How AI gives cybercriminals machine-speed attack capability
AI has accelerated cyber attacks to the point where organisations must now detect and respond to breaches within minutes to limit damage
Organisations that cannot detect and respond to a breach within roughly an hour are now operating below the threshold of what constitutes an adequate security posture, according to a senior Palo Alto Networks threat intelligence specialist.
Taylor Reed, principal consultant and threat intelligence advisory lead at Palo Alto Networks, Unit 42, JAPAC, told a UNSW Cyber Security Summit that AI has fundamentally changed the speed at which criminal groups can penetrate corporate environments and extract data. In 25% of cases tracked by the company’s Unit 42 research team, attackers moved from initial access to confirmed data exfiltration in 72 minutes.
“AI is no longer a concept – it’s now an attack accelerator,” Mr Reed said. “What it’s doing is increasing the attack speed and the consistency, so it’s collapsing that time window that incident responders have to be able to detect, identify, and respond to attacks that are happening within the environment.”
Photo gallery: the UNSW Cyber Security Summit
That 72-minute figure represents the new status quo. Mr Reed observed that organisations with established security operations centres and strong processes were struggling to keep pace. “We work with a lot of our large organisations that kind of have the gold standard in a well-established SOC with very mature processes as well, and they’re even struggling now, so they’re bringing in more automation for some of the tasks that they do throughout the SOC, so they can match that machine speed.”
Three trends reshaping the threat environment
Mr Reed outlined three trends driving the shift. The first is that AI has become a force multiplier for criminal groups. Major cybercriminal threat actors are already using it at scale, and as the skill barrier falls, smaller and less experienced criminal factions will become capable of executing attacks at the same level.
The second trend is the increasing centrality of identity in attack chains. Mr Reed said identity weaknesses played a role in 89% of investigations handled by Unit 42. Attackers are using AI to improve the quality and volume of phishing campaigns, but the more notable development is how effectively they can move through an environment once inside, using legitimate credentials to blend into normal network traffic.
Learn more: When AI becomes a weapon in the cybersecurity arms race
“What we’re seeing is that credentials – not only from obtaining credentials on the dark web, but also being able to pull credentials out of memory or conduct things like Kerberoasting attacks – are used to move laterally throughout the environment as well, using living-off-the-land tactics, techniques, and procedures,” he observed.
The third trend is the expansion of software supply chain risk. Unit 42 has tracked a 3.8-fold increase in attacks involving third-party SaaS applications, with that vector now accounting for 23% of attacks in 2026. The risk is no longer limited to vulnerable code; it extends to the abuse of trusted connectivity between organisations and their vendors.
How attackers get in
Phishing and software vulnerabilities each accounted for 22% of initial access in cases Unit 42 investigated, with previously compromised credentials responsible for a further 13%. Mr Reed said AI is making phishing harder to detect, even for security professionals familiar with the threat. “It used to be pretty easily detectable, especially if you work in this field. However, it’s becoming more and more difficult now to be able to discern that as well.”
The growing exploitation of third-party connections is compounding the problem. In one 2025 investigation, Unit 42 discovered approximately 100 third-party integrations following a breach that were unknown to the organisation’s security team, many of which were dormant or owned by former employees.
"It comes down to the fundamentals – identity, things like zero trust architecture, defence in depth, setting up proper segmentation in your network"
TAYLOR REED
Because those integrations lacked endpoint detection agents and generated normal-looking traffic, Mr Reed noted they provided attackers with an unmonitored entry point. “Attackers are aware of this, particularly when it comes to third-party applications, so that’s what they target, and they can effectively have the same impact as if they were breaching the environment directly.”
Mr Reed cited the Canvas breach executed by Shiny Hunters as an illustration of how a single compromised third party can cascade across multiple large organisations simultaneously. Universities face particular exposure on this front. Open-by-design networks, large volumes of intellectual property, and complex federated identity environments across student and staff populations consistently place the education sector among the top ten verticals targeted by threat actors. Mr Reed said AI-enabled attackers can now breach a university network and exfiltrate data in under two hours.
The attack is changing shape
Beyond speed, Mr Reed said the nature of ransomware attacks is shifting in ways that require organisations to rethink their defensive priorities. Groups that previously focused on encrypting environments to extract payment are now skipping that step and moving directly to data exfiltration and publication on the dark web.
“In 2026, what we’re assessing is that intent will continue to change, where we’ll see less encryption, but it will be really important to have things like DLP, and be able to monitor how data is egressing the environment and doing so at scale,” he told the audience.

Mr Reed said the change in intent is a direct consequence of attack speed. Encryption takes time and creates noise that defenders can detect; exfiltration at machine speed does not. As breach-to-theft windows have collapsed, the incentive for attackers to encrypt at all has diminished, making data monitoring a higher priority than it has historically been.
Mr Reed said the response to that shift requires automation on the defensive side. As attackers move at machine speed, organisations that rely on manual processes to monitor data egress will not be able to keep pace, and the window between breach and publication on the dark web is now too narrow for a human-speed response to be effective.
Prevention remains within reach
Mr Reed said the picture, while concerning, is not insurmountable. Over 90% of breaches Unit 42 investigated were enabled by preventable gaps in visibility and inconsistently applied controls, not novel or sophisticated techniques. “These are not net new, or these are not novel TTPs. These are effectively still the same TTPs; they’re just being used much more effectively.”
The defensive response, Mr Reed said, does not require organisations to replace existing technology. The priority is to close known gaps and apply controls consistently. “If that is living somewhere in a too-hard bucket, or it’s somewhere in tech debt, or it’s on a roadmap somewhere, effectively what we’re seeing is a lot of organisations are being held to account.”
Subscribe to BusinessThink for the latest research, analysis and insights from UNSW Business School
Mr Reed identified three areas for immediate focus. The first is giving security operations teams the automation tools needed to detect and respond at machine speed. The second is treating identity and access management as a dedicated security domain rather than a function attached to IT operations, with investment in configuration management, trust zone mapping and federated identity governance. The third is integrating security earlier in the software development lifecycle, including AI-assisted code review and threat-led red team activity across applications and cloud environments.
“These problems, I promise you, are solvable,” Mr Reed said. “It comes down to the fundamentals – identity, things like zero trust architecture, defence in depth, setting up proper segmentation in your network.”
Top 5 recommendations for countering AI-enabled cyberthreats
- Close visibility gaps before adding new technology: Over 90% of breaches investigated by Unit 42 were enabled by preventable visibility gaps and inconsistently applied controls. Organisations should audit their existing environment and address known gaps before investing in new tools.
- Design security operations to respond at machine speed: The 72-minute breach-to-exfiltration window means human-speed detection and response is no longer sufficient. Security operations centres should bring in automation to match the attacker's pace and reduce the mean time to detect and respond.
- Treat identity as a dedicated security domain: Identity weaknesses featured in 89% of Unit 42 investigations. Organisations should invest in configuration management, trust zone mapping and federated identity governance rather than treating identity as an extension of IT operations.
- Govern third-party and SaaS integrations continuously: A 3.8-fold increase in third-party SaaS exploitation means unmonitored integrations represent a material risk. Organisations should inventory, assess and monitor all third-party connections, including dormant or legacy applications.
- Integrate security earlier in the software development lifecycle: Shifting security left into development pipelines, including AI-assisted code review and threat-led red team activity, reduces the attack surface before applications reach production environments.