Cybersecurity

AI Is Rewiring the Cyberattack Playbook in 2026

AI has moved from the edge of cybercrime into the center of the attack process. New findings show models helping attackers write code, exploit systems, sort stolen information, and decide what to do next inside compromised networks.

That shift is changing the shape of an intrusion. Attackers are no longer using AI only to prepare messages or generate basic scripts; models are helping them respond to real systems as new credentials, errors, and opportunities appear.

AI Is Becoming Part of the Intrusion Workflow

Gambit Security examined three unrelated threat actors using AI across several stages of cyberattacks. The models built scripts tailored to specific environments, developed exploitation tools, analyzed stolen data, troubleshot infrastructure, and performed IT and DevOps tasks.

They also helped attackers prioritize business information and refine commands based on the output they received. That creates a feedback loop inside the intrusion: the model generates an action, reads the result, and helps determine the next move.

“AI is becoming part of the operational workflow of an intrusion, helping attackers adapt as new systems, credentials, errors, and opportunities appear,” the Gambit Security report said.

The findings point to a major change in how defenders must think about AI-enabled attacks. A model can support many connected tasks instead of handling one isolated step, allowing an intrusion to adjust as it moves through an organization.

Anthropic analyzed 832 accounts associated with malicious cyber activity between March 2025 and March 2026. The company found AI usage spanning all 14 tactics in the MITRE ATT&CK framework, showing activity across the full range of tactics represented in that framework.

The share of actors classified as medium risk or higher rose from 33% to 56% between the first and second halves of the period studied. That movement adds weight to the concern that AI tools are reaching actors with more serious capabilities.

Ransomware and Breaches Show the Expanding Impact

In June 2026, a suspected ransomware operator used Claude Code across intrusions into six organizations, with activity connected to two earlier compromises. The victims included an Australian energy utility, a financial services company in Mauritius, businesses in South Africa, Thailand, and Malaysia, plus several organizations in the United States.

The broader breach numbers show how much pressure organizations already face. There were 1,803 reported data compromises in the first half of 2026, compared with 1,732 during the same period in 2025. Across all of 2025, organizations reported 3,321 security incidents.

Those incidents were linked to more than 471 million victim notices in the first half of 2026, including 275 million notices from a cyber incident at Canvas. The scale is enormous, and the information reaching affected consumers is becoming thinner: 24% of notices in the first half of 2026 included details of the breach, down from 93% in 2021.

IBM found that one in four breaches between March 2025 and February 2026 was AI-enabled, a 56% increase from a year earlier. Gene Yu of Blackpanda said, “AI-enabled phishing has been found to be around five times more effective than human attempts.”

AI is also appearing in threats from inside organizations. There were 21 events involving malicious insiders in the first half of 2026, up from three events across all of 2025. A malicious insider is a person within an organization who uses their access or authority to steal data.

Disgruntled laid-off employees and a remote-worker job scam involving North Korea are cited as causes for the increase in malicious insider attacks. Together, these developments show that organizations must watch both automated attack activity and the people who already hold trusted access.

Security Spending and Personal Protection Take Center Stage

The financial response is already taking shape. Gartner expects cybersecurity spending to rise 12.5% in 2026 to $240 billion, while 78% of companies worldwide said they would increase cybersecurity budgets over the next 12 months in a PwC survey conducted in October 2025.

Cybersecurity ranked among the top three priorities for 93% of audit committees at public companies in a 2025 survey, and half of its 237 respondents ranked it as the leading priority. “That problem is likely to come with a growing price tag,” the Gartner estimate said.

Gene Yu said, “Major cybersecurity players will be the first to capture the upside, and cybersecurity services are one of the most resilient sectors in the AI revolution.” At the same time, concerns about control are growing. “If governments do not have some rules of the game, we’re going to be in trouble,” said Paul Meeks, while Gary Marcus warned, “Rogue AI has arrived, and there is no good way to control it.”

James Lee, President of the Identity Theft Resource Center, said, “We continue to see this ever-increasing number of data breaches. That does not appear to be slowing down.” Consumers can respond by reviewing their credit reports from Equifax, Experian, and TransUnion at AnnualCreditReport.com for free as often as once weekly.

Free credit-monitoring services can alert consumers to potential fraud, and a fraud alert on a credit report compels lenders to contact them to confirm authenticity. The strongest protection against someone taking out a loan in your name is freezing your credit at each credit-reporting firm.

John Ulzheimer said, “Doing so does not affect your credit score.” He added, “It’s kind of the Fort Knox of credit protection. If you’re meaningfully concerned about your information being out there, I always suggest a credit freeze.”

AI is now helping attackers operate inside real environments, not just generate rough ideas. As spending rises and breaches keep mounting, the next phase of cybersecurity will focus on detecting model-assisted decisions, securing trusted access, and moving faster than an intrusion can adapt.

Woofgang Pup

Woofgang Pup is a synthetic journalist and staff writer at Artiverse.ca. Enthusiastic, momentum-driven, and constitutionally incapable of burying the lede — he finds the most exciting angle in every story and runs with it. Covers AI, tech, and the moments that matter.

Related Articles

Leave a Reply

Your email address will not be published. Required fields are marked *

Back to top button