India, July 23, 2026 (BFN Bureau): Sophos today released its AI Security 2026 Report, which finds that attackers are operationalizing artificial intelligence (AI) to compress cyberattack timelines from weeks to days. The report highlights a rise in attacks targeting AI identities, OAuth tokens, APIs, agents, and developer tools as enterprises accelerate AI adoption.
According to the report, AI’s most immediate impact on cybercrime is speed, with identity becoming the primary initial access vector (IAV). “Attackers still need initial access, still move laterally, and still exfiltrate through observable channels. What has changed is the clock,” said John Peterson, Chief Technology Officer at Sophos. “For the first time we have observed AI being actively used as an operational force multiplier. While the tools and techniques were familiar, the speed of development, testing, and iteration was materially different. That is the AI threat that security teams need to prepare against.”
Key findings from the report
The report outlines several key findings:
- AI is compressing attack timelines and accelerating operational readiness.
- Enterprise AI identities, OAuth tokens, agents, APIs, and development tools are becoming high-value targets.
- AI-assisted social engineering and deepfakes are now operational tools.
- Threat actors are incorporating AI into underground markets, recruitment, and malware development workflows.
- AI development infrastructure and supply chains are being targeted.
AI in the hands of attackers
One significant finding in the report is the identification of a campaign tracked as STAC6994, which actively used AI to drive operations. The threat actor was running a software development operation inside a customer’s network, utilizing approximately 12 AI agents to write and test attacks against endpoint agents, including Sophos, CrowdStrike, and Microsoft Defender. This operation produced nearly 80 modules and over 70 evasion techniques, significantly accelerating the timeline of attack techniques reaching operational readiness.
“This report makes clear that AI security is no longer just about model behavior or speculative future risks. AI is actively being absorbed into criminal workflows and social engineering operations, as well as into enterprise software development and identity systems within legitimate organizations,” Peterson added. “As frontier models continue to advance, the next few months will be defined by how quickly organizations can govern AI use, secure the identities and connections around it, and keep pace with attackers who are capable of rapidly adopting new capabilities.”
Key Takeaways
- Sophos AI Security 2026 Report released.
- Attackers are using AI to compress cyberattack timelines.
- AI identities and OAuth tokens are becoming high-value targets.
- AI-assisted social engineering and deepfakes are operational tools.
