Sophos Releases AI Security 2026 Report on Faster AI-Driven Attacks
Sophos released its AI Security 2026 report, which describes how attackers used artificial intelligence to reduce the time required to move from development to operational readiness. The report places emphasis on speed and on identity-related entry points in observed attacks.
Sophos said the most immediate effect from AI in cybercrime involved faster cycles for building, testing, and iterating attack workflows. The report also described a shift toward identity as a primary initial access vector, including identity elements such as AI identities, OAuth connections, and API keys, alongside the continued use of established stages like lateral movement and exfiltration through observable channels.
The report reported that attackers used AI as an operational force multiplier while keeping to familiar tools and techniques. In one described campaign tracked as STAC6994, Sophos said a threat actor ran a software development operation inside a customer’s network and used AI agents to write and test attacks against endpoint agents, including Sophos, CrowdStrike, and Microsoft Defender. Sophos said the actor produced nearly 80 modules and more than 70 evasion techniques, turning work that would have taken weeks into a few days.
Across other findings, Sophos said it observed AI-assisted social engineering and deepfakes used operationally, including an AI-themed investment scam that used months of AI-themed lessons and coordinated messaging before a UK-based victim lost hundreds of thousands of pounds. Sophos also said attacks targeted compromised developer tools and credential-stealing malware, while supply chain risks involved model weights, training data provenance, MCP servers, and inference infrastructure. Sophos based the report on findings from its X-Ops Managed Detection and Response casework, SophosLabs analysis, Sophos Counter Threat Unit intelligence, Sophos AI research, and endpoint and network observations across more than 625,000 customers worldwide. “Attackers still need initial access, still move laterally, and still exfiltrate through observable channels. What has changed is the clock,” said John Peterson, chief technology officer, Sophos. “For the first time we have observed AI being actively used as an operational force multiplier. While the tools and techniques were familiar, the speed of development, testing, and iteration was materially different. That is the AI threat that security teams need to prepare against. It means faster cycles and shorter windows to respond, with greater pressure on defenders to detect and contain activity before impact.”
Provided by Globe Newswire on behalf of Sophos. Click to read original content.