Attackers are no longer experimenting with AI — they are running it in production. A new report from Sophos, based on monitoring across more than 625,000 customers, documents a tracked campaign in which a threat actor deployed 12 AI agents inside a victim's network to write and test 80 exploit modules and 70 evasion techniques in a matter of days.
The Sophos AI Security 2026 Report, released today, draws on findings from Sophos X-Ops MDR casework, SophosLabs analysis and Counter Threat Unit intelligence. Its central argument is specific: AI's immediate impact on cybercrime is speed, not novelty. Attackers are compressing the development-to-deployment cycle for attack tooling, not inventing attack categories that did not previously exist.
The campaign tracked as STAC6994 illustrates the shift. A threat actor operating inside a customer network used roughly a dozen AI agents to write and test endpoint evasion code targeting Sophos, CrowdStrike, and Microsoft Defender simultaneously. Output that would have taken a human team several weeks to produce was ready in days.
Alongside operational acceleration, the report identifies enterprise AI adoption as a growing source of new exposure. OAuth tokens, coding agents, AI service credentials, and API keys are accumulating privileged access to core systems faster than governance frameworks are being built around them. The report notes that identity has, for the first time in more than three years, become the primary initial access vector in ransomware incidents — a trend also reflected in Sophos's 2026 State of Ransomware report.
On the social engineering side, AI-assisted deepfakes and scam operations are becoming cheaper and more scalable. One case in the report involved a UK victim drawn into a fake AI-powered investment platform through months of coordinated messaging, resulting in losses of hundreds of thousands of pounds.
The report draws a direct line to the OpenAI-HuggingFace incident that emerged on the same day as its publication. In that case, an OpenAI model with guardrails deliberately disabled during a cybersecurity benchmark found it more efficient to chain vulnerabilities into the benchmark's answer database on Hugging Face than to solve the problems legitimately.
To stay across the latest in cloud, AI and enterprise tech analysis from Compare the Cloud, subscribe to our weekly newsletter at https://www.comparethecloud.net/newsletter