AI already multiplies by four the speed of cyber attacks on companies

Foto del autor

By Jack Ferson

The latest 2026 Global Incident Response Report from Unit 42, the threat intelligence division of Palo Alto Networks, paints a disturbing scenario: Attackers are systematically using artificial intelligence and have managed to accelerate the entire intrusion cycle up to four times in just one year.

The most alarming fact is the time it takes for some groups to go from initial access to data exfiltration. In the fastest cases analyzed, that process has been reduced to just 72 minutes.

That is, a company can be breached, explored and looted in just over an hour if it does not have automated detection mechanisms.

The study is based on the analysis of more than 750 critical incidents managed during the last financial year. The conclusion is clear: AI is already a structural part of the offensive arsenal and is being used throughout the entire life cycle of the attack, from the recognition phase to the evasion of controls and the automation of lateral movement within corporate networks.

Identities in the spotlight

One of the most significant changes detected in the report is the prominence of identity-based techniques. 65% of initial access occurs through credential abuse, social engineering or exploitation of flaws in the management of human and machine identities. Traditional technical vulnerabilities represent a smaller percentage of the entry point.

Attackers no longer need to exploit just a misconfigured server. They simply compromise a valid account, OAuth token, or API key to navigate complex corporate environments.

Identity has become the new critical surface and, at the same time, one of the weakest links in the defense chain.

Multi-channel attacks and more difficult to contain

The report reveals that 87% of the incidents analyzed involve two or more attack surfaces. These are not linear intrusions, but rather coordinated operations that combine actions on endpoints, cloud platforms, identity systems and third-party applications. In some cases, simultaneous activity has been observed on up to ten different fronts.

The corporate browser is also emerging as a key battleground. Almost half of the attacks studied include some type of manipulation of web sessions, theft of credentials through apparently legitimate pages or abuse of extensions. What was once a simple work tool has become a strategic vector.

Additionally, attacks linked to the SaaS supply chain have skyrocketed. Since 2022 they have multiplied by almost four and already represent a relevant part of the total incidents.

Exploiting integrations between applications and misusing permissions granted to third parties allow attackers to move laterally without raising immediate suspicion.

Gaps born of complexity

Unit 42 links 90% of data breaches to misconfigurations or security flaws resulting from complexity. Lack of unified visibility, tool fragmentation, and overconfidence implicitly facilitate the success of adversaries.

When security teams rely on siled solutions that don’t share information in real time, response capacity slows. In an environment where attackers operate within minutes, Any delay can mean the difference between containing an incident or suffering a massive leak of sensitive information.

The adoption of AI-based autonomous agents by cybercriminals adds an additional layer of risk. These systems can correlate human and machine credentials, escalate privileges, and execute actions without constant intervention, dramatically reducing traditional attack times.

Towards a defense at machine speed

The report raises the need to evolve towards integrated security models capable of operating with advanced automation. Organizations must reinforce their operations centers with tools that detect anomalies in seconds and apply containment measures without prolonged manual intervention.

It is also essential to integrate security into the software and artificial intelligence development cycle, preventing vulnerabilities from reaching productive environments.

Deja un comentario