When AI Started Running the Attacks

Check Point Research’s second annual AI Security Report 2026 delivers a blunt message: artificial intelligence has stopped merely assisting cybercriminals and started operating attacks on its own. The report, built on real incidents and Check Point’s own telemetry, paints a picture of a threat landscape that moves faster than defenders can keep up with.

From assistant to operator

A year ago, AI was seen as a “force multiplier” — making existing attacks cheaper and faster. Now, researchers have documented intrusions where AI ran exploitation workflows with minimal human input. In one striking case, a single developer used a commercial AI coding tool to build VoidLink, an 88,000-line malware framework, in under a week — work that once would have needed a skilled team of engineers. In Anthropic’s disclosed GTG-1002 campaign, Claude Code reportedly handled 80–90% of the tactical work in an espionage operation. Most tellingly, these AI-driven attacks were usually discovered because of the attackers’ own mistakes — not because victims caught them.

AI itself is now a target

The report devotes a full chapter to AI as an “attack surface.” Because language models treat instructions and data as a single continuous stream of text, attackers can hide commands within documents, emails, or web pages — a technique known as prompt injection. Configuration files that coding agents blindly trust, such as CLAUDE.md, have already been weaponised in real breaches, including a sweeping attack against nine Mexican government agencies that exposed roughly 400 million records.

Trust itself is breaking down

Perhaps the most unsettling finding is that voices, faces, and even live video calls can no longer be trusted as proof of identity. Voice-cloning services now run as commercial products, deepfake video calls have tricked crypto investors, and North Korean operatives have used AI-generated personas to get hired as remote IT workers at Western companies — reportedly funnelling close to $800 million toward weapons programs.

Enterprises are leaking data by accident

Away from criminal activity, the report finds that ordinary business use of AI is itself a growing risk. High-risk GenAI prompts — those containing sensitive corporate or personal data — doubled over the past year, and the average company now uses ten different AI tools a month, many without formal approval.

The bottom line

Check Point’s core recommendation for security leaders is a mindset shift: treat AI as a live, fast-moving attacker, not just a productivity tool. As the report puts it, vulnerabilities are now found and exploited in hours, not weeks — meaning defenders must adopt AI-speed security just to keep pace.

Author