When Cybercriminals Set the Pace

A security monitoring center and an analyst responding to threats involving AI in cybercrime.

A phishing message or a stolen password may be only the beginning of an attack. What follows depends increasingly on how quickly attackers can turn that initial access into further intrusions. AI in cybercrime is accelerating this process, leaving defenders less time to understand what is happening and contain the damage.

AI in Cybercrime Goes Beyond Phishing

AI in cybercrime is no longer confined to specialized hacking groups. Tools powered by artificial intelligence serve everyone from perpetrators of mass scams and phishing campaigns to data thieves and groups conducting cyber espionage. AI makes their work easier at many stages: researching potential victims, creating persuasive content, and analyzing information obtained during a breach.

Two reports published in September 2026 illustrate how cybercriminals’ use of AI is changing. The first came from Google Threat Intelligence Group, Google’s team of digital threat analysts. The second came from Anthropic, the company behind Claude. Both analyses point to the same trend. AI is moving beyond its role as a digital assistant and increasingly supporting successive stages of an attack, from identifying weaknesses to stealing data.

Given a Task, the System Looks for a Solution

Google highlights the shift from basic prompting—giving a model individual instructions—to agentic systems. These systems can receive a goal, a set of instructions, and access to specific tools. They can then carry out successive steps, check their results, and try alternative approaches when they encounter a problem.

The difference is like asking a chatbot to write a fraudulent email versus asking it to prepare an entire campaign.

In the first case, a person receives a finished text and decides what to do next. In the second, the system can research recipients, prepare several versions of a message, create the necessary technical components, check whether they work, and attempt repairs if something goes wrong. A person still sets the goal and provides access to the tools, but no longer has to carry out every step personally.

AI in Cybercrime Speeds Up Every Stage of an Attack

In one case described by Google, cybercriminals gained access to corporate cloud resources and used them, together with an AI coding chatbot and AI agents, to steal login credentials on a large scale. Planning, preparing, and launching the operation took less than six hours.

AI agents automatically identified vulnerable targets, resolved technical problems, and rotated the IP addresses used in the campaign. Google concluded that this reduced “human-in-the-loop latency” between successive stages of the attack.

The attack was not fully autonomous. A person first had to gain access to the infrastructure and define the operation’s goal. Even so, the example reveals a significant change. Less time now passes between a cybercriminal’s decision and the execution of subsequent stages of an attack. Previously, each stage required human involvement. Someone had to review scan results, fix code, find another route to the target, or decide what to do after encountering a security control.

Anthropic Describes a Similar Pattern

Google’s observations are not isolated. Anthropic described cases in which cybercriminals used its tools. The findings showed that artificial intelligence helped them gather information and create content, as well as automate activities leading to intrusions and data theft.

In one case, AI tools supported almost the entire operation: setting up infrastructure, conducting phishing, maintaining access to compromised systems, and extracting data. In another, AI agents rebuilt malware after security systems detected it. A person still set the goal and monitored the results, but the model took over a substantial share of the repetitive technical work.

Every Hour Works in the Attackers’ Favor

For users, the difference between a traditional attack and an agentic attack may be almost imperceptible. Either can begin in an entirely ordinary way: with a fraudulent message, a stolen password, or a poorly secured account. What changes is the pace of what follows. An agentic system can simultaneously examine stolen data, attempt to gain access to additional services, and prepare the next stage of the attack. Before an organization responds to the first warning sign, attackers may already have copied the data and used the compromised account to carry out further scams.

For a bank, online store, public agency, or social media platform, detecting and stopping suspicious activity takes time. Staff must confirm that an alert indicates a real attack, assess its scale, and decide what to block. That caution is necessary, but every hour spent verifying a threat gives attackers time to take further action.

AI in cybercrime does not mean that machines now carry out every intrusion on their own. People still choose targets, provide tools, and make the most important decisions. Yet the Google and Anthropic reports point in the same direction: AI systems are taking over more of the repetitive tasks between cybercriminals’ successive actions. For defenders, the central challenge is the shrinking window in which to detect an attack, understand how it is unfolding, and limit the damage.


Read this article in Polish: AI wspiera cyberprzestępców. Coraz mniej czasu na obronę

Published by

Mariusz Martynelis

Author


A Journalism and Social Communication graduate with 15 years of experience in the media industry. He has worked for titles such as "Dziennik Łódzki," "Super Express," and "Eska" radio. In parallel, he has collaborated with advertising agencies and worked as a film translator. A passionate fan of good cinema, fantasy literature, and sports. He credits his physical and mental well-being to his Samoyed, Jaskier.

Want to stay up to date?

Subscribe to our mailing list. We'll send you notifications about new content on our site and podcasts.
You can unsubscribe at any time!

Your subscription could not be saved. Please try again.
Your subscription has been successful.

Popular

Zmień tryb na ciemny