AI-Powered Attacks Now Compress From Weeks to Days: What the Sophos 2026 Report Reveals
Artificial intelligence has fundamentally changed the speed and scale of cyberattacks, compressing what once took weeks into just days. According to Sophos' 2026 AI Security Report, released in July, attackers are now deploying autonomous AI agents to automate malware development, test evasion techniques, and exploit corporate identities at machine speed. The shift represents a critical inflection point for defenders, who must now operate faster than ever before.
How Are Attackers Using AI to Speed Up Cyberattacks?
The most immediate impact of AI on cybercrime is velocity. Sophos researchers tracked a real-world campaign called STAC6994, which used approximately 12 simultaneous AI agents to write and test attacks against major endpoint protection tools, including Sophos, CrowdStrike, and Microsoft Defender. In just days, these agents created nearly 80 modules and more than 70 techniques to evade detection, a feat that would have taken human attackers weeks to accomplish.
"Attacks are faster and cover more areas of the environment simultaneously," explained Alex Rose, a Sophos expert.
Alex Rose, Sophos Expert
The report identifies several ways attackers are weaponizing AI to accelerate their operations:
- Identity Theft as Primary Entry Point: For the first time in over three years, stolen or misused identities, including OAuth tokens, API keys, and corporate credentials, have become the main gateway for cyberattacks, replacing traditional vulnerability exploitation.
- Autonomous Malware Development: AI agents are automating the creation and testing of malicious code, allowing attackers to rapidly iterate and refine their tools against security defenses.
- Supply Chain Targeting: Attackers are directly targeting AI development infrastructure, stealing programming tools and injecting malware designed to harvest credentials from development environments.
- Mass Social Engineering: Deepfakes and AI-generated scams are now routine tools for large-scale criminal operations, making fraud more credible, scalable, and cheaper to execute across multiple languages.
Why Has the Attack Timeline Compressed So Dramatically?
The tipping point arrived in November 2025, according to Sophos CEO Joe Levy, when frontier AI models evolved from simple assistants into autonomous agents capable of executing multi-step tasks independently. This same capability that benefits defenders also empowers attackers, but without the friction of procurement processes, legal reviews, or board approvals.
"For Defense teams, this is the most powerful tool we have ever had to close the capabilities gap and integrate CISO-level judgment into systems operating at machine speed. For attackers, it means the same power, but without the frictions of procurement processes, legal reviews, or board approvals," stated Joe Levy, CEO of Sophos.
Joe Levy, CEO of Sophos
John Peterson, Chief Technology Officer of Sophos, emphasized the severity of this acceleration. "Attackers still need a door in, they still move laterally within the network, and they still steal information through channels we can monitor. What has changed is the clock," he noted. This compression of timelines means defenders have less time to detect, respond to, and contain attacks before they cause damage.
John Peterson, Chief Technology Officer of Sophos
What Are the New Targets and Vulnerabilities?
As organizations rapidly deploy AI tools and autonomous agents, they are inadvertently creating new attack surfaces. AI identities, OAuth connections, API keys, and development tools are increasingly becoming high-value targets for attackers. The report highlights that AI adoption in companies is now the fastest-growing source of new risks, as programming assistants and autonomous agents gain elevated permission access to critical systems.
One striking case involved an AI-based investment fraud that deceived a victim in the United Kingdom into believing they were participating in a legitimate AI investment platform. Through months of fake lessons and coordinated AI-generated messages, the attacker convinced the victim to invest hundreds of thousands of British pounds before the fraud was discovered.
Steps to Strengthen Your Organization's AI Security Posture
- Implement Identity and Access Management: Prioritize monitoring and controlling OAuth tokens, API keys, and AI service credentials, treating them with the same rigor as traditional user accounts and administrative access.
- Deploy Unified Detection Systems: Move beyond disconnected security tools that only perceive fragments of your environment. Invest in integrated platforms capable of visualizing the entire attack surface and responding in a coordinated manner.
- Monitor AI Development Infrastructure: Secure your AI development tools, training environments, and model repositories against credential theft and malware injection, as attackers are now directly targeting these systems.
- Accelerate Incident Response Capabilities: With attack timelines compressed to days, traditional incident response processes are no longer sufficient. Organizations must adopt faster detection and response mechanisms, potentially including AI-assisted security tools.
The Sophos report is based on analysis of real cases handled by the company's Managed Detection and Response (MDR) service, investigations by SophosLabs, threat intelligence from the Threat Analysis Unit, and monitoring of networks and devices across more than 625,000 customers worldwide. This extensive real-world data provides credible evidence that AI-accelerated attacks are not theoretical threats but active dangers in production environments today.
As AI continues to evolve, the security industry faces a critical challenge: defenders must adopt AI-powered tools and autonomous agents at the same pace as attackers, while maintaining oversight and control. The gap between AI deployment speed and security readiness remains a significant vulnerability that organizations must address urgently.