Sophos Report Finds AI Is Accelerating Cyberattacks and Creating New Risks Around AI Identities
AI-powered attacks are compressing timelines from weeks to days as threat actors increasingly target AI agents, OAuth tokens, and non-human identities
Sophos has released its AI Security 2026 Report, warning that cybercriminals are increasingly operationalizing artificial intelligence to accelerate attacks, exploit AI identities, and scale social engineering campaigns. According to the report, the most immediate impact of AI on cybercrime is not the creation of entirely new attack methods but the dramatic reduction in the time required to execute existing attacks.
The findings reveal that attackers are using AI to compress attack development and deployment cycles from weeks to just days, giving security teams significantly less time to detect and respond to threats. Sophos researchers found that AI is becoming a force multiplier for cybercriminals, enabling faster testing, development, and refinement of attack techniques.
One of the report’s most significant discoveries involved a threat group tracked as STAC6994, which was found using approximately 12 AI agents inside a compromised environment to develop and test attacks against endpoint security platforms including Sophos, CrowdStrike, and Microsoft Defender. The operation reportedly generated nearly 80 attack modules and more than 70 evasion techniques, dramatically accelerating the pace of attack development.
“For the first time we have observed AI being actively used as an operational force multiplier. While the tools and techniques were familiar, the speed of development, testing, and iteration was materially different.”
John Peterson, Chief Technology Officer, Sophos
The report also highlights the emergence of AI identities as a rapidly expanding attack surface. As enterprises adopt AI assistants, coding agents, large language models, APIs, and autonomous systems, attackers are increasingly targeting OAuth tokens, AI service credentials, API keys, and privileged non-human identities. Sophos warns that governance and security controls are not evolving quickly enough to manage these new risks.
Additionally, AI-powered social engineering and deepfake technologies are becoming operational tools for cybercriminals, enabling more convincing and scalable scams across multiple languages at significantly lower costs.
Sophos also noted growing attacks against AI development infrastructure, including compromised developer tools, credential theft, model supply chains, and exposed AI environments.
Based on intelligence gathered from Sophos X-Ops, SophosLabs, threat research teams, and observations across more than 625,000 customers worldwide, the report concludes that organizations must strengthen AI governance, secure AI-related identities, and adapt security operations to counter increasingly AI-enabled threats.
As AI adoption accelerates across enterprises, Sophos warns that cyber resilience will increasingly depend on an organization’s ability to secure not only AI models, but also the identities, systems, and infrastructure that support them.


