AI shrinks cyberattack timelines as attackers target AI identities, Sophos report finds
Artificial intelligence (AI) is accelerating cyberattacks by significantly reducing the time required to develop and deploy malicious tools, according to a recent Sophos AI Security 2026 Report. The report says cybercriminals are using AI to streamline existing attack techniques rather than invent entirely new ones, while increasingly targeting AI identities, OAuth tokens, APIs, and development infrastructure.
The findings are based on intelligence from Sophos X-Ops Managed Detection and Response (MDR), SophosLabs, the Sophos Counter Threat Unit (CTU), AI research, and telemetry collected across more than 625,000 customer environments worldwide.
John Peterson, Chief Technology Officer, Sophos, said attackers are using AI primarily as a force multiplier.
“Attackers still need initial access, still move laterally, and still exfiltrate through observable channels. What has changed is the clock. For the first time we have observed AI being actively used as an operational force multiplier. While the tools and techniques were familiar, the speed of development, testing, and iteration was materially different. That is the AI threat that security teams need to prepare against.”
AI is accelerating existing attack techniques
A key finding in the report is the identification of a threat campaign tracked as STAC6994, which Sophos says provides one of its first confirmed observations of attackers operationally using multiple AI agents during an intrusion.
According to Sophos, the threat actor deployed approximately 12 AI agents inside a compromised customer environment to develop and test attacks against endpoint security products, including Sophos, CrowdStrike, and Microsoft Defender. The AI agents reportedly generated nearly 80 attack modules and more than 70 evasion techniques, reducing development timelines from weeks to just a few days.
Sophos said the intelligence gathered during the operation enabled its researchers to identify and counter the techniques before they were deployed in broader attacks.
The report also notes that AI is increasingly being incorporated into underground criminal ecosystems, including malware development, prompt engineering, jailbreak techniques, recruitment, and cybercrime-as-a-service offerings.
AI identities emerging as a new enterprise risk
Beyond offensive AI use, Sophos highlights enterprise AI adoption as an expanding security challenge.
As organizations deploy AI coding assistants, autonomous agents, and open-weight models with privileged access to business systems, attackers are increasingly targeting the identities and credentials associated with these services. The report identifies AI identities, OAuth connections, API keys, developer tools, and AI infrastructure as growing attack surfaces that many organizations have yet to govern effectively.
Sophos also points to AI-powered social engineering and deepfakes becoming operational tools for cybercriminals. The report cites an investment fraud case in which a UK victim was persuaded over several months through AI-themed educational content and coordinated messaging before losing hundreds of thousands of pounds.
The findings align with the company’s recently released State of Ransomware 2026 report, which found that identity-based attacks have overtaken exploited vulnerabilities as the leading initial access vector for ransomware incidents. Malicious email accounted for 26% of attacks, phishing 24%, and compromised credentials 23%, meaning identity-based techniques contributed to 79% of ransomware intrusions.
Peterson said organizations should shift their focus beyond AI models themselves and secure the identities, credentials, and governance surrounding enterprise AI deployments.
“This report makes clear that AI security is no longer just about model behavior or speculative future risks. AI is actively being absorbed into criminal workflows and social engineering operations, as well as into enterprise software development and identity systems within legitimate organisations. That means the threat is in the here and now. As frontier models continue to advance, the next few months will be defined by how quickly organizations can govern AI use, secure the identities and connections around it, and keep pace with attackers who are capable of rapidly adopting new capabilities.”