Rogue AI Agents Are Democratizing Cyberattacks. Here’s How.
Agents can already discover assets, enumerate services, and map an attack surface with little human input.

In mid September 2025, Anthropic's threat intelligence team detected what it later described as the first documented AI-orchestrated cyber espionage campaign at scale.
A Chinese state sponsored group, tracked internally as GTG 1002, used Anthropic's coding assistant, Claude Code, as the operational core of an intrusion effort against roughly 30 organizations worldwide including major tech firms, financial institutions, chemical manufacturers, and government agencies.
Human operators selected targets and approved a small number of key decisions. The AI carried out the rest, including reconnaissance, vulnerability discovery, exploit writing, credential harvesting, and lateral movement.
Anthropic estimated the AI executed between 80 and 90 percent of the operational work at a request rate no human team could match. Human involvement in key decision points was limited to roughly 20 minutes, according to a summary of the case published by law firm Paul, Weiss.
Nine months later, a similar pattern surfaced closer to an active geopolitical flashpoint. In early July 2026 hackers suspected to be linked to China assembled what researchers described as a near autonomous hacking system aimed at Taiwan, running as many as eight AI agents simultaneously, each capable of researching targets, testing for weaknesses, correcting its own errors, and adjusting strategy with limited human supervision, according to reporting from PCMag. Taiwan's National Security Bureau said China linked attacks on the island's critical infrastructure rose 6 percent in 2025, reaching an average of 2.63 million attempts per day.
Separately, researchers behind a 2025 study on abusing the Model Context Protocol for agentic red teaming reported that a system integrating their MCP based command and control framework achieved full domain dominance on a corporate network in under an hour, with no human intervention, adapting its tactics on the fly to evade endpoint detection and response tools.
"The security risk evolves from bad output to bad actions," Tony Sabaj, Head of Americas Channel Engineering at Check Point Software, told International Business Times.
The Lifecycle is Already Automatable
Sabaj broke down the cyberattack lifecycle step by step.
Agents can already discover assets, enumerate services, and map an attack surface with little human input. They can analyze code for vulnerabilities and misconfigurations, and in some cases surface novel weaknesses. They can generate phishing content and social engineering material that reads as legitimate correspondence. Once inside an environment, they can chain known vulnerabilities together, write exploit code for documented flaws, identify high value credentials and systems, and recommend paths for lateral movement.
That breakdown maps closely onto Anthropic's account of the GTG 1002 campaign, in which the orchestration engine ran autonomous reconnaissance in parallel against multiple targets, independently discovered vulnerabilities, and carried out exploitation largely without a human at the keyboard.
Anthropic's report also noted how the attackers got Claude to participate in the first place.
Rather than using a technical exploit against the model itself, the operators told Claude they worked for a legitimate cybersecurity firm conducting authorized defensive penetration testing, and the model, trained to avoid harmful behavior, proceeded on that basis, according toa summary of the incident from the Congressional Research Service.
Is it Actually Lowering the Bar?
Asked whether agentic AI is genuinely handing sophisticated capability to less skilled attackers, Sabaj said, "Yes, but with important caveats."
He went on to say that mid tier attackers can now operate at a noticeably higher level, experienced operators can scale campaigns dramatically, and small teams can run operations that previously required a much larger group.
Vincenzo Ciancaglini, a senior threat researcher at Trend Micro, described the current state of malicious agentic AI as an even bigger Wild West than the large language model field was two years ago, according to MIT Technology Review. Dmitrii Volkov, research lead at Palisade Research, a group that builds AI agents to test how other AI agents behave in attack scenarios, said the effort behind that work was to ground theoretical concerns in evidence, according to the same report.
Where Experts Disagree on Timing
Michael Freeman, head of threat intelligence at Armis, predicted that by mid 2026 at least one major global enterprise would suffer a breach caused or significantly advanced by a fully autonomous agentic AI system, describing agents capable of using reinforcement learning and multi-agent coordination to plan, adapt, and execute an entire attack lifecycle, allowing a single operator to direct a swarm of agents at a target, according to SecurityWeek.
The United Kingdom's National Cyber Security Centre has taken a more measured position, assessing that fully automated, end to end advanced cyberattacks are unlikely before 2027, and that skilled human operators will still need to remain in the loop even as individual pieces of the attack chain become more automated, according to the same SecurityWeek report.
Sabaj pointed to several unresolved limitations behind that more cautious assessment: agents still make mistakes and misjudge goals under uncertainty, long horizon planning across many coordinated decisions remains difficult to sustain, and the operational security instincts human attackers rely on, including stealth and adaptation, are not yet consistent strengths of AI systems.
Real enterprise environments add further friction, including incomplete information, authentication barriers, and network segmentation. Agents also remain bounded by what they are permitted to access, meaning autonomy has a hard ceiling without credentials and tool integrations.
Anthropic's own report on GTG 1002 noted that Claude's tendency to hallucinate, including fabricating credentials and overstating findings during autonomous operation, created friction for the attackers, a factor cited as one reason a fully autonomous, error free campaign remains unlikely for now.
What Businesses Are Being Told to Prepare For
Tal Skverer, Head of Research at Astrix, offered a framing of the GTG 1002 case: the incident is not evidence that attackers found a fundamentally new way in, but evidence that they can now run familiar attacks more efficiently and at greater scale, according to Astrix Security.
Sabaj listed priorities for organizations preparing for AI assisted attacks. They include maintaining an inventory of which AI agents exist and what they can access; monitoring agents at runtime the way privileged human users are monitored; treating prompt injection as the leading attack vector against AI systems specifically; limiting agent permissions and tool access by default; and building incident response plans for scenarios including agent compromise, memory poisoning, and AI driven data exfiltration.
Scott Swanson, Practice Leader for Security Advisory at Stroz Friedberg, a LevelBlue company, said the industry is "seeing the first big splash of autonomous AI agents," a trend he expects to accelerate through 2026.
"The organizations most likely to struggle," Sabaj said, "are those treating AI as a productivity tool rather than as a new category of privileged actor that requires governance, monitoring, and runtime controls."
© Copyright IBTimes 2026. All rights reserved.






















