Cybercriminals are using artificial intelligence to develop and test cyberattacks within days instead of weeks, while targeting the digital identities and credentials connected to enterprise AI systems, according to a new Sophos report.
The Sophos AI Security 2026 Report said AI’s immediate impact on cybercrime is accelerating existing attack methods rather than creating entirely new types of attacks.
“Attackers still need initial access, still move laterally, and still exfiltrate through observable channels. What has changed is the clock,” said John Peterson, chief technology officer at Sophos.
“For the first time we have observed AI being actively used as an operational force multiplier. While the tools and techniques were familiar, the speed of development, testing, and iteration was materially different.
“That is the AI threat that security teams need to prepare against. It means faster cycles and shorter windows to respond, with greater pressure on defenders to detect and contain activity before impact.”
Sophos cited a campaign it tracks as STAC6994, in which a threat actor allegedly operated a software development environment inside a customer’s network and deployed about 12 AI agents to write and test attacks against endpoint security products from Sophos, CrowdStrike, and Microsoft Defender.
The operation produced nearly 80 attack modules and more than 70 evasion techniques in a few days, work that Sophos said would have taken human operators weeks.
The findings indicate that generative and agentic AI tools can shorten the time required to develop, test, and prepare malicious software for deployment, reducing the window available to defenders to detect and contain an intrusion.
The report also identified AI identities as an emerging attack surface. As organizations give coding agents, digital assistants, and open-weight models access to internal systems, attackers are increasingly targeting OAuth tokens, API keys, AI service credentials, development tools, and other permissions associated with them.
Sophos said governance and security controls have not kept pace with the adoption of these systems. Compromised credentials and connections could allow attackers to exploit the access granted to AI agents without necessarily attacking the underlying AI model.
The company’s 2026 State of Ransomware report similarly found that identity had become the leading initial access vector for the first time in more than three years.
AI is also making social engineering and deepfake scams cheaper to produce and easier to scale across different languages, according to the report.
One case involved a fake AI-powered investment platform that used AI-themed lessons and coordinated messages over several months to deceive a victim in the United Kingdom. The victim eventually lost hundreds of thousands of pounds.
Attackers are also targeting AI development infrastructure, including developer tools, model weights, training data, Model Context Protocol servers, and systems used to run AI models.
“This report makes clear that AI security is no longer just about model behavior or speculative future risks. AI is actively being absorbed into criminal workflows and social engineering operations, as well as into enterprise software development and identity systems within legitimate organizations. That means the threat is in the here and now,” Peterson said.
“As frontier models continue to advance, the next few months will be defined by how quickly organizations can govern AI use, secure the identities and connections around it, and keep pace with attackers who are capable of rapidly adopting new capabilities.”
The report drew from Sophos managed detection and response cases, malware analysis, threat intelligence, AI research, and endpoint and network observations involving more than 625,000 customers worldwide.


