Lessons Learned from a Year of Mapping AI-Driven Cyber Threats
Key point
AI is lowering the technical barrier for cyberattacks, increasing the autonomy of attacks, and changing the nature of threats.
Details
Analysis of 832 malicious accounts blocked between March 2025 and March 2026 revealed that attackers are actively leveraging AI in the complex stages that occur later in cyber operations.
Key findings from the analysis are as follows:
- Sophistication of attacks: 67.3% of those investigated used AI to write malware, and 6.5% used AI for Lateral Movement to navigate within networks.
- Surge in threat levels: During the first six months of the analysis period, attackers classified as medium risk or higher accounted for 33%, but this rose to 56% in the latter six months—an increase of about 1.7x.
- Shift in the attack lifecycle: Rather than phishing for initial intrusion (down 8.6%), AI use is increasing in post-compromise stages, such as Account Discovery (up 8.9%), which identifies internal accounts after infiltration.
As AI performs highly technical tasks, the correlation between an attacker's skill level and the number of techniques they use is weakening. Now, whether an attacker builds an autonomous architecture that uses AI to chain together each stage of an attack without human intervention has become a key indicator for distinguishing high-risk attackers.
This summary was generated automatically by AI. Check the original for the author's claims and context. Copyright belongs to the original author.
Our guide explains how the AI works. Report summary errors, attribution issues, or removal requests via Contact.