AI cyber attacks are attacks that use artificial intelligence to automate, accelerate, or adapt an attacker’s capabilities, not just AI-assisted tools bolted onto an old playbook, but attack techniques AI makes possible for the first time. That includes AI-generated phishing at scale, malware that rewrites itself to dodge detection, automated vulnerability discovery, deepfake-enabled fraud, and early agentic AI campaigns that run with limited human input.
Key takeaways
- An AI cyber attack means AI is doing real attack work—writing malware, discovering vulnerabilities, running a campaign—not just cleaning up an attacker’s grammar.
- AI-generated phishing surged from under 5% to 56% of detected attacks in a single month at the end of 2025, according to Hoxhunt’s 2026 phishing trends data.
- In September 2025, Anthropic disrupted a Chinese state-sponsored group that used its Claude Code tool to run 80–90% of a cyber espionage campaign autonomously.
- Deepfakes now account for roughly 11% of global fraud activity, and people can only spot AI-generated audio and video correctly about half the time.
- AI cyber attacks shift the old attacker-defender math: attackers only need to succeed once, and AI now lets them try more times, faster, more convincingly, with less skill required.
AI shows up in most security conversations on the defense side, and how it helps a security operations team catch more threats, faster. That’s a real and growing part of AI and security. Attackers are using the same technology, and AI cyber attacks are changing what an intrusion looks like in 2026: faster to build, more convincing, and harder to fingerprint with the signature-based tools most security teams still lean on.
What makes a cyber attack AI-powered instead of just AI-assisted?
An attacker using ChatGPT to fix typos in a phishing email is AI-assisted. That’s a productivity boost. A cyberattack becomes AI-powered when AI does real attack work: writing functional malware, adapting code on the fly to dodge a specific defense, discovering a vulnerability, or running steps of a campaign with little human direction.
Our own threat research shows how far that gap can stretch. A North Korean state-sponsored group Expel tracks as HexagonalRodent used commercial AI tools, including ChatGPT and Cursor, to write malware and build phishing sites targeting Web3 developers, reportedly exfiltrating around $12 million in cryptocurrency across thousands of infected systems in three months. Researchers noted the group’s own prompts were full of spelling and grammar mistakes. The humans behind the campaign couldn’t write working code without AI. AI made the attack possible.
Is “malicious AI” the same thing as an AI cyber attack?
Close, but the terms do different work. Malicious AI describes the tooling: an AI model or agent being used to cause harm, whether that’s a jailbroken commercial chatbot, a purpose-built criminal model sold on the underground market, or a legitimate coding assistant pushed past its guardrails. An AI cyberattack is what happens when someone points malicious AI at a target. Most cases documented so far involve mainstream commercial models pressed into service.
What are the main types of AI attacks in 2026?
Six patterns show up most often in current threat research:
1. AI-generated phishing and social engineering at scale
AI lets one attacker personalize thousands of phishing attempts instead of sending one generic template to everyone. Hoxhunt’s 2026 phishing trends data found AI-generated phishing jumped from under 5% of detected attacks to 56% in a single month at the end of 2025, before settling near 40% in January 2026.
IBM X-Force tested this directly: attackers needed just five prompts and five minutes to generate a phishing email nearly as effective as one that took a skilled team 16 hours to write by hand. It’s worth noting that in the same test, the human-written email still edged out the AI version on click-through rate. Speed and scale are AI’s real advantage here, not superhuman persuasion, at least for now.
2. Polymorphic and adaptive malware
Polymorphic malware rewrites parts of its own code to look different to signature-based detection tools every time it runs. AI accelerates this by generating variations faster than a human malware author could. That said, Expel’s own 2026 Annual Threat Report found that most endpoint attacks last year were “less about innovation and more about refinement”—well-tested delivery methods like ClickFix and backdoored productivity apps, not exotic AI-mutated code. The bigger near-term risk is AI making existing techniques cheaper to run at scale, not necessarily inventing malware nobody has seen before.
3. Automated vulnerability discovery and exploit generation
AI can scan code and infrastructure for weaknesses and draft exploit code far faster than a person doing the same work manually. In the Anthropic espionage case described below, the AI agent discovered and tested vulnerabilities at a rate—thousands of requests per second—no human operator could match.
4. Deepfake-enabled fraud
Deepfake audio and video are now good enough to impersonate an executive on a phone call or a video request for a wire transfer. Sumsub’s 2025–2026 Identity Fraud Report found deepfakes now account for roughly 11% of global fraud activity, up sharply from just a few years ago. People aren’t well-equipped to catch this by eye or ear—studies on human detection of AI-generated audio and video put accuracy at only slightly better than a coin flip.
5. Agentic AI attack campaigns
This is the newest and most consequential type of AI attack: AI agents that plan, execute, and adapt across an entire attack with minimal human involvement. It also changes who, or what, counts as the threat agent in an intrusion. A threat agent is the entity that actually carries out an attack, historically a person, a crew, or a state-sponsored team. Agentic AI adds software to that list: a threat agent that works through a target list at machine speed and needs a human only at decision points.
In September 2025, Anthropic disrupted a Chinese state-sponsored group that manipulated its Claude Code tool into running roughly 80–90% of a cyber espionage campaign autonomously, targeting around 30 organizations across tech, finance, and government. The attackers broke the operation into small tasks and misrepresented their intent to get around the model’s safeguards. Anthropic has called it the first documented large-scale cyberattack executed with minimal human involvement, and it’s a preview of what end-to-end autonomous attack campaigns can look like as the technology matures.
6. AI-powered credential stuffing and account takeover
Identity-based attacks are already the most common threat MDR providers see. Expel’s 2026 Annual Threat Report found that nearly half—47.7%—of identity-related incidents last year involved an attacker successfully gaining account access with stolen credentials. AI speeds up the front end of this problem: testing large volumes of leaked credentials faster, and generating the follow-on phishing or social engineering needed to get past multifactor authentication once a password alone isn’t enough.
For more information on AI threat frameworks, explore MITRE ATLAS.
Why do AI cyber attacks change the balance between attackers and defenders?
Security has always had an uneven fight built into it: an attacker only needs one attempt to work, while a defender has to stop every attempt, every time. AI cyber attacks tilt that further in the attacker’s favor in four ways. They automate attacks at scale, so one person can run thousands of personalized phishing campaigns instead of one. They compress timelines, shrinking the window between a vulnerability going public and someone exploiting it. They adapt in real time. And they lower the skill floor, putting capabilities that once needed a skilled operator within reach of attackers who couldn’t build them on their own.
How are defenders countering AI-powered threats?
The short version: with AI of their own, pointed at the parts of the job humans can’t do at volume. AI-powered defenses analyze far more data than a human team could review manually, use behavioral analysis to flag anomalies regardless of which specific technique an attacker used, and draw on threat intelligence gathered across many customer environments to recognize a pattern the moment it shows up anywhere in the network. An analyst still makes the call on what’s real and what gets done about it. AI does the triage math and the pattern matching. A person owns the decision.
Expel’s take
Most AI cyber attacks succeeding right now are making existing playbooks—phishing, credential theft, malware delivery—cheaper, faster, and available to attackers who couldn’t have pulled them off unassisted. That’s a real problem worth taking seriously. It’s also a more useful problem to plan for than a hypothetical AI supervillain, because it tells you where to actually put your attention: email security, identity, and the speed of your own detection and response.
Frequently asked questions
What are the most common types of AI attacks?
The main types of AI attacks are highly personalized AI-generated phishing campaigns, polymorphic malware that rewrites itself to evade detection, automated vulnerability scanning and exploit development, deepfake-based fraud targeting executives and financial systems, AI-assisted credential stuffing and account takeover, and early-stage agentic AI campaigns capable of multi-step autonomous intrusion.
How does AI make cyber attacks more dangerous?
AI cyber attacks are more dangerous because of automation at scale (one attacker can run thousands of personalized phishing campaigns), compressed attack timelines (vulnerabilities found and exploited faster), adaptation (malware that changes to evade specific defenses), and lower barriers to entry (capable attacks within reach of less-skilled attackers).
What is malicious AI?
Malicious AI is any AI model, tool, or agent used to cause harm—a jailbroken commercial chatbot, a criminal model sold on the underground market, or a legitimate coding assistant pushed past its guardrails. Malicious AI is the tooling. An AI cyberattack is what happens when that tooling gets pointed at a target.
Can an AI be a threat agent?
Yes. A threat agent is the entity that carries out an attack, and agentic AI now qualifies. In the September 2025 espionage campaign Anthropic disrupted, an AI agent handled roughly 80–90% of the operation, with humans stepping in only at decision points. That’s a threat agent that works at machine speed and doesn’t get tired.
What is AI-generated phishing?
AI-generated phishing uses large language models to create highly personalized, contextually accurate phishing emails that are harder to detect than traditional mass phishing. AI can research targets, mimic writing styles, generate convincing pretexts, and scale attacks that previously required a skilled social engineer for each target.
What should security teams prioritize to defend against AI cyber attacks?
Priorities include strengthening email security with AI-powered phishing detection, implementing behavioral analytics to catch threats that evade signatures, maintaining 24×7 monitoring coverage to match the speed of automated attacks, educating employees on AI-enhanced social engineering, and working with an MDR provider that uses AI defensively at scale.
How can you tell if an attack is using AI?
A few signals point to AI involvement: phishing messages that are unusually polished and personalized with none of the typos or awkward phrasing you’d expect, synthetic media like deepfake audio or video used for social engineering, and automation patterns that move faster or more consistently than a human attacker could manage alone. No single sign proves it on its own, but seeing several together is a strong indicator you’re dealing with an AI-powered attack, not a manual one.

