Sophos report warns AI is compressing cyberattack timelines and expanding identity risks

0

Sophos has released its AI Security 2026 report, warning that threat actors are using artificial intelligence to shorten attack development cycles from weeks to days and to expand identity-focused intrusion paths into enterprise environments.

The company said attackers are moving beyond experimenting with AI and are now “operationalising” it to accelerate malware development, automate testing and improve social engineering at scale. According to the report, AI’s most immediate impact on cybercrime is speed rather than the creation of entirely new attack techniques, with identity increasingly used as the primary initial access vector.

“Attackers still need initial access, still move laterally, and still exfiltrate through observable channels. What has changed is the clock,” said John Peterson, chief technology officer at Sophos. “For the first time we have observed AI being actively used as an operational force multiplier. While the tools and techniques were familiar, the speed of development, testing, and iteration was materially different.”

Sophos’ report lists key findings including compressed attack timelines; increased targeting of enterprise AI identities, OAuth tokens, agents, APIs and development tools; and the use of AI-assisted social engineering and deepfakes as operational tools. It also points to AI being incorporated into underground markets and criminal services, and to growing targeting of AI development infrastructure and supply chains.

In one case described in the report, Sophos said it observed a campaign tracked as STAC6994 running what it described as a software development operation inside a customer network. Sophos said the threat actor used around 12 AI agents to write and test attacks against endpoint agents, including Sophos, CrowdStrike and Microsoft Defender. The report claims the actor produced nearly 80 modules and more than 70 evasion techniques, reducing work that would have taken weeks to “a few days”.

The report also argues that enterprise AI adoption is creating new exposure as coding agents, assistants and open-weight models gain privileged access to core systems. Sophos said attackers are targeting the credentials and access permissions around these systems, making AI identities, agents, OAuth connections and API keys a growing attack surface, while governance lags.

Separately, Sophos said AI-assisted social engineering and deepfakes are making scams more scalable, convincing across languages and cheaper to produce. The report cites an AI-themed investment scam in which a UK-based victim was allegedly drawn into a fake AI-powered investment platform through months of AI-themed lessons and coordinated messaging, ultimately losing “hundreds of thousands of pounds”.

“This report makes clear that AI security is no longer just about model behavior or speculative future risks,” Peterson said. “AI is actively being absorbed into criminal workflows and social engineering operations, as well as into enterprise software development and identity systems within legitimate organisations.”

Sophos said the report is based on findings from Sophos X-Ops Managed Detection and Response casework, SophosLabs analysis, Sophos Counter Threat Unit intelligence, Sophos AI research, and endpoint and network observations across more than 625,000 customers worldwide.

You can read the full report here.

Share.