Artificial intelligence (AI) is helping cybercriminals carry out attacks much faster, leaving organizations with less time to detect and stop threats, according to the Sophos AI Security 2026 Report.
The report found that AI is not introducing entirely new forms of cybercrime. Instead, it is speeding up existing attack methods by automating tasks that once took weeks to complete. Sophos also warned that identity-based attacks, targeting user accounts, AI identities, access tokens, OAuth connections, and API keys, are becoming one of the biggest cybersecurity risks for businesses.
“Attackers still need initial access, still move laterally, and still exfiltrate through observable channels. What has changed is the clock,” said John Peterson, chief technology officer, Sophos.
“For the first time we have observed AI being actively used as an operational force multiplier. While the tools and techniques were familiar, the speed of development, testing, and iteration was materially different. That is the AI threat that security teams need to prepare against. It means faster cycles and shorter windows to respond, with greater pressure on defenders to detect and contain activity before impact.”
One of the report’s key findings involved a campaign tracked as STAC6994, which Sophos described as one of the first proven cases of attackers using AI to accelerate cybercrime. According to the company, the threat actor operated within a customer’s network and deployed about 12 AI agents to write and test code designed to evade endpoint security products from Sophos, CrowdStrike, and Microsoft Defender.
The AI agents generated nearly 80 software modules and more than 70 evasion techniques, reducing work that would normally take weeks to just a few days. Sophos said it detected the activity before the techniques could be used in real-world attacks.
The report also found that enterprise AI adoption is expanding the cyberattack surface. AI assistants, coding agents, and machine identities often have privileged access to business systems, making them attractive targets for attackers. Rather than attacking AI models directly, cybercriminals are increasingly stealing credentials, compromising developer tools, and exploiting trusted connections that link AI services to corporate networks.
Sophos said the findings mirror those in its 2026 State of Ransomware report, which showed that identity has become the primary initial access vector for ransomware attacks for the first time in more than three years.
The report also warned that AI-powered social engineering and deepfakes are making scams more convincing, scalable, and cheaper to produce. Sophos cited a case in which a UK victim lost hundreds of thousands of pounds after being lured into a fake AI-powered investment platform.
“This report makes clear that AI security is no longer just about model behavior or speculative future risks. AI is actively being absorbed into criminal workflows and social engineering operations, as well as into enterprise software development and identity systems within legitimate organizations. That means the threat is in the here and now,” said Peterson.
The report is based on investigations by Sophos X-Ops Managed Detection and Response (MDR), SophosLabs, the Sophos Counter Threat Unit (CTU), Sophos AI research, and endpoint and network observations from more than 625,000 customers worldwide.