Compressing cyberattack timelines and targeting ungoverned AI identities

July 2026 Information Security, News & Events

Sophos has released its AI Security 2026 Report, finding that attackers are operationalising artificial intelligence (AI) to collapse attack workflows from weeks to days. The report finds that AI’s most immediate impact on cybercrime is speed, as well as a rise in attacks using identity as the primary initial access vector (IAV), rather than inventing new attack types at this stage.

“Attackers still need initial access, still move laterally, and still exfiltrate through observable channels. What has changed is the clock,” said John Peterson, chief technology officer, Sophos. “For the first time we have observed AI being actively used as an operational force multiplier. While the tools and techniques were familiar, the speed of development, testing, and iteration was materially different. That is the AI threat that security teams need to prepare against. It means faster cycles and shorter windows to respond, with greater pressure on defenders to detect and contain activity before impact.”

Key findings

• AI is compressing attack timelines and accelerating operational readiness.

• Enterprise AI identities, OAuth tokens, agents, APIs, and development tools are becoming high-value targets.

• AI-assisted social engineering and deepfakes are now operational tools.

• Threat actors are incorporating AI into underground markets, recruitment, prompt engineering, jailbreaking, malware development workflows, and criminal services.

• AI development infrastructure and supply chains are being targeted.

AI in the hands of attackers

In one of the report’s most significant findings, Sophos uncovered a campaign tracked as STAC6994, actively using AI to drive their operations; one of the first provable demonstrations of this happening.

The threat actor was running a software development operation inside a customer’s network, and using approximately 12 AI agents to write and test attacks against endpoint agents, including Sophos, CrowdStrike, and Microsoft Defender. They produced nearly 80 modules and more than 70 evasion techniques, and turned what would have taken a human weeks into a few days. This dramatically accelerated the timeline of attack techniques reaching operational readiness.

This intelligence collection effort meant that we could stay ahead of the threat, defeating attacks before they made it into the wild.

AI identities: a new attack surface

The report identifies enterprise AI adoption as the fastest-growing source of new exposure. As coding agents, assistants, and open-weight models take on privileged access to core systems, attackers are targeting the trust, credentials and access permissions surrounding these systems. As a result, AI identities, agents, OAuth connections, and API keys are increasingly becoming a high-value attack surface, and governance is not keeping pace.

Attackers are creating new pathways into enterprise networks by compromising OAuth tokens, AI service credentials, developer tools, and exposed AI infrastructure. This demonstrates that AI is now as much an identity, governance, and supply chain issue as it is a model security issue.

This is also reflected in the recent Sophos 2026 State of Ransomware report, which showed that, for the first time in more than three years, identity has become the primary IAV.

AI-Powered social engineering and deepfakes

AI-assisted social engineering and deepfakes are making scams more scalable, more convincing across languages, and significantly cheaper to produce.

Incidents highlighted in the report include an AI-themed investment scam which drew a UK-based victim into a fake AI-powered investment platform through months of AI-themed lessons and coordinated messaging. The victim ultimately lost hundreds of thousands of pounds.

AI development infrastructure is also being targeted directly with attacks involving compromised developer tools and credential-stealing malware. Supply chain risks around model weights, training data provenance, MCP servers and inference infrastructure are also becoming more prolific.

“This report makes clear that AI security is no longer just about model behaviour or speculative future risks. AI is actively being absorbed into criminal workflows and social engineering operations, as well as into enterprise software development and identity systems within legitimate organisations. That means the threat is in the here and now,” says Peterson. “As frontier models continue to advance, the next few months will be defined by how quickly organisations can govern AI use, secure the identities and connections around it, and keep pace with attackers who are capable of rapidly adopting new capabilities.”

The report is based on findings from Sophos X-Ops Managed Detection and Response (MDR) casework, SophosLabs analysis, Sophos Counter Threat Unit (CTU) intelligence, Sophos AI research, and endpoint and network observations across more than 625 000 customers worldwide.

For more information contact Sophos SA, +27 11 444 4000, www.sophos.com




Share this article:
Share via emailShare via LinkedInPrint this page



Further reading:

SAFPS urges taxpayers to remain alert to fraud
Security Services & Risk Management News & Events
The SAFPS warns taxpayers about evolving SARS scams this tax season, highlighting common fraud tactics, practical prevention tips, and trusted reporting channels to stay protected.

Read more...
Zero-touch automation certificate life cycle management loop
Products & Solutions Information Security Security Services & Risk Management
ManageEngine completes the certificate life cycle management loop with CA-agnostic, zero-touch automation. New post-deployment automation in Key Manager Plus removes the last manual step in certificate renewal as lifespans gradually shrink to 47 days

Read more...
Dallmeier extends software maintenance up to 10 years
Dallmeier Electronic Southern Africa Surveillance News & Events
Dallmeier is expanding its software maintenance offering and now provides an additional maintenance package for cameras and recorders, enabling customers to keep their video security systems up to date for up to 10 years.

Read more...
Sophos launches AI-native cybersecurity defence system
News & Events Information Security Security Services & Risk Management
Built for a threat landscape reshaped by AI, Sophos Fusion unites security operations, endpoint, network security, identity, email, and cloud into one defence system that prevents, detects, investigates, and responds at AI speed.

Read more...
Video surveillance market faces faster growth, and 2026 price shock
Surveillance News & Events
Novaira Insights has released its 2026 edition of The World Market for Video Surveillance Hardware and Software, highlighting a stronger global growth profile in 2025, tentative improvements in China’s market outlook, and unprecedented price increases in 2026.

Read more...
Ungoverned AI agents and deepfakes pose critical threats
Information Security Security Services & Risk Management
Global study reveals 64% of South African organisations already deploy autonomous AI agents with little to no governance, while 63% of employees admit they are unlikely to be able to spot attacks such as deepfakes

Read more...
How ‘TikTok Brain’ is breaking legacy security training
Training & Education Information Security
Between doomscrolling, rapid-fire Slack notifications, and algorithmic video feeds, the average employee is trapped in an aggressive, highly engineered dopamine loop that automatically shuts down in traditional training situations.

Read more...
Quantum is coming
Infrastructure Information Security
The global cybersecurity landscape is approaching a turning point as quantum computing accelerates faster than most organisations realise; the shift is not a distant, theoretical concern, but a present-day business risk that demands immediate action.

Read more...
Outpacing cyberthreats in the age of AI
SMART Security Solutions Technews Publishing News & Events Information Security
SMARTpod talks to Fred Streefland, Global Field CISO for EMEA at Check Point Software Technologies, about framing modern cyber defence around adaptability, rapid decision-making, and the OODA loop adapted for cybersecurity.

Read more...
Prompt injection is the new phishing
Information Security Security Services & Risk Management
AI security is heading in an uncomfortable direction following Microsoft’s research showing how prompt injection can be chained to remote code execution vulnerabilities in AI agent frameworks, including work involving Semantic Kernel

Read more...










While every effort has been made to ensure the accuracy of the information contained herein, the publisher and its agents cannot be held responsible for any errors contained, or any loss incurred as a result. Articles published do not necessarily reflect the views of the publishers. The editor reserves the right to alter or cut copy. Articles submitted are deemed to have been cleared for publication. Advertisements and company contact details are published as provided by the advertiser. Technews Publishing (Pty) Ltd cannot be held responsible for the accuracy or veracity of supplied material.




© Technews Publishing (Pty) Ltd. | All Rights Reserved.