AI Is Collapsing Cyberattack Timelines From Weeks to Days, New Report Warns
Artificial intelligence is fundamentally changing the speed and scale of cyberattacks, compressing what once took weeks into just days. A new report from Sophos reveals that threat actors are now operationalizing AI as an active force multiplier in their criminal operations, marking a significant shift in how modern cybersecurity threats unfold.
How Fast Are AI-Powered Attacks Really Getting?
The Sophos 2026 AI Security Report uncovered a campaign tracked as STAC6994, which provides one of the first concrete demonstrations of AI being actively used to drive cyberattacks. The threat actor was running a software development operation inside a customer's network and deployed approximately 12 AI agents to write and test attacks against endpoint security tools, including Sophos, CrowdStrike, and Microsoft Defender. The result was striking: they produced nearly 80 modules and more than 70 evasion techniques in just a few days, a process that would have taken human attackers weeks to accomplish.
"For the first time we have observed AI being actively used as an operational force multiplier. While the tools and techniques were familiar, the speed of development, testing, and iteration was materially different. That is the AI threat that security teams need to prepare against," said John Peterson, Chief Technology Officer at Sophos.
John Peterson, Chief Technology Officer at Sophos
This acceleration matters because it dramatically shortens the window security teams have to detect and respond to threats. Defenders are now facing faster cycles and shorter response times, with greater pressure to contain activity before it causes damage.
What New Attack Surfaces Are Emerging From Enterprise AI Adoption?
As organizations rapidly deploy AI tools across their networks, they're inadvertently creating new vulnerabilities. Enterprise AI adoption is now the fastest-growing source of new security exposure, according to the Sophos report. Coding agents, AI assistants, and open-weight models are gaining privileged access to core systems, but governance hasn't kept pace with deployment.
Attackers are exploiting this gap by targeting the trust, credentials, and access permissions surrounding these AI systems. The result is a new high-value attack surface that many organizations haven't adequately secured:
- AI Identities and Agents: Enterprise AI identities, OAuth tokens, and AI agents are increasingly becoming primary targets for attackers seeking initial access to networks.
- Developer Tools and API Keys: Compromised OAuth tokens, AI service credentials, developer tools, and exposed AI infrastructure are creating new pathways into enterprise networks.
- Identity as the Primary Vector: For the first time in more than three years, identity has become the primary initial access vector, according to Sophos's 2026 State of Ransomware report.
This represents a fundamental shift in how attackers operate. Rather than inventing entirely new attack types, threat actors are leveraging AI to accelerate existing techniques and exploit the governance gaps around AI systems themselves.
How Are AI-Powered Social Engineering and Deepfakes Being Used in Real Attacks?
AI-assisted social engineering and deepfakes are no longer theoretical threats; they're operational tools actively being used in criminal campaigns. The Sophos report highlights a real-world example: an AI-themed investment scam that drew a UK-based victim into a fake AI-powered investment platform through months of coordinated messaging and AI-themed lessons. The victim ultimately lost hundreds of thousands of pounds.
These attacks are becoming more scalable and more convincing across different languages, while simultaneously becoming significantly cheaper to produce. The sophistication of AI tools is changing how social engineering attacks unfold, with threat actors exploiting trusted relationships among employee and executive networks to extract credentials or redirect payments without triggering a traditional data breach.
The scale of AI-enabled fraud is already widespread. According to Cisco's 2025 Cybersecurity Readiness Index, 86% of US business leaders with cybersecurity responsibilities have reported at least one AI-related incident in the past 12 months. In Canada, KPMG research published in March 2026 found that 81% of Canadian businesses that experienced fraud in the past year also faced an AI-enabled attack.
What Are Organizations Doing to Address This New Threat Landscape?
Some organizations are taking proactive steps to address AI-related cyber risks. BOXX Insurance, a global cyber insurtech company and part of Zurich Insurance Group, recently announced affirmative coverage for AI and deepfake-related events tied to social engineering and security failures within its commercial policy offering, Cyberboxx Business.
The move reflects a broader divide that has opened across the cyber insurance market since the start of 2026. While some carriers began explicitly excluding AI-generated deepfake fraud from standard social engineering coverage starting January 1, 2026, others like BOXX moved in the opposite direction, updating their social engineering insuring agreements to affirmatively include losses from AI-generated impersonation, including voice cloning and video deepfakes.
"Threat actors are exploiting trusted relationships amongst employee and executive networks which can result in handing over credentials or misdirecting payments without an actual breach. That's why we've updated our policy language to address the real risks that businesses, executives and their employees face in the age of AI," said Erik Tifft, global head of underwriting at BOXX Insurance.
Erik Tifft, Global Head of Underwriting at BOXX Insurance
The Canadian market is particularly focused on this issue. Canadians lost approximately $643 million to fraud in 2024, an increase of nearly 300% since 2020, according to the Canadian Anti-Fraud Centre. An RBC poll released in March 2026 found that 81% of Canadians feel a new scam emerges almost weekly, while 87% said it is getting harder to tell whether an online ad is genuine.
Steps Organizations Should Take to Defend Against AI-Powered Attacks
- Govern AI Identities and Access: Implement strict governance around AI identities, OAuth tokens, and API keys. Ensure that AI agents and development tools have only the minimum necessary permissions, and monitor their access patterns continuously.
- Accelerate Detection and Response Capabilities: Given that attackers can now compress attack timelines from weeks to days, organizations need to invest in faster detection and response mechanisms. This includes automated threat hunting and real-time monitoring of AI infrastructure.
- Secure AI Development Infrastructure: Protect the tools, supply chains, and infrastructure used to develop and deploy AI systems. This includes securing model weights, training data provenance, and inference infrastructure against compromise.
- Train Employees on AI-Powered Social Engineering: Since AI-assisted deepfakes and social engineering are now operational threats, regular training on recognizing sophisticated impersonation attempts is essential, particularly for executives and employees with access to sensitive systems.
The broader cybersecurity landscape continues to evolve as AI becomes embedded in both attack and defense operations. Organizations that can quickly govern their AI use, secure the identities and connections around it, and keep pace with attackers who are rapidly adopting new capabilities will be better positioned to withstand the threats ahead.