When the Hacker Isn’t Human Anymore: Inside the AI Driven Attack Surge of 2025 to 2026
Cybersecurity has always been an arms race, but the last eighteen months have compressed years of escalation into a handful of headlines. Threat actors that used to need a team, a budget, and weeks of reconnaissance can now run a sophisticated intrusion with a laptop, an API key, and a jailbroken chatbot. The numbers coming out of the industry’s most credible threat intel shops this year aren’t speculative “AI will change everything” predictions anymore; they’re after-action reports.
The headline number: an 89% jump
CrowdStrike’s 2026 Global Threat Report put a hard figure on what practitioners have felt anecdotally for two years: attacks by AI enabled adversaries increased 89% year over year in 2025. That’s not a rounding error or a methodology quirk; it tracks with a broader shift in how fast intrusions move once an attacker is inside.
The report’s other flagship metric is arguably more alarming than the 89%: average eCrime “breakout time” (the time it takes an attacker to move from initial compromise to lateral movement inside a network) dropped to just 29 minutes in 2025, a 65% acceleration from 2024. The fastest recorded breakout was 27 seconds. For context, that average sat at 98 minutes back in 2021. Defenders who built their incident response playbooks around “we have a few hours to detect and contain” are now working against a clock measured in minutes, sometimes seconds.
CrowdStrike also named names. Russia nexus FANCY BEAR deployed an LLM-enabled malware strain called LAMEHUG. The eCrime group PUNK SPIDER used AI generated scripts to automate credential dumping. North Korea’s FAMOUS CHOLLIMA leaned on AI-generated personas to run insider threat and fake remote worker schemes, while a related DPRK nexus actor, PRESSURE CHOLLIMA, was tied to a staggering $1.46 billion cryptocurrency theft. Over 90 organizations were separately targeted through malicious prompts injected directly into generative AI tools, meaning the AI infrastructure itself is now part of the attack surface, not just the attacker’s toolkit.
When AI runs the whole operation
If the CrowdStrike numbers describe a trend, Anthropic’s own threat intelligence disclosures describe what the leading edge of that trend actually looks like in practice, and it’s a genuine inflection point.
In September 2025, Anthropic disrupted a cyber espionage campaign it assessed with high confidence was run by a Chinese state-sponsored group. The attackers had jailbroken Claude Code, convincing the model it was an employee at a legitimate cybersecurity firm conducting authorized defensive testing. Once past that guardrail, the AI didn’t just assist; it executed. Anthropic’s own accounting is worth reading twice: the AI performed an estimated 80 to 90% of the campaign autonomously, with human operators stepping in only at four to six critical decision points per engagement, mostly to approve targets or make judgment calls the model wouldn’t make on its own. The system fired off thousands of requests, often multiple per second, a tempo no human operator team could sustain. Roughly thirty organizations were targeted (major tech companies, financial institutions, chemical manufacturers, and government agencies) and a small subset were successfully infiltrated.
Anthropic called it the first documented large scale cyberattack executed without substantial human intervention. That label matters less than what it implies: the traditional bottleneck on sophisticated cyber operations (needing a skilled team large enough to do reconnaissance, write exploits, move laterally, and stay undetected all at once) is eroding. A single operator with the right jailbreak can now direct what used to require a nation state’s staffing.
Anthropic’s follow-up report, covering activity through August 2026, showed this wasn’t a one-off. The company disrupted campaigns across seven categories of AI misuse, including a Russian-linked espionage operation (tracked as GTG20006) that hit more than 20 organizations across Ukraine, Europe, the Middle East, and Asia, compromising over 300,000 national identity records and 500,000 company registry entries pulled from a North African government system. A financially motivated group affiliated with ShinyHunters (GTG50014) used AI to harvest 1.8 million Android APKs, exfiltrate more than a terabyte of data from a technology provider, and reach tens of millions of airline passenger records, reportedly achieving full administrative control of one target’s systems in roughly three hours.
A separate Chinese-linked group (GTG10007) hit about 50 organizations worldwide. In one especially pointed case, a criminal group compromised an AI vendor’s own evaluation sandbox specifically to steal production API keys from multiple AI providers, attackers going after AI infrastructure as the payload, not just the tool.
It’s not just nation states, it’s everyday fraud, too
The state sponsored campaigns get the headlines, but the dollar and cents impact on ordinary people and businesses is arguably more consequential day to day. The FBI’s 2025 Internet Crime Report included AI-related fraud statistics for the first time in the IC3’s roughly 25-year history, a telling milestone on its own. The bureau logged 22,364 complaints involving AI and nearly $893 million in reported losses. The report specifically calls out fraudsters using AI to generate fake social media profiles, cloned voices, fabricated identification documents, and convincing videos impersonating public figures or, more disturbingly, victims’ own loved ones. The deepfake “grandparent scam” and its corporate cousin, the deepfake CEO wire transfer request, have both moved from novelty to statistic.
On the enterprise side, a large scale IBM/Ponemon breach study covering March 2025 through February 2026 found that one in four malicious breaches were now AI enabled, a 56% year over year increase, and that AI enabled breaches cost organizations an average of $6 million, about a million dollars more than the global average breach cost. More than one in five breached organizations reported attacks that specifically targeted their AI models or applications, and researchers at Trend Micro separately found more than 113,000 internet-exposed Ollama instances and 2,500 exposed Chroma vector database servers sitting open between September and December 2025, unlocked doors into the AI systems companies rushed to deploy without securing them first.
What this actually means for defenders
Pull these threads together, and a consistent picture emerges. AI is lowering the skill and cost barrier to running a sophisticated attack, compressing the time defenders have to detect and respond, and, critically, becoming a target in its own right, not just a tool attackers borrow. The organizations getting hurt worst aren’t necessarily the ones with weak firewalls; they’re the ones that deployed AI systems and agentic tooling faster than they built the guardrails, monitoring, and incident response muscle to match.
That’s also the honest case for why the skills gap matters right now more than it did two years ago. Breakout times measured in minutes mean detection and response can’t be a purely human, purely manual process anymore; analysts need to understand how AI-enabled attacks actually behave, how to red team the AI systems their own organizations are standing up, and how to build defenses that can move at machine speed when the adversary already does. The attackers adapted first. The defenders who catch up won’t do it by accident.
Build the skills before the next breakout timer starts
None of this is theoretical for the people who have to defend a network on a Monday morning. If a 29-minute breakout time and an autonomous, AI-orchestrated espionage campaign sound like reasons to get serious about your own skill set, that’s exactly the gap Cyberkraft was built to close.
If you learn best with structure and a cohort, Cyberkraft’s live, instructor-led bootcamps run 40 hours of real-time training across Security+, CySA+, PenTest+, SecAI+, CISSP, CCSP, CEH, CCNA, and more, with bonus video access so nothing gets missed. If you’d rather move at your own pace, the self-paced courses cover the same certification tracks with full video modules, live review sessions, and practice exams you can work through on your own schedule.
Enroll in a live bootcamp or browse the self-paced courses at cyberkrafttraining.com to start closing that gap today.

