Google security leadership and Google Threat Intelligence Group (GTIG) warned that AI-enabled “end-to-end” attack toolkits—akin to today’s exploit kits but driven by LLMs—are likely to emerge, enabling cybercriminals to automate more of the intrusion lifecycle at scale. Google’s Heather Adkins highlighted current attacker use of AI for incremental workflow improvements (e.g., polishing phishing lures) and expressed concern about future capabilities where a model could be prompted to compromise a target and return actionable exploitation guidance (e.g., a “root prompt”) after extended autonomous work. GTIG also reported that some malware is already using LLMs to generate data-theft commands, and that state-linked actors from China, Iran, and North Korea are abusing AI across stages such as reconnaissance and command-and-control development.
Industry forecasts for 2026 similarly anticipate AI-driven attacks accelerating faster than many organizations’ governance and security tooling can keep up, including disruption to vulnerability management and security testing and the likelihood of early “major breaches” tied to AI adoption and agentic workflows. Predictions also point to continued evolution in extortion economics, with ransomware pressure shifting toward data-leak and regulatory/insurance uncertainty, increasing the need for resilience strategies that combine automation with human oversight. Overall, both perspectives converge on near-term attacker experimentation becoming more operationalized, while defenders are expected to respond with increased use of AI-driven scanning, predictive analytics, and improved detection/response automation.

Track how attackers are adapting to this technology.
7 events from the most recent confirmed update back to the earliest known activity.
A government-focused resilience analysis argued that 2026 would be a pivotal year for defending against fast, covert, AI-driven attacks, especially against critical infrastructure and decision-support systems. It recommended recovery-centric planning, AI-augmented defense, stronger governance, workforce training, and rapid clean-room recovery capabilities.
Guidance aimed at U.S. federal agencies warned that accelerating AI adoption would expand attack surfaces, including AI browsers and LLM-driven workflows, while criminals and state-linked actors were already using AI-generated text and voice deepfakes. The piece recommended continuous automated purple teaming and alignment with emerging AI governance frameworks to address these risks.
A broad expert assessment projected that weaponized AI would become a default capability for threat actors in 2026, increasing attack speed, scale, and evasiveness. The forecast highlighted agentic intrusion automation, prompt-injection attacks, AI-driven social engineering, cloud API abuse, and continued dominance of credential and token theft.
Google security executive Heather Adkins warned that cybercriminals are moving toward AI-enabled toolchains that could automate attacks at scale, potentially allowing an attacker to prompt a model to compromise a company and gain high-privilege access within about a week. Google also said its Threat Intelligence Group had already observed malware using LLM-generated commands and state actors from China, Iran, and North Korea abusing AI in attack workflows.
Security leaders publicly predicted that 2026 would bring the first major breaches directly caused by enterprise AI adoption, especially through exploitation of agentic or AI-enabled workflows. They also forecast a shift in extortion away from encryption toward data theft and leak-based pressure, with resilience depending on combining AI-driven detection with human oversight.
Multiple references characterize 2025 as a year in which AI-enabled cyberattacks increased significantly, with threat actors using AI for phishing, reconnaissance, command-and-control development, and data theft. This surge set the stage for broader concern about more autonomous attacks in 2026.
Anthropic tracked an operation identified as GTG-2002 that used Claude models to help automate end-to-end attacks against 17 organizations in government, healthcare, and emergency sectors. The reporting is cited as an early real-world example of agentic AI being used operationally in cyber intrusions.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Follow how adversaries are adapting to this technology, and where it touches your stack today.
6 references tracked. Mallory keeps watching after this page renders.
nextgov.com
Open sourcenextgov.com
Open sourcescworld.com
Open sourcezdnet.com
Open sourcego.theregister.com
Open sourcescworld.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.