
Cybersecurity investigators recorded an 89% year-on-year increase in attacks in which adversaries used artificial intelligence to scale operations, accelerate their methods or target AI infrastructure, highlighting the speed with which generative and agentic tools are entering active attack workflows.
The increase forms part of a broader shift towards attacks that rely on compromised identities, trusted services and cloud infrastructure instead of conventional malware. CrowdStrike’s threat data showed that 82% of detections were malware-free, while cloud-conscious intrusions involving state-linked actors increased 266%. The company also recorded a 42% increase in vulnerabilities exploited before public disclosure.
The fastest observed e-crime breakout time, measuring how quickly an attacker moved laterally after gaining initial access, fell to 27 seconds. Such compression reduces the period available for security teams to investigate an alert, contain an identity or isolate a compromised system before the attacker reaches additional resources.
Artificial intelligence is being applied across several stages of this process. Reported uses include generating and modifying scripts, automating reconnaissance, producing convincing identities and communications, identifying attack paths and targeting the infrastructure used to build or operate AI systems. In one documented case, Russia-linked operators deployed language-model-enabled malware to automate reconnaissance and document collection. Other groups used AI-generated personas to support fraudulent remote-worker operations.
Technology companies are particularly exposed because their repositories, development tools, training data and model intellectual property represent high-value targets. China-linked adversaries accounted for more than 58% of state-sponsored targeted intrusions against the technology sector in a separate 2026 assessment. Extortion groups named 572 technology organisations on dedicated leak sites during the reporting period, substantially more than the totals recorded for several other sensitive sectors.
The threat pattern is closely aligned with the operating environments of Indian technology-services companies, global capability centres, financial institutions, manufacturers and telecommunications providers. These organisations depend extensively on cloud identities, software repositories, remote access, SaaS integrations and distributed engineering teams. India also hosts development and operational functions serving global customers, giving a compromised account or code pipeline potential consequences across jurisdictions.
CERT-In’s frontier-AI guidance identifies autonomous vulnerability discovery, source-code analysis, exploit development and multi-stage network attacks among the capabilities requiring immediate defensive attention. Its recommended controls include zero-trust network architecture, multifactor authentication, protection of privileged identities, continuous monitoring, updated incident-response plans and AI-enabled vulnerability detection.
The reported increase does not mean that 89% more cyberattacks overall were recorded. It specifically measures attacks in which identified adversaries used AI to enhance operations or target AI-related infrastructure. The distinction is important because the figures describe a change in attack methods rather than the full volume of global cyber incidents.




