Loading...

Sophos unveils the report on AI security 2026

Sophos has released its AI Security 2026 Report, revealing that cybercriminals are increasingly using artificial intelligence (AI) to accelerate cyberattacks, significantly reducing the time required to plan, develop and execute malicious operations.

According to the report, AI’s biggest impact on cybercrime is not the creation of new attack methods but the speed at which existing attacks can be carried out. Sophos said attackers continue to rely on familiar techniques such as gaining initial access, moving across networks and stealing data, but AI has shortened attack timelines from weeks to just a few days.

Commenting on the findings, John Peterson, Chief Technology Officer, Sophos, said AI is now acting as an operational force multiplier for attackers, enabling faster development, testing and refinement of cyberattack techniques. He added that security teams now have much less time to detect and respond before attacks cause damage.

One of the report’s key findings is the discovery of a threat campaign, tracked as STAC6994, in which attackers reportedly used around 12 AI agents to develop and test attacks against endpoint security products, including Sophos, CrowdStrike and Microsoft Defender. The operation produced nearly 80 attack modules and more than 70 evasion techniques, compressing work that would normally take weeks into only a few days.

The report also highlights AI identities, including AI agents, OAuth tokens, API keys and AI service credentials, as an emerging attack surface. As organisations increasingly deploy AI-powered tools with access to critical systems, attackers are targeting these identities to gain entry into enterprise networks.

Sophos further noted that AI-assisted social engineering and deepfake technology have become practical tools for cybercriminals, enabling more convincing scams across multiple languages at lower costs. The report cites incidents where AI was used to support sophisticated investment scams and other fraud campaigns.

In addition, the report warns that AI development infrastructure, including developer tools, model supply chains, training data and inference infrastructure, is becoming an increasingly attractive target for attackers.

Sophos said the report is based on intelligence gathered from Sophos X-Ops Managed Detection and Response (MDR) investigations, SophosLabs, the Sophos Counter Threat Unit (CTU), AI research and security observations across more than 625,000 customers worldwide.

Send news announcements/press releases to:
editor@thefoundermedia.com

About The Author