October 10, 2025
Updated: August 18, 2026
Verified 2026 data on AI-enabled attacks, breach costs, documented campaigns, exposed AI systems, and the controls that reduce risk.
Khaled Hassan

Last updated: August 2026
AI is now a measured factor in real cybercrime, but there is no credible single percentage for all AI cyber attacks. IBM found that one in four malicious breaches in its 2026 study were AI-enabled, while the FBI recorded 22,364 U.S. complaints involving AI and nearly $893 million in reported losses during 2025. Separate provider and threat-intelligence datasets show attackers using AI most heavily for preparation, social engineering, malware development, and evasion. Autonomous operations are documented, but human-led, AI-assisted activity remains the more common pattern.
The numbers below are the strongest current signals we found. They do not share a universal denominator, so each row names the population or measurement behind it.
| Statistic | What was measured | Scope and interpretation |
|---|---|---|
| 1 in 4 malicious breaches were AI-enabled, up 56% year over year | Breach study | IBM/Ponemon study of 602 breached organizations globally, March 2025–February 2026 |
| $6 million average cost for an AI-enabled breach | Breach cost study | About $1 million above IBM’s $4.99 million global breach average in the same study |
| 22,364 AI-related complaints and nearly $893 million in reported losses | U.S. complaint data | FBI IC3 complaints for 2025; not a global attack count and not limited to enterprise intrusions |
| 89% increase in attacks by AI-enabled adversaries | Vendor threat telemetry | CrowdStrike intelligence for activity observed in 2025; not the share of every attack worldwide |
| 832 banned malicious accounts used 482 unique ATT&CK sub-techniques across all 14 tactics | AI-provider misuse dataset | Anthropic sample selected where sufficient detail existed to map behavior, March 2025–March 2026 |
| Medium-or-higher AI-enablement risk rose from about 33.5% to 56.1% | AI-provider misuse dataset | Change within two halves of Anthropic’s selected sample; detection improvements may contribute |
| 69% of the sampled actors used AI for capability development | AI-provider misuse dataset | 574 of 832 accounts; 560 were observed in malware-development activity |
| 6.5% of the sampled actors used AI for lateral movement | AI-provider misuse dataset | 54 of 832 accounts, showing that observed in-network adaptive use remained less common |
| More than 20% of breached organizations reported an attack targeting AI models or applications | Breach study | IBM’s breached-organization sample; 27% cited compromised surrounding APIs, apps, or plug-ins and 27% cited cloud misconfiguration |
| More than 113,000 confirmed Ollama instances and 2,500 Chroma servers were internet-exposed | Exposure scan | Trend Micro/Shodan observations from September to mid-December 2025; exposure does not prove compromise |
IBM’s 2026 Cost of a Data Breach announcement supplies the clearest current breach-cost evidence. The study covers organizations that had already experienced a breach, so its one-in-four result is not a prevalence estimate for every organization or every cyber event.
The FBI’s 2025 Internet Crime Report announcement is a direct measure of reports received by IC3. Complaint totals depend on victim reporting, classification, and U.S. jurisdiction; they should not be relabeled as confirmed incidents or global losses.
CrowdStrike reported an 89% increase in attacks by AI-enabled adversaries and more than 90 organizations where legitimate AI tools were exploited to generate malicious commands or steal sensitive data. Those findings come from the company’s threat-intelligence visibility and should be cited as vendor telemetry, not a census of the internet.
Anthropic’s LLM ATT&CK Navigator study analyzed 832 accounts banned for malicious cyber activity. It offers unusually detailed behavioral evidence, but the company explicitly says this was a selected subset of banned accounts with enough information to map not a random sample of attackers.
For broader context on ransomware, vulnerability exploitation, the human element, and breach patterns that are not necessarily AI-specific, use our current cybersecurity statistics reference rather than merging all cyber-risk figures into an AI total.
“AI cyber attack” is not yet a standardized reporting category. One organization may count a phishing message drafted with a model; another may require AI to materially shape intrusion activity; a third may count attacks against an AI application. Combining those categories produces dramatic but meaningless totals.
Use this five-level evidence hierarchy before quoting a number.
| Evidence type | What it measures | Best use | What it cannot prove alone |
|---|---|---|---|
| Confirmed incident or breach study | Investigated security events, affected organizations, and sometimes financial impact | Estimating business impact and comparing breach outcomes inside the stated sample | The percentage of all organizations or all global attacks involving AI |
| Security telemetry and threat intelligence | Activity visible to a provider’s sensors, customers, investigations, or intelligence collection | Tracking direction, techniques, and changes within that provider’s visibility | A complete census outside the provider’s coverage and detection methods |
| AI-provider misuse dataset | Malicious behavior detected on a specific model, account set, or platform | Understanding how actors request and apply AI assistance | Behavior on other hosted services, local models, or attacks that never touch the provider |
| Complaint or law-enforcement data | Victim reports, alleged losses, and reported criminal methods within a jurisdiction | Measuring reported harm and identifying fraud patterns | Confirmed incident totals, unreported losses, or worldwide prevalence |
| Exposure scan, survey, or forecast | Reachable systems, respondent experience, expectations, or modeled scenarios | Finding attack surface, sentiment, preparedness gaps, and plausible future pressure | Successful compromise; a survey or forecast is not observed attack telemetry |
The comparison prevents a common error: treating an exposure count as a breach count or a provider trend as a global prevalence rate. Always keep the source population, observation window, geography, and attribution method beside the number.
| Label | Working definition | Evidence required | Common reporting error |
|---|---|---|---|
| AI-assisted | A human operator leads the activity and uses a model for one or more discrete tasks | Evidence that a model contributed to a task plus evidence of human direction | Calling any generated message or script an autonomous attack |
| AI-enabled | AI materially expands the speed, scale, reach, or capability of the malicious activity | Incident, telemetry, or provider evidence showing a meaningful operational contribution | Counting every attack in which AI appeared, regardless of material effect |
| AI-orchestrated | An agent chains multiple actions, uses tools, interprets results, and continues with intermittent supervision | Tool-call records, case reconstruction, or provider investigation showing multi-step agency | Assuming “agentic” means fully unsupervised from target selection to impact |
| Attack on an AI system | The model, data, agent, plug-in, API, vector store, or surrounding infrastructure is the target | Evidence of unauthorized access, manipulation, exposure, or service abuse | Mixing attacks against AI systems with attackers’ malicious use of AI |
These labels are a practical editorial taxonomy, not an industry reporting standard. They make the article’s comparisons explicit and keep early agentic cases separate from more common human-led use.
This page owns malicious-use and attack evidence. Our separate AI in cybersecurity statistics guide covers defensive adoption, SOC automation, and how security teams use AI.
AI can reduce the time and language skill needed to produce tailored messages, synthetic profiles, voice clones, and convincing video. Modern AI video creation has also made realistic synthetic media more accessible, reinforcing the need to verify identity through trusted channels rather than visual appearance alone. The practical risk is not that every message becomes perfect; it is that attackers can test more variants and maintain credible conversations across email, messaging, phone, and video. The practical risk is not that every message becomes perfect; it is that attackers can test more variants and maintain credible conversations across email, messaging, phone, and video.
The FBI’s complaint data specifically references fake social profiles, voice clones, identification documents, and believable videos. Organizations should treat a familiar voice or face as a presentation layer, not proof of identity. Review our social engineering attack statistics for the wider human-targeting context.
Payment and account-change workflows need a second channel that attackers cannot satisfy with the same message. A callback to a known number, dual approval, and a cooling-off rule for unusual requests are stronger than asking the sender another question in the compromised channel. Our business email compromise statistics page covers the financial-fraud pattern in more detail.
In Anthropic’s selected sample, capability development was the most common technique family: 574 of 832 accounts, or 69%. Obfuscated files or information appeared for 64.7% of actors, data from local systems for 55.9%, and impairment of defenses for 54.9%. These are observations of model misuse, not proof that the model independently completed a successful breach.
The defensive implication is to measure outcomes rather than guess authorship. Endpoint, identity, email, cloud, and network telemetry should still detect suspicious behavior whether code or content was written by a person, a model, or both. Regular penetration testing services can validate whether exposed paths produce real business impact.
Google Threat Intelligence Group reported the first threat actor it believes used an AI-developed zero-day exploit. Google said the criminal actor planned mass exploitation, while proactive discovery may have prevented the exploit’s use. That is a vendor assessment of a specific case not evidence that AI-generated zero-days are routine.
AI may compress research and development time, but exploitable exposure still depends on ordinary weaknesses: reachable services, vulnerable software, weak identity controls, excessive privileges, and slow remediation. Internet-facing applications need an owner, an inventory record, a patch target, logging, and a tested containment path. Web application penetration testing services help validate those controls against realistic abuse cases.
Agentic tools can plan subtasks, invoke tools, interpret results, and continue with limited supervision. That creates a genuine speed and scale concern, yet current evidence does not support calling most attacks autonomous. Anthropic observed AI use for lateral movement in 54 of 832 sampled malicious accounts, or 6.5%, and for privilege escalation and impact stages in 22.5%.
High-risk testing should focus on what an agent can reach and authorize: identities, secrets, tools, data stores, network destinations, and approval gates. A scoped LLM and AI penetration test should evaluate the whole application and tool chain, not just prompt behavior.
IBM found that more than one in five breached organizations in its study reported an attack targeting AI models or applications. The two most common surrounding causes were compromised APIs, applications, or plug-ins and cloud misconfigurations, each reported by 27%. This shifts security attention from the model alone to the identity, integration, application, and cloud layers around it.
Trend Micro’s 2026 AI security research identified more than 113,000 confirmed internet-exposed Ollama instances and 2,500 exposed Chroma servers in its 2025 observation window. These are exposures, not confirmed attacks, but they demonstrate why discovery, authentication, network restriction, and timely upgrades must precede production use.
Cloud configuration reviews should cover model endpoints, vector stores, object storage, service accounts, API gateways, logging, secrets, and egress. Cloud penetration testing services can test whether a configuration weakness can be chained into unauthorized access without relying on speculative model behavior.
The three cases below show different roles for AI and different levels of public evidence. They should not be added together as one incident total.
| Documented case | AI role | Reported scope | What it demonstrates | Key limitation |
|---|---|---|---|---|
| Anthropic espionage campaign, detected September 2025 | AI-orchestrated activity with periodic human decisions | Roughly 30 global targets; successful in a small number of cases | A provider-documented chain in which AI reportedly performed most campaign work | Provider-authored assessment based on visibility into its own service; limited independent public validation |
| Google suspected AI-developed zero-day, reported May 2026 | AI-assisted vulnerability and exploit development | Planned mass exploitation that Google said may have been prevented | AI may contribute to development of a previously unknown exploit | Google stated a belief about one investigated case; no confirmed mass-exploitation outcome was reported |
| FBI warning on senior-official impersonation | AI-assisted social engineering using synthetic voice and messaging | Public warning without a campaign-wide incident count | Synthetic media can strengthen identity and trust abuse across channels | The warning describes a pattern and victim risk, not a quantified breach dataset |
In September 2025, Anthropic detected activity it assessed with high confidence as a Chinese state-sponsored operation. The company said the actor attempted infiltration of roughly 30 technology, financial, chemical, and government targets and succeeded in a small number of cases.
Anthropic described the event as the first documented large-scale cyberattack executed without substantial human intervention. It estimated that AI performed 80%–90% of campaign work, with human decisions at a small number of critical points. This is a provider-authored incident assessment based on visibility into its own service; independent public validation is limited.
The case matters because it connects planning, tool use, interpretation, and repeated action. It does not prove that fully autonomous compromise is now dominant. Defenders should respond by constraining agent permissions, monitoring tool calls, isolating sensitive environments, and rehearsing the decisions that require a human stop.
Google’s May 2026 report said its team identified a criminal actor using a zero-day exploit it believes was developed with AI. The planned mass-exploitation event may not have occurred because of Google’s counter-discovery. The careful wording matters: this is evidence of AI-assisted exploit development in one investigated case, not a count of successful AI-generated zero-day attacks.
The control lesson is familiar but urgent: reduce public exposure, shorten remediation time, require strong identity controls, detect unusual process and account behavior, and maintain an emergency path for containment. Continuous penetration testing can help verify whether newly introduced exposure becomes exploitable between annual assessments.
The FBI warned that malicious actors had impersonated senior U.S. officials through text messages and AI-generated voice messages. The objective was to establish trust and move targets into another communication channel where further access or information could be requested.
This pattern is best understood as identity and process abuse. Controls should verify the request, not the media. Known-directory callbacks, approval separation, protected contact lists, and reporting channels can interrupt the attack even when the synthetic content is convincing.
IBM’s 2026 breach study reported a $6 million average cost for AI-enabled breaches, about $1 million above its $4.99 million global average. The report says those AI-enabled events consisted mainly of deepfake impersonation and AI-enabled malware. Because the study includes 602 organizations that experienced breaches, use the figure for planning and comparison not as a prediction of what any single event will cost.
The same study says 62% of reported AI-driven attacks targeted critical-infrastructure sectors. Financial-services breaches averaged $6.3 million and energy breaches averaged $5.2 million. Sector labels, reporting practices, company size, and incident mix all affect those averages, but the concentration supports prioritizing high-consequence workflows and essential services.
The cost mechanism is broader than model usage. Faster preparation and scalable impersonation increase the volume of attempts; weak identity and application controls allow access; delayed detection extends dwell time; and uncertain ownership slows containment. A security program should therefore connect AI-specific controls to established identity, cloud, application, data, and incident-response capabilities.
The table gives leaders a quick comparison of the three phases. The detailed steps that follow provide the implementation sequence.
| Phase | Primary objective | Highest-priority actions | Exit evidence |
|---|---|---|---|
| Days 0–30 | Establish ownership and remove obvious exposure | Inventory AI assets and privileged identities; assign owners; restrict public endpoints; strengthen MFA and transaction verification | Every production AI asset and privileged identity has an owner, exposure classification, and remediation date |
| Days 31–60 | Harden the surrounding system and improve telemetry | Apply least privilege; protect secrets; centralize model, tool, identity, data, and egress logs; patch critical exposure | Security operations can reconstruct who invoked the system, what it called, and which resources it reached |
| Days 61–90 | Validate controls under realistic pressure | Test impersonation workflows and AI applications; run table-top exercises; retest fixes; assign residual risk | High-consequence paths are prevented, detected, contained, or formally accepted by an accountable owner |
Exit criterion: Every production AI asset and privileged identity has an owner, exposure classification, and remediation date for critical gaps.
Exit criterion: Security operations can reconstruct who invoked an AI system, which tools it called, what sensitive resources it reached, and which controls acted.
A scoped red teaming as a service engagement can connect identity, application, cloud, and human-control failures into a realistic exercise while keeping objectives and safety boundaries explicit.
Exit criterion: The organization has evidence that its highest-consequence attack paths are prevented, detected, contained, or accepted by an accountable risk owner.
Avoid a vanity metric such as “AI attacks blocked.” Detection rules and classifications change too quickly for that total to stand alone. Track control coverage and operational outcomes instead:
Review these measures quarterly and after material model, agent, plug-in, identity, or data-flow changes. The aim is not to prove that the organization is “AI secure,” but to show that high-consequence paths are owned, observable, and tested.
There is no reliable global percentage. IBM found that one in four malicious breaches in its 2026 sample were AI-enabled, while other sources measure vendor-observed attacks, banned platform accounts, complaints, or exposed systems. Those denominators cannot be combined into one worldwide share. Quote the source, sample, time window, and definition with any percentage.
Several scoped datasets point upward. IBM reported a 56% year-over-year increase in AI-enabled malicious breaches within its study, CrowdStrike reported an 89% increase in attacks by AI-enabled adversaries in its visibility, and Anthropic’s medium-or-higher risk share rose between halves of its selected sample. These are consistent directional signals, not a universal growth rate.
It depends on the dataset. Provider observations emphasize capability development, scripting, obfuscation, and data collection. Complaint data highlights synthetic profiles, voice, video, and impersonation. Across sources, preparation and social engineering appear more common than fully autonomous, end-to-end intrusion activity.
IBM’s 2026 study reported an average of $6 million for AI-enabled breaches, roughly $1 million above the study’s $4.99 million global breach average. That is an average across a defined breached-organization sample, not a guaranteed cost for an individual company or incident.
Yes, but they are early and should be described precisely. Anthropic reported a large-scale espionage campaign in which AI performed most campaign work with occasional human decisions. Its broader 832-account study still found much lower observed use for lateral movement than for preparation, so autonomous operations are documented without being the dominant pattern in that sample.
Start with controls that remain effective regardless of who or what produced the attack: phishing-resistant MFA, independent transaction verification, least privilege, asset and exposure management, rapid patching, centralized identity and tool-call logs, tested incident response, and regular adversarial validation. Add AI-specific controls around agent permissions, plug-ins, model endpoints, vector stores, and sensitive data access.
The credible 2026 evidence does not support one sensational global AI-attack number. It supports a more useful conclusion: attackers are applying AI across preparation, impersonation, development, evasion, exploitation, and selected in-network operations, while AI applications themselves create additional targets. Organizations should classify the evidence correctly, secure the surrounding system, and test whether their highest-consequence paths can be abused at machine speed.
DeepStrike can help scope and validate an evidence-led testing program across AI applications, cloud, identity, web applications, and human workflows.
Khaled Hassan is the CEO of DeepStrike, an elite cybersecurity firm specializing in advanced penetration testing and offensive security operations. A veteran red team leader, Khaled holds prestigious industry certifications including CISSP, OSCP, and OSWE. He has successfully directed complex adversary emulation engagements for Fortune 500 companies across the finance, healthcare, and technology sectors. Throughout his career, Khaled has focused on dissecting complex attack chains and neutralizing critical cloud and application vulnerabilities to build resilient defense strategies for global enterprises.

Stay secure with DeepStrike penetration testing services. Reach out for a quote or customized technical proposal today
Contact Us