-over-year increase in operations by AI-enabled adversaries in its 2026 Global Threat Report. Mandiant described a shift from experimental AI use to operationalized adaptive tools and agents, while Microsoft has documented AI use across phishing, identity fraud, and adversary tradecraft.

Evidence, not hype

Validated in the real world

Every record is labeled by evidence type and source strength so an incident, a standard, and emerging research are never presented as if they are the same thing.

Technical ValidationResearch / emerging practice

Google documents agent-enabled credential harvesting and AI resource theft

2026-09-08Google Threat Intelligence Group / Mandiant

Google's September 8 report describes a Q2 2026 case in which attackers compromised a cloud resource and planned, built, and executed an agent-enabled credential-harvesting campaign in under six hours. It also documents theft of AI credentials and unauthorized use of victim cloud resources.

Why this is evidence

The timeline describes one observed case, not an industry average or a claim that all attacks are autonomous. The report is newly published; the described activity occurred earlier.

See the source — Google Threat Intelligence Group / Mandiant: GTIG AI Threat Tracker: From Prompting to Autonomy – The Evolution of Adversarial AI
Technical ValidationMeasured outcome

CrowdStrike observed 15x device-code phishing growth, 2x vishing growth, and exploitation windows collapsing to hours

2026-08-03CrowdStrike Counter Adversary OperationsCross-sector

CrowdStrike's 2026 Threat Hunting Report says monthly device-code phishing attempts rose 15x in 1H 2026, vishing intrusions doubled, 88% of observed exploitation involving public PoC occurred within 48 hours, cloud-conscious eCrime rose 171%, and adversaries increasingly targeted AI systems and software dependencies.

Why this is evidence

These measurements validate several of the fastest-moving 2026 threat themes and show that attackers are abusing trusted authentication, cloud, AI, software, and newly disclosed vulnerabilities at increasing speed.

See the source — CrowdStrike: 2026 Threat Hunting Report
Technical ValidationOperational validation

Microsoft documented an AI-enabled device-code phishing campaign operating at scale

2026-04-06Microsoft Defender Security ResearchCross-sector

Microsoft observed a widespread campaign abusing OAuth device-code authentication with automated infrastructure, dynamic code generation, AI-personalized lures, token acquisition, automated reconnaissance, and malicious inbox-rule persistence.

Why this is evidence

The campaign demonstrates that a victim can complete authentication on a legitimate Microsoft page and still authorize an attacker's session, making modern phishing a token and workflow problem rather than only a fake-password-page problem.

See the source — Microsoft Security: Inside an AI-enabled device code phishing campaign
Technical ValidationMeasured outcome

2026 DBIR: vulnerability exploitation became the leading breach entry point

2026-06Verizon BusinessCross-sector

Verizon's 2026 DBIR overview reports exploitation of software vulnerabilities at 31% of breach entry points, third-party involvement at 48%, and employee use of unapproved shadow AI at 45%, alongside increasing AI-driven attack speed.

Why this is evidence

The DBIR provides broad breach-data evidence that vulnerability exploitation, third-party trust, and unmanaged AI use are not niche concerns in 2026; they are major enterprise exposure patterns.

See the source — Verizon: Vulnerability exploitation top breach entry point, 2026 DBIR finds
Technical ValidationMeasured outcome

CrowdStrike reported AI-enabled adversary operations up 89% year over year

2026-02-24CrowdStrikeCross-sector

CrowdStrike's 2026 Global Threat Report says AI-enabled adversary operations increased 89% year over year, average eCrime breakout time fell to 29 minutes, the fastest observed breakout was 27 seconds, and attacks increasingly traversed identity, SaaS, cloud, and unmanaged edge environments.

Why this is evidence

The report validates both the growing operational use of AI by attackers and the shrinking time defenders have to detect and contain intrusions.

See the source — CrowdStrike: 2026 Global Threat Report: AI Accelerates Adversaries and Reshapes the Attack Surface
Emerging / ResearchResearch / emerging practice

Mandiant described AI moving from experimentation into operational adversary tradecraft

2026-03-09Google Cloud / MandiantCross-sector

Mandiant's 2026 AI Risk and Resilience report describes attackers moving beyond basic LLM use into adaptive code rewriting and agent-like workflows, while warning that shadow AI and poor AI asset visibility create significant enterprise risk.

Why this is evidence

This distinguishes two different 2026 AI security problems: adversaries using AI to improve attacks, and organizations creating unmanaged attack surface through rapid AI adoption.

See the source — Google Cloud / Mandiant: AI Risk and Resilience
Government / AuthoritativeGovernment advisory

FBI warned that scammers were using AI-generated videos and voice cloning to impersonate trusted authorities

2026-07-20FBI Internet Crime Complaint CenterPublic / Cross-sector

The FBI warned of ongoing schemes impersonating IC3 and FBI personnel using AI-generated videos, spoofed websites, social media personas, and voice cloning. The advisory notes scammers can use synthetic media in real-time video chats and private communications to make fraudulent identities appear authentic.

Why this is evidence

This is direct government validation that synthetic media is being used operationally for impersonation and fraud, reinforcing the need for independent identity verification rather than trusting voice or video appearance.

See the source — FBI / IC3: FBI Warns of Scammers Impersonating the IC3

Understand the mechanics

How it works

  1. 1

    Use AI to gather and summarize target information.

  2. 2

    Generate personalized social-engineering or fraud content.

  3. 3

    Assist exploit research, scripting, or malware modification.

  4. 4

    Automate infrastructure and attack workflows.

  5. 5

    Adapt content and behavior based on victim or defender response.

  6. 6

    Scale operations that previously required more human time and expertise.

Practice

What to watch for

  • Highly tailored lures at unusual scale
  • Rapid infrastructure rotation
  • Automated attack sequences
  • AI service abuse linked to attacker-controlled credentials
  • Attack tooling that adapts quickly to controls

Perform

What to do

  1. 1

    Respond to the underlying attack technique rather than assuming AI changes incident fundamentals.

  2. 2

    Contain compromised identities, systems, tokens, or services.

  3. 3

    Preserve prompts, AI service logs, API activity, and generated artifacts when relevant.

  4. 4

    Increase response speed when automation is allowing rapid attacker iteration.

How to reduce the risk

  • Strong identity controls
  • Rapid vulnerability management
  • AI service logging
  • Abuse monitoring
  • Secure-by-design AI deployment
  • Human verification for high-impact actions
  • Machine-speed detection and containment

Business impact

  • Faster attack cycles
  • Higher campaign scale
  • More convincing social engineering
  • Reduced attacker skill barrier
  • Greater pressure on detection and response time

What different roles should do

Executive

  • Treat AI as both a productivity platform and an expanded security attack surface

Security

  • Measure whether detection and containment can keep pace with automated attack speed

Framework & standards context

  • NIST AI RMF
  • MITRE ATLAS

Keep learning

Source transparency

Authoritative sources

Last reviewed: 2026-09-02