Skip to main content
Threat IntelligenceEmerging Threats

AI Emerges as Force Multiplier in Cyberattacks

Rows of computer equipment in a dimly lit server room lie in disarray, cables scattered and screens flickering with error…

"AI-driven threats should be treated as a strategic priority, particularly as the technology continues to evolve," said Andy Piazza, senior director of threat intelligence, Unit 42.

AI as a force multiplier, not a new class of compromise

Unit 42’s 2026 Global Incident Response Report finds a clear distinction: AI is accelerating and scaling attacks, but it is not fundamentally changing how adversaries gain access. Drawing on hundreds of incident response engagements, the report concludes that AI “is acting as a force multiplier to increase the speed and efficiency of attacks, but is not significantly redefining methods of compromise.” The underlying tradecraft remains familiar — credential theft, phishing, exploitation of known vulnerabilities and ransomware continue to dominate observed intrusions.

Where AI is actually being applied: speed, scale and orchestration

Unit 42 documents concrete uses that explain how AI is altering operations. Threat actors use AI to shorten development cycles, automate content generation and streamline reconnaissance techniques — changes that compress stages of the attack lifecycle from days to hours. Researchers observed malware written using AI and malware that "calls out to a large language model (LLM) or Model Context Protocol (MCP) server for command and control instructions." In one case, Unit 42 identified agentic ransomware that managed multiple stages of an extortion operation; while not fully autonomous, the agent operated end-to-end and reduced operational complexity and timelines.

Token jacking, compute fraud and emerging misuse of stolen AI credentials

Unit 42 highlights token jacking — the exploitation of exposed credentials to access cloud AI services and LLM API tokens — as a rising trend. Stolen tokens can be misused to generate “millions of dollars in unauthorized compute charges at the victim's expense,” and recent trends suggest adversaries are moving beyond simple misuse toward training their own malicious models. These developments show how attackers can weaponize cloud-based AI economics as part of traditional intrusions.

Defenders: prevention first, but know how to use AI

Both Unit 42’s leadership and report authors urge organizations not to overreact by redesigning defenses wholesale, while simultaneously treating AI-driven threats as strategic priorities. Andy Piazza says current signals do not require a fundamental redesign of cyber defense strategy, but he warns that adoption will change operational dynamics. If AI enables attackers to operate faster or at greater scale, teams that rely primarily on detect-and-respond models “may struggle to keep up.” Unit 42 recommends emphasizing prevention controls and continuing to adapt detection and response practices. The report stresses defenders can mitigate AI-enhanced attacks using existing processes and controls — but must also remain informed and integrate AI thoughtfully into their tooling and workflows.

What this means for students and emerging professionals, enterprises, and adversaries

  • Students and emerging cybersecurity professionals: Academic adoption of AI remains limited, creating an “almost ‘anti-AI’ mindset” in some curricula and widening the skills gap between graduates and employer expectations. Unit 42’s authors argue that understanding AI is becoming as essential as knowing traditional security technologies — including the ability to validate AI-generated outputs, spot hallucinations, and know when human judgement must overrule automated recommendations.
  • Affected enterprises and procurement leaders: Organizations should watch for faster, AI-enabled workflows from attackers and prepare by prioritizing prevention controls, ensuring SOCs are not overwhelmed by volume, and considering defensive AI to respond in real time while retaining human oversight of automated agents.
  • Adversaries and threat actors: Unit 42 documents that attackers are already experimenting with agentic approaches, LLM-linked command and control, and token theft. These tactics are currently nascent and “have not had major impacts” to date, but their operational efficiency gains make wider adoption a realistic near-term risk.

Unit 42’s central charge is precise: AI has amplified attackers' speed and scale more than it has invented new vulnerabilities. That nuance matters. Defenders retain the familiar playbook — prevention, detection, response — but must now fold AI literacy and controls into that playbook, train practitioners to validate AI outputs, and plan for a future where automated agents operate faster than individual humans can track. Whether organizations will accelerate preventive controls and defensive AI fast enough to keep pace with adoption by adversaries is the question Unit 42 leaves squarely in the hands of defenders.

Unit 42 — AI, Automation and Attacks: Unpacking the Unit 42 2026 Global Incident Response Report