AI: The New Head Operator in Today’s Cyber Attacks

Study finds AI is no longer just a development tool for attackers, it's running whole operations itself.

Key Takeaways

  • AI is now operating entire cyber attacks, according to a new study from Check Point
  • AI-enabled threat tools have evolved, with phishing and one-time password attacks becoming more mature
  • Businesses should ensure their cybersecurity experts are embedded within company operations, and that continuous conversations are being had about the ever evolving threat landscape

AI is no longer just making cyber attacks cheaper and faster, but it’s now in charge of running whole operations, a new study has found.

Cybersecurity leaders have been warning about the dangers of AI for some time, and developments such as a maturing AI-enabled criminal tooling market and more sophisticated imitations of voice, face, live video, and documents pose serious concerns.

Experts are urging businesses to integrate cybersecurity practices within organizations, including cybersecurity leads and teams. Likewise, businesses should align their security protocols with the AI applications they are using to have a foundation to build from as threats continue to change.

Study Finds AI is Now Operating Attacks on Behalf of Users

In Check Point’s 2026 AI Security Report, AI has taken a leading role in cyber attacks. The technology is no longer just enhancing cyber attacks by making them cheaper, faster, and more accessible. Instead, it’s now doing the hands-on operational work itself.

In one example outlined, a human attacker carried out a breach by running two commercial tools, Claude Code and GPT-4.1, together. This led to the breach of 9 Mexican government agencies.

 

About Tech.co Video Thumbnail Showing Lead Writer Conor Cawley Smiling Next to Tech.co LogoThis just in! View
the top business tech deals for 2026 👨‍💻
See the list button

The report tracks how AI has reshaped the threat landscape over the past year, and is grounded in real-world incident and Check Point Research threat intelligence.

How AI Threats Have Evolved in the Past Year

Check Point found AI is now able to turn a new system vulnerability into a working exploit within hours, giving companies little time to react.

“[We] hear from the security operations center and incident respond teams [that] if a human was doing these tasks, we’d at least have some time to detect it, respond, and try to prevent it, but the agents are so fast, by the time [we] know about it the damage is already done.” Adam Ely, general manager of AI Security at Check Point Software, during a media roundtable at Check Point Engage Singapore 2026

Similarly, existing AI threat tools have matured in the past year. Phishing-as-service kits now have language models with jailbreak features built-in, and conversational AI voice-agents can run vishing and one-time passcode attacks.

Furthermore, the report notes that Virtual Identity measures can no longer be fully trusted. Thanks to AI, attackers can imitate voice, face, documents, and live video with ease, which makes communication scams more widely available across multiple platforms.

Protecting Your Business in 2026 and Beyond

Businesses are increasingly at risk as AI becomes more common in cyber attacks. The study found 1 in 17 AI prompts carry a serious data exposure risk, a particularly concerning statistic for organizations typically running 10 AI apps a month on average. Many of these AI apps, the study notes, also remain ungoverned.

Overall, high-risk prompts doubled to 4% in a year, one example of how AI is changing the cybersecurity landscape in a rapid fashion. “Enterprise data leakage through GenAI is a persistent and growing risk,” the report warns.

Not only are organizations going to have to ensure their core security principles are intact and solid, but they’ll have to continue to rework and update these principles, in order to keep up with new risks.

“Ensuring that companies are putting their protections for AI really in line with the AI applications or at the runtime level of the application is really important. As models change or functions change, that implementation can then be built on versus having to do a completely new security implementation.” Adam Ely

Adam Ely, general manager of AI Security at Check Point Software, believes organizations should also ensure cybersecurity teams and leaders are fully integrated into business operations. With these teams, businesses should have regular conversations about potential threats and how these are changing.

Did you find this article helpful? Click on one of the following buttons
We're so happy you liked! Get more delivered to your inbox just like it.

We're sorry this article didn't help you today – we welcome feedback, so if there's any way you feel we could improve our content, please email us at contact@tech.co

Written by:
Nicole is a Writer at Tech.co. On top of a degree in English Literature and Creative Writing, they have written for many digital publications, such as Outlander Magazine. They previously worked at Expert Reviews, where they covered the latest tech products and news. Outside of Tech.co, they enjoy keeping up with sports and playing video games.
Explore More See all news
Back to top