Cybercrime has always evolved alongside technology, but the jump AI is enabling right now is different in scale. Attacks that once needed a skilled operator and hours of manual work can now be planned, written, and in some cases executed by AI systems in minutes. What used to be a theoretical risk is now a documented pattern, with security researchers and AI companies themselves reporting real incidents.
Why AI Changes the Equation
Traditional hacking had a relatively high skill barrier. Writing malware, mapping a target’s network, finding vulnerabilities, and crafting convincing scams often required significant technical knowledge and experience. AI is lowering that barrier. It can process huge amounts of information, analyze unfamiliar systems, generate code, and create convincing content in seconds. Tasks that once took a skilled attacker hours can now be completed much faster with AI assistance.
This does not mean that every cyberattack is fully automated. In most cases, AI acts as an assistant that helps attackers make their existing techniques faster, more scalable, and more effective. However, that is precisely what makes the threat serious: people with limited technical skills may now be able to carry out attacks that previously required considerably more expertise.
AI is therefore not necessarily replacing hackers, t is giving more people access to capabilities that were once limited to highly skilled attackers.
Real Instances Where AI Has Been Used in Attacks
These are not just hypothetical scenarios. Security researchers, AI companies, and threat intelligence teams have documented real cases where attackers used AI to support or automate parts of cyberattacks.
- An AI-assisted espionage campaign. In September 2025, Anthropic detected a Chinese state-sponsored group, which it identified as GTG-1002, using Claude Code in an espionage campaign targeting roughly 30 organizations. The targets included organizations across several sectors, and Anthropic said the attackers used AI for reconnaissance, vulnerability discovery, exploitation, lateral movement, credential harvesting, data analysis, and data exfiltration. Anthropic estimated that AI performed about 80–90% of the tactical work, while humans remained responsible for higher-level decisions and objectives. Anthropic described it as the first documented cyberattack that was largely executed without human intervention at scale.
- Malware using AI to search for valuable information. In 2025, Google Threat Intelligence identified a credential-stealing malware family called QUIETVAULT. The malware primarily targeted GitHub and NPM credentials. Researchers found that, after infecting a system, QUIETVAULT could use an AI command-line tool installed on the compromised computer to help search for additional secrets and potentially valuable files. This is different from saying that the malware contained its own built-in large language model.
- AI assisted exploit development. Researchers have demonstrated that AI can significantly speed up the process of analyzing newly released security patches and developing proof-of-concept exploits. In one 2025 example, researchers used AI models to analyze the differences between vulnerable and patched code and produced an exploit for a vulnerability in Erlang’s SSH library within hours. More recent research from Anthropic found that advanced AI systems could autonomously develop working exploits against a number of recently patched Firefox and Windows vulnerabilities in controlled testing environments. This does not mean every newly patched vulnerability can immediately be exploited by AI, but it shows that the time and expertise required for some forms of exploit development are decreasing.
- Deepfake impersonation of company executives. In January 2024, an employee at engineering company Arup’s Hong Kong office was deceived during a video conference involving deepfake versions of company executives and colleagues. The employee subsequently authorized 15 transfers totaling about HK$200 million, or roughly US$25.6 million. Arup later confirmed that it was the company affected. The incident was primarily a sophisticated fraud and social-engineering attack rather than a conventional network intrusion; Arup said its systems were not compromised.
- AI-generated phishing and social engineering. Microsoft has documented threat actors using AI to create phishing messages, malicious code, and other content. Microsoft says AI can help attackers produce more convincing messages, adapt them to a target’s language and communication style, generate or debug malware, and automate other parts of an attack. In one 2025 campaign, Microsoft detected phishing malware whose code appeared to have been generated or assisted by an AI model to make the malicious payload more difficult to detect.
- Celebrity and public-figure deepfakes used in scams. Criminals have increasingly used AI-generated images, video, and cloned voices to impersonate celebrities, business leaders, and public officials in fraudulent schemes, including investment scams. The broader problem is well documented: the FTC reported that consumers lost $3.5 billion to impersonation scams in 2025, although that figure covers impersonation fraud generally and should not be presented as entirely AI-generated. AI makes these scams easier to produce and potentially more convincing, but not every impersonation scam involves AI.
The important point is that AI is not replacing every hacker or automatically carrying out every cyberattack. In many documented cases, AI is being used as a force multiplier: helping attackers research targets, write convincing messages, analyze vulnerabilities, generate code, process stolen information, or automate repetitive tasks. As these systems become more capable, the amount of expertise and time required to carry out some attacks may continue to decrease.
What This Adds Up To
Taken together, these cases shows AI appearing at almost every stage of the attack lifecycle: scouting targets, writing malicious code, developing exploits, impersonating trusted individuals, and crafting convincing messages designed to trick people into clicking.
Industry research also suggests that AI is already playing a meaningful role in cyberattacks. IBM’s 2026 research indicates that roughly one in four malicious breaches involved some form of AI assistance.
Defenders Are Racing to Keep Up
The same underlying technology cuts both ways. AI can process huge volumes of security logs, detect unusual behavior, and help analysts investigate threats much faster than manual review. Anthropic has also said that the same AI capabilities that enabled the espionage campaign are helping push cybersecurity defense into a new phase, where AI tools can genuinely help identify and fix vulnerabilities before attackers can exploit them.
This has created something close to a race: attackers are using AI to move faster, while defenders are using the same technology to detect threats, respond to attacks, and strengthen security just as quickly.
What Organizations Should Do Now
- Tighten identity controls. Multi-factor authentication, passwordless login, and least-privilege access can limit what a compromised account or stolen identity can actually do.
- Verify before acting on urgent requests. Any payment, permission change, or data request linked to a call or message from a “senior leader” should be verified through a second channel. This is especially important now that voices and faces can be convincingly faked.
- Train employees to recognize AI-era red flags. Polished writing and a familiar voice are no longer reliable proof of identity. Security awareness training needs to reflect this new reality.
- Secure AI systems themselves. Every AI model, agent, and API an organization deploys becomes part of its attack surface and should be protected like any other critical system.
The threat is not coming, it is already here, and there are documented incidents to prove it. Organizations that strengthen their defenses now, rather than waiting until after an attack, will be better prepared for what comes next.