The Attackers Got AI First: What That Means for Your Business

Published on CyberCon Services | Cybersecurity Insights


There’s a rule in security that defenders have lived by for decades: if something looks suspicious, slow down, investigate, escalate. Take a breath. That rule just broke.

At this year’s RSA Conference 2026, CrowdStrike president Michael Sentonas revealed something that should stop every IT and security professional in their tracks: the fastest recorded adversary breakout time — the window between an attacker gaining initial access and moving laterally through a network — has dropped to 27 seconds. The average is 29 minutes. A year ago it was 48 minutes.

“I’ve never seen anything like it,” Sentonas said. “I’ve never seen anything move so fast.”

The reason attacks are moving at these speeds isn’t better human hackers. It’s artificial intelligence. And the implications for every business — from enterprise to small-and-mid-sized — are profound, immediate, and largely underestimated.


AI Didn’t Create New Attacks. It Supercharged the Old Ones.

Let’s be precise about what’s happening here, because the reality is both more mundane and more alarming than the headlines suggest.

According to CrowdStrike’s 2026 Global Threat Report, there was an 89% year-over-year increase in attacks where adversaries deployed AI tools. But researchers noted that in most cases, AI isn’t inventing new attack vectors — it’s radically optimizing existing ones. Phishing is still phishing. Social engineering is still social engineering. Malware is still malware. What’s changed is the speed, scale, personalization, and success rate of all of it.

Think of it this way: attackers used to need skilled humans to craft each attack. Now they have AI doing the work — faster, cheaper, and at a scale no human team could match.

IBM’s 2026 Cost of a Data Breach study found that one in four malicious breaches were AI-enabled. The FBI’s 2025 Internet Crime Report recorded over 22,000 AI-related fraud complaints with nearly $893 million in reported losses — and Congressional researchers estimate fewer than 5% of voice clone victims ever report their losses. The actual damage is orders of magnitude higher.


The Five Ways AI Is Changing How Attackers Operate

1. Phishing That’s Actually Convincing

For years, cybersecurity training taught employees to spot phishing by looking for grammatical errors, awkward phrasing, and generic greetings. That playbook is dead.

Large language models can now generate phishing emails in any language, perfectly mimicking writing styles, referencing real names and project details scraped from LinkedIn and company websites, and passing through spam filters that rely on linguistic patterns. Campaigns that used to take a skilled human hours to craft can now be generated in minutes — and launched at thousands of targets simultaneously.

The result: AI-generated spear-phishing has reached a tipping point where traditional email security filters and annual security awareness training are structurally unable to keep pace with the volume and quality of attacks being produced.

2. Voice Cloning and Deepfake Fraud

This is where AI attacks become genuinely difficult to defend against with human judgment alone.

Voice cloning technology has crossed what researchers are calling the “indistinguishable threshold” — human listeners can no longer reliably tell a cloned voice from the real one. Attacks are already exploiting this at scale. A typical scenario: a CFO’s cloned voice calls an accounts payable clerk, says “I’m in a closing, wire $480,000 to this account in the next 20 minutes, the lawyer will email instructions, don’t loop in legal yet” — and a follow-up email arrives from a convincing lookalike domain.

According to the FTC, the average loss per voice clone incident in 2025 was $11,000. At the enterprise level, losses from a single incident regularly reach six or seven figures.

Deepfake video has followed the same trajectory. Deepfake video scam instances surged 700% in 2025. Real-time synthetic video calls — where every participant on a conference call can be a fabricated avatar — are no longer theoretical.

The cost of executing these attacks has also collapsed. Voice cloning that once required research-lab resources is now a weekend project using open-source models.

3. AI-Written and AI-Adapted Malware

Traditional antivirus and endpoint detection tools work by recognizing signatures — patterns in known malicious code. AI is systematically dismantling this approach.

AI-enabled malware can now generate its own code variants, alter itself mid-execution to avoid detection, and create malicious functions on demand when deployed. Google’s Threat Intelligence Team documented a code family that used AI capabilities mid-execution to dynamically alter the malware’s behavior. Nation-state actors have already deployed malware that uses large language models during execution — not just during development.

Critically, CrowdStrike’s 2026 data found that 82% of compromises were executed without malware binaries at all — attackers are increasingly living off the land, using legitimate system tools so there’s nothing for signature-based scanners to find.

4. Automated Reconnaissance and Zero-Day Exploitation

Before launching an attack, adversaries need to map their target — finding vulnerabilities, identifying users, understanding the network layout. This reconnaissance phase used to take days or weeks of skilled human work. AI compresses it to hours.

AI systems can now autonomously probe networks for security weaknesses, map attack surfaces, and identify exploitable paths — all without human direction. Zero-day exploitation increased 42% before disclosure in 2025, meaning attackers are finding and weaponizing vulnerabilities faster than vendors can patch them.

5. The Democratization of Advanced Attacks

Perhaps the most dangerous long-term trend: AI is eliminating the skill barrier for attackers.

Sophisticated attacks used to require nation-state resources or years of expertise. Today, criminal platforms rent AI-driven attack kits to affiliates. “With AI, you don’t need deep skills, you need ideas,” one threat intelligence analyst put it. “As barriers to entry drop even further, more low-skilled actors will become more dangerous, faster.”

Deepfake-as-a-service platforms proliferated through 2025, making AI-powered fraud accessible to criminals with no technical background. The number of threat actors capable of launching previously “advanced” attacks has exploded. The volume of attacks on businesses of all sizes has followed.


The Speed Problem Is the Core Problem

All of these individual capabilities are serious. But the deeper issue is what they do to the timeline of an attack.

When an adversary can move from initial access to full lateral network compromise in under 30 minutes — and the fastest recorded case was 27 seconds — traditional security operations simply cannot respond in time. The average Security Operations Center (SOC) takes longer than 29 minutes just to triage a single alert.

CrowdStrike CEO George Kurtz put it plainly at Fal.Con 2026: “Breakout time is over. Attacks now happen at inference speed. And when an attacker has inference speed, there is no breakout time. There’s actually no time at all to defend.”

This isn’t a problem that more analysts can solve. It requires AI-powered defense to match AI-powered offense.


What Defenders Are Doing About It

The cybersecurity industry is responding — and the responses are substantive.

AI-native threat detection is becoming the baseline requirement. Security tools are shifting from signature-based pattern matching to behavioral AI that can identify anomalies in real time across massive volumes of network traffic, endpoint telemetry, and log data — finding attacks that have no signatures because they’ve never been seen before.

Agentic Security Operations Centers pair human analysts with AI agents that can investigate, triage, and begin response actions autonomously. CrowdStrike’s “human on the loop” model keeps a human analyst working the same detection as an AI agent in parallel — maintaining human judgment for high-stakes decisions while operating at machine speed.

Zero Trust architecture assumes breach and requires continuous verification — limiting what an attacker can reach even after initial access. Paired with identity hardening (particularly FIDO2 hardware keys), it directly attacks the lateral movement that AI accelerates.

Out-of-band verification protocols for high-risk requests are the most practical near-term defense against voice cloning and deepfake fraud. A written, enforced callback rule — requiring independent verification through a pre-established channel for any request involving money, credentials, or system access — defeats the majority of AI-powered social engineering attacks regardless of how convincing they sound.

Security awareness training modernization is overdue. Annual compliance modules and email-only phishing simulations were designed for a threat environment that no longer exists. Effective training must cover voice, video, and SMS attack surfaces and refresh continuously to match the pace of AI-generated attack evolution.


What This Means for Small and Mid-Sized Businesses

Here’s the uncomfortable reality for businesses without enterprise security teams: AI didn’t just upgrade the attacks used against Fortune 500 companies. It made enterprise-grade attacks affordable enough to use against everyone.

The same AI tools that allow nation-state actors to execute devastating intrusions are available to criminal affiliates targeting a 50-person accounting firm or regional healthcare provider. The targeting criteria is no longer “is this a big enough target” — it’s “is this an exploitable target.”

The most important steps any organization can take right now:

  • Adopt multi-factor authentication everywhere — particularly hardware-based MFA (FIDO2 keys) for privileged accounts. This is the single highest-return investment in security.
  • Establish a callback protocol for all financial requests — voice, email, or text. Any request involving wire transfers, credential changes, or vendor payment updates must be verified through a separate, pre-established channel before action is taken. No exceptions.
  • Update endpoint protection to AI-behavioral tools — signature-based antivirus is insufficient against modern fileless attacks and AI-mutating malware.
  • Review your identity posture — 82% of breaches in 2026 involved no malware; they relied on stolen or manipulated credentials. Privileged access management and regular access reviews are essential.
  • Have an incident response plan — at AI attack speeds, a documented playbook that teams can execute without deliberating is the difference between a contained incident and a catastrophic breach.

The Honest Assessment

AI has handed attackers a set of capabilities that compress time, eliminate skill barriers, and systematically defeat the defenses most organizations still rely on. The 89% year-over-year increase in AI-enabled attacks isn’t an anomaly — it’s the beginning of a trend line.

The good news is that AI-powered defense tools are maturing rapidly, and the cybersecurity industry is adapting. The less comfortable news is that most organizations are still running playbooks, training programs, and toolsets designed for a threat landscape that existed three years ago.

The businesses that come through this transition intact will be the ones that recognized the shift early — and moved their security posture to match the speed of the threat, not the speed of the old calendar.


At CyberConservices, we help businesses assess their security posture against modern AI-powered threats and build practical, right-sized defenses. Contact us to schedule a security review.


Tags: AI Cyberattacks, Cybersecurity 2026, Deepfake Fraud, Voice Cloning, Phishing, AI Malware, Threat Intelligence, CrowdStrike, Zero Trust, MSP Security

Leave a Reply

Verified by ExactMetrics