AI's Role in Evolving Cyberattack Strategies
Security leaders are engaged in ongoing discussions about whether artificial intelligence (AI) will create an entirely new class of cyberattacks. However, a more immediate transformation is already taking place: AI has significantly reduced the cost of retrying failed attacks. This shift is evident in the tactics employed by attackers, who can now quickly adjust their strategies after an initial failure.
In a typical scenario, an attacker may gain access to a low-privilege cloud account and attempt to escalate their privileges. If this initial attempt fails, the process that once required extensive documentation, permission checks, and debugging can now be streamlined with AI assistance. The AI can analyze the error, suggest fixes, and initiate new attempts within minutes, effectively shortening the time and skill required for successful intrusions.
The evolution of AI's role in cybercrime has been documented over the past few years. In early 2025, Google's Threat Intelligence Group reported that state-sponsored actors were utilizing generative AI for various tasks, including translation and scripting. By late 2025, these same actors were leveraging AI to enhance their malware capabilities, with reports of AI-assisted operations that spanned from reconnaissance to ransom demands. In May 2026, the group identified a two-factor authentication bypass in an open-source tool, attributing the discovery and exploit development to AI assistance.
This distinction between AI-assisted operations and confirmed deployments in the wild is crucial. While the evidence suggests a trend toward AI integration in attacker workflows, the actual prevalence and attribution of these activities remain challenging to ascertain. The direction of this trend indicates that AI is becoming an integral part of the cyberattack process, rather than merely a tool used alongside traditional methods.
Provider guardrails play a significant role in mitigating misuse of AI technologies. Safety measures and abuse prevention mechanisms increase the cost of employing AI for malicious purposes. However, these guardrails are not foolproof. Attackers can still manipulate AI systems by reframing requests or splitting malicious tasks into seemingly innocuous ones, thereby circumventing security policies.
The attack lifecycle is often depicted as a linear process: reconnaissance, access, escalation, and impact. In practice, however, attackers operate in a loop, continuously adjusting their strategies based on real-time feedback from their environment. AI accelerates this loop, allowing both novice and experienced attackers to conduct more experiments in a shorter timeframe.
Adapting Defense Strategies to Attack Dynamics
Defensive strategies should ideally mirror this iterative approach. When an alert is triggered, security teams gather context, form hypotheses, validate scope, and take action. Unfortunately, this process is often interrupted by delays and handoffs, leading to inefficiencies. Alerts may sit unassigned, and critical information can be lost in the transition between teams.
The mean time to acknowledge and remediate alerts often obscures the underlying delays. While an alert may be acknowledged quickly, the subsequent investigation can take hours as analysts sift through various consoles to reconstruct the incident. This latency in decision-making can hinder effective responses to threats.
The functions of a security operations center (SOC) typically include threat intelligence, threat hunting, detection engineering, investigation, and remediation. While these functions are essential, the real challenge lies in the transfer of information between them. Each handoff can result in a loss of critical context, leading to duplicated efforts and missed opportunities for timely action.
For example, consider a scenario where a finance employee logs in from an unfamiliar hosting provider. Despite passing multi-factor authentication, suspicious activity follows, such as the creation of a mailbox rule that forwards emails to an external address. While no single event conclusively proves compromise, the sequence of actions warrants investigation. However, the context that connects these events may not be fully communicated across teams, leading to incomplete assessments.
Final Assessment
To address these challenges, organizations need to adopt a more stateful approach to security operations. This involves retaining evidence and case histories while ensuring that the reasoning behind decisions is preserved. By creating a shared operational memory, security teams can enhance their ability to respond to incidents effectively.
In conclusion, the integration of AI into cyberattack strategies is reshaping the landscape of cybersecurity. As attackers leverage AI to streamline their operations, security teams must adapt by improving their workflows and ensuring that critical context is retained throughout the incident response process. The future of cybersecurity will depend on the ability to maintain a comprehensive understanding of threats and to respond with agility and precision.