
In the first half of 2026, 85.3% of incurred losses in the Resilience portfolio came from phishing, social engineering, and transfer fraud, up from 17.7% two years earlier, according to our H1 2026 Cyber Risk Report. Those losses started with someone believing a voice, a message, or a request that looked legitimate. No H1 2026 losses traced to an AI-specific attack vector like prompt injection or agentic misuse, but AI is making identity-based attacks like these cheaper to run and harder to spot.
For our September Risk Briefing, I sat down with Steph Barnes, a senior cyber threat intelligence analyst on our team, and Max Henderson, who leads global digital forensics and incident response at Kroll. Steph watches threats before they turn into cases, and Max’s team is usually called in once they have.
Attackers log in with stolen credentials
According to CrowdStrike’s 2026 Global Threat Report, 82% of the detections it recorded in 2025 were malware-free. That matches what our threat intelligence team sees, Steph said, which is why the team tracks access-for-sale listings and infostealer logs. “Once they have the credentials, they don’t have to worry about being as stealthy, because it looks like that person is doing their job,” she said.
Mandiant’s M-Trends 2026 report shows attackers taking more of those credentials over the phone, with voice phishing at 11% of intrusions, second only to exploits as a way in. Attackers now run their lures through the same chatbots everyone else uses, which is why Steph wants the old training advice retired. “You can’t say things like ‘just look for misspellings’ anymore,” she said.
An AI-driven intrusion is fast and loud
Max has worked agentic intrusions, where an attacker hands an AI a goal and lets it run, and they look nothing like a nation-state operator’s light-touch reconnaissance spread over weeks. “When you have an AI attack, it’s a relentless sprint. It doesn’t sleep, it doesn’t think, it just does,” he said. The agent grabs every computer and account name it can find, until it knows the environment better than the people who built it.
In one agentic intrusion Max’s team worked, the agent got in through a vulnerability that had been known for years, and the application it landed on ran under an admin-level identity, so it controlled the environment almost immediately. Foundational cybersecurity actions matter more than ever. Max doubts the AI would have gotten in at all if those two basics had been fixed. “If you’re saying that AI has to create a zero-day to hack me, you’re in a pretty good position,” he said.
Once inside, the agent made a lot of noise. It set up virtual machines labeled by purpose, one for reconnaissance and one for stealing credentials, and kept running logs of every account it tried and whether each attempt worked. That’s how Max’s team knew the attack was automated, since human intruders don’t write up their own work as they go. “Nobody’s writing that out,” he said. The noise also gives defenders an opening, because controls that slow the agent down, even for a few minutes, give your alerts time to fire before it finishes.
Attackers are turning AI on your data and your own AI tools
Max described cases where an attacker who got into a mailbox opened the company’s AI assistant and asked it to find invoices and wiring details. The same CrowdStrike report counted more than 90 organizations where adversaries exploited legitimate AI tools to generate malicious commands and steal data. In 2023, a car dealership’s website chatbot [agreed to sell a new SUV for $1](LINK TBD) and called it a legally binding offer, after a user told it to agree with anything the customer said. The dealership pulled the bot, but the screenshot went everywhere.
Max pointed to Clop’s 2023 MOVEit Transfer campaign as the classic smash-and-grab, in which the group used a previously unknown flaw in the file transfer product to steal data from internet-facing servers, according to a joint CISA and FBI advisory. According to Resilience claims data, vendor-driven incidents accounted for 61% of higher education claims in our portfolio in 2023, the highest share in that dataset, and the MOVEit campaign drove that spike [VERIFY: scope of MOVEit confirmation]. It’s the same shared-dependency pattern I wrote about after this summer’s water utility attacks, where attackers scanned for a controller model many utilities shared instead of picking targets one by one.
After smash-and-grab thefts like that, victims used to tell Max that if the attackers only knew what they’d taken, they’d ask for more. Now attackers run AI over the stolen data to find whatever will raise the ransom.
Max has seen attackers break into companies that resell AI services just to take access tokens, then spend that stolen capacity on their next attack. Sysdig’s threat research team coined the name LLMjacking for this kind of theft in 2024, and in a June 2026 report it documented an attacker using an exposed, unauthenticated model server as the reasoning engine for an automated hacking tool. The tool was still being built and tested against a private practice range, so read it as a preview. Still, every AI endpoint and API key you run belongs on the same inventory as your service accounts.
AI agents need their own identity
An AI agent that acts on a user’s behalf should carry its own identity and its own audit trail, Steph argued. “When something goes wrong, you want to know if it went wrong because the human messed up, or if it went wrong because the AI did something that it wasn’t supposed to do,” she said.
An agent should only reach systems its human can already reach, and in practice you narrow that further with just-in-time access, granting this agent these resources for this task and this window, with the grant expiring when the task does. Our CISO, Chris Wheeler, has written about the fields every agent action should log when you govern GenAI risk.
Every vendor connection is an identity
Max counts API keys, tokens, secrets, and service accounts as identity, and he keeps finding them overprivileged across vendor integrations. On the Resilience side, we still see partners reach a client’s environment through one login for the whole company, so nobody can tell whether one person is behind it or five, or who’s accountable when something breaks. Ask how each of those people gets in.
Right now, Max said, he sees companies lose the most time after the incident, when third parties require an attestation that you’re safe to reconnect, and that can take seven to 10 days. He recommends mapping which partners you’d need to reassure, in what order, with legal counsel directing the process, and doing the same for customers downstream of you.
Patch the perimeter first and keep investing in identity
Steph would patch what’s reachable from the internet first, like VPNs and firewalls, and let internal systems that are harder to get to wait a couple of weeks.
Max would fund both, because the most active groups his team sees are working voice and email phishing and getting past text-message and app-approval multifactor authentication (MFA), and they’ll scale just as fast on a good zero-day when one lands. He’d weigh it by geography, though. In Max’s US casework, attackers lean heavily toward stealing data, while Canada and Europe run closer to an even split between data theft and encryption, so he’d put a US organization’s first dollar into access controls for SaaS and cloud.
The controls that stop these incidents are old advice, and AI has taken away the slack you used to have for getting them in place. So if you pick one project this quarter, list every credential that doesn’t belong to a person, including AI agents and vendor accounts, and give each one a named owner and its own log.
Frequently asked questions
What is an identity-based attack?
An identity-based attack uses a stolen or tricked credential to get in, so the attacker moves through an environment looking like a legitimate user. According to CrowdStrike’s 2026 Global Threat Report, 82% of the detections it recorded in 2025 were malware-free.
Are AI attacks causing real losses yet?
Not in Resilience’s claims data. No incurred losses in the Resilience portfolio traced to an AI-specific attack vector in the first half of 2026, according to the H1 2026 Cyber Risk Report. AI is making the phishing, social engineering, and transfer fraud behind 85.3% of those losses cheaper to run and harder to spot.
How can you tell if an attack is AI-driven?
AI-driven intrusions tend to be fast and noisy. Incident responders have seen agents set up virtual machines labeled by purpose and keep running logs of every account they tried and whether each attempt worked, which human intruders rarely do. That noise gives defenders an opening, because controls that slow the agent down, even for a few minutes, give alerts time to fire.
How are attackers using AI tools?
Attackers are exploiting the AI tools companies already run and stealing access to AI models for their own use. CrowdStrike’s 2026 Global Threat Report found adversaries exploiting legitimate AI tools at more than 90 organizations to generate malicious commands and steal data. Attackers also run AI over stolen data to find whatever will raise a ransom demand.
What is LLMjacking?
LLMjacking is the theft of access to AI models, usually through stolen API keys or exposed model servers, so attackers can use that capacity themselves. Sysdig’s threat research team named it in 2024, and in its June 2026 report, “LLMjacking evolved,” it documented an attacker using an exposed model server to power an automated hacking tool that was still in development.
Should AI agents have their own credentials?
Yes. An AI agent acting for a user needs its own identity and audit trail, so you can tell whether a person or the AI took an action. Keep its access within what its human can reach, and narrow that with just-in-time access for each task.
Why does vendor access cause so much downtime after an attack?
Much of the downtime comes after the incident, when third parties require an attestation that you’re safe to reconnect, and that can take seven to 10 days. Map which partners you’d need to reassure, and in what order, with legal counsel directing the process, and give each person on the vendor’s side their own named account instead of one shared login.
The full briefing recording is available here, and our October session covers the biggest mistakes and successes we saw this year.
Nothing here should be taken as legal, financial, or security advice for your specific situation — see the full disclaimer at cyberresilience.com/disclaimer.



