FR
live

AI-assisted cyberattacks now breach systems in 72 minutes

Attackers are deploying AI agents to automate reconnaissance, phishing, and exfiltration, compressing the breach-to-theft window to 72 minutes in the fastest observed cases. SOC teams that still rely solely on human-first triage are structurally unable to keep up.

Les cyberattaques assistées par IA percent les systèmes en 72 minutes — ETTAYEB illustration

July 2023. WormGPT surfaces on underground forums: an unconstrained LLM built to generate phishing emails and malicious code with zero ethical guardrails.

January 2025. Sophos X-Ops detects a campaign in which 12 AI agents operate simultaneously inside a corporate network, writing and testing 80 malicious modules and 70 evasion techniques over a few days.

Early 2026. Unit 42, the threat intelligence arm of Palo Alto Networks, documents a collapse in dwell time: in the fastest cases investigated, attackers move from initial access to data exfiltration in 72 minutes — a fourfold acceleration year over year.

Attack automation has left the lab. It is measured, documented, live in the wild, and it is resetting the clock for every security team.

Malicious AI has moved from experiment to operational playbook

The tools are a matter of public record. WormGPT broke the dam in 2023, followed by FraudGPT, Evil-GPT, and a stream of variants maintained across criminal marketplaces. Their value proposition is blunt: grammatically flawless phishing content in any language, produced in seconds, with none of the restrictions of commercial models.

Sophos documented the STAC6994 campaign in 2025 — the first provable case of attackers using AI agents as an operational force multiplier. Inside the compromised network, 12 AI agents were developing, testing, and iterating malicious code against the major EDR platforms: CrowdStrike Falcon, Microsoft Defender, Sophos Intercept X. The output: 80 modules and 70 evasion techniques, produced in days. A human operator working alone would have needed weeks.

The Unit 42 2026 Global Incident Response Report, published by Palo Alto Networks in February 2026, makes the picture quantitative. Drawing on 750-plus incident response engagements across 50 countries, the report finds that AI is not fundamentally changing what attacks look like. It is collapsing how long they take.

Attackers are not inventing novel techniques. They are automating reconnaissance, payload generation, multilingual spear phishing, and data staging. The result is a kill chain that fits inside a one-hour meeting.

Identity has replaced the perimeter — and the attackers know it

The Unit 42 data surfaces a statistical shift that most SOCs have not yet baked into their processes.

65% of initial access vectors are now identity-based: compromised credentials, MFA manipulation, targeted social engineering, help-desk impersonation. Software vulnerabilities account for just 22% of entry points. Attackers are not breaking in. They are logging in.

In 89% of investigations, identity weaknesses played a material role in the breach. Ungoverned OAuth tokens, non-rotating service accounts, unmonitored active sessions — every brick of the IAM stack has become an attack vector in its own right.

48% of incidents now involve browser-based activity. The browser is no longer a productivity tool. It is the primary theater of compromise, where attackers steal session cookies, access tokens, and browser-stored credentials in bulk.

Attacked surfaces are fragmenting faster than teams can track them

Another figure from the Unit 42 report: in 87% of cases, attackers operated across two or more attack surfaces simultaneously — endpoint, cloud, SaaS, identity, email. In some incidents, malicious activity unfolded across ten distinct vectors at once.

SaaS integrations have become a risk multiplier. 23% of incidents exploited a third-party application connected to the victim’s environment. An OAuth token granted to a productivity tool becomes a backdoor into email, CRM, and cloud storage.

The root cause is rarely attacker sophistication. In 90% of cases, misconfigurations and visibility gaps enabled the attack. Tool sprawl — some organizations run 50 or more security products — creates a complexity debt that security teams can no longer service.

Deepfake phishing is no longer a thought experiment

Voice and video deepfake tools have crossed the operational threshold. In February 2025, a finance employee at a multinational transferred $25 million after a video call with what appeared to be their CFO — a real-time deepfake generated from public footage.

Uncensored LLMs can now generate personalised spear phishing emails at the scale of an entire organization. An attacker scrapes LinkedIn profiles, parses a company’s public communications, and produces hundreds of context-aware lures in under an hour.

The cost of these attacks is in freefall. Where a manual spear phishing campaign cost thousands of dollars in human time, AI brings it within reach for tens of dollars in API credits.

Defenders have one option: automate or fall behind

The compression of dwell time to 72 minutes delivers a harsh verdict: a SOC that relies on human analysts for first-line detection is structurally late.

Only 6% of organizations have deployed agentic AI in their security operations, even though 92% acknowledge that AI helps their teams review more events. The gap is not technological. It is decision-making velocity.

The recommendations are converging:

  • EDR/XDR with automated response capabilities (SOAR): detection without immediate containment is useless against a 72-minute attack chain.
  • Behavioral detection: static signatures cannot keep up with AI-generated payloads that mutate on every execution. Endpoint and identity behavioral analysis becomes the primary safety net.
  • Phishing-resistant MFA: attackers now bypass standard MFA through fatigue attacks, push bombing, and token theft. FIDO2 security keys and strict conditional access policies are no longer optional.
  • Machine identity governance: every API key, every OAuth token, every service account must be inventoried, scoped to least privilege, and rotated on a schedule.
  • Segmentation and zero trust: a compromised credential must not grant unfettered traversal of the entire environment without re-authentication.

CISA, the US cybersecurity agency, has lost nearly 30% of its workforce since early 2025, dropping from approximately 3,400 to 2,400 staff. The CIRCIA incident reporting rule is delayed. CISOs cannot count on a federal safety net that is itself contracting.

The verdict

If your security team still measures effectiveness by the number of alerts processed per shift, you have already lost the first 72 minutes.

The metric that matters is no longer volume. It is MTTR — Mean Time to Respond — brought under 15 minutes for high-criticality incidents. Hitting that target means automating tier-1 triage and containment to the point where no human approval is required for the initial response.

Organizations that have started this transition — unified platform, AI-native detection, automated response — are closing the gap. Those hiring more analysts to keep pace are widening it. The cost of a traditional SOC is no longer just financial. It is measured in the minutes the adversary is stealing.

The question is not whether AI will accelerate cyberattacks. It already has. The question is whether your defenses operate at the same speed.

References

The cyber brief, every Tuesday

The flaws that matter and the patches to apply, in a ten-minute read.

No spam. One-click unsubscribe.
read next

On the same topic

API attacks became the number one data breach vector in 2026

99% of organizations experienced an API security incident in 2025. APIs now account for 43% of actively exploited vulnerabilities in CISA’s KEV catalog. Your API gateway is your new firewall — and you probably haven’t configured it.

← Back to the feed

Type at least two characters.

navigate open esc dismiss