The cybercrime economy is embracing agentic AI — and that’s a problem

You are probably already suffering from AI attack headline fatigue syndrome, but please, pay attention: the agentic AI threat isn’t going away, and you need to accept that and respond accordingly.

Yes, I know the whole generative AI being used to create and largely automate phishing campaigns doesn’t represent a need for some kind of paradigm shift in defence strategy. But maybe, just maybe, the trend towards using agentic AI systems capable of executing cyberattacks from one end of the chain to the other, with very little actual human involvement, could be.

The latest Flashpoint Global Threat Intelligence Report has observed a 1,500% surge in AI-related illicit activity, with 3.3 billion compromised credentials being used to drive identity-based attacks. No surprise, then, that an increasing number of cybersecurity professionals are starting to warn that the mechanics of cybercrime are changing, with a shift from a “breaking in” mentality to a “logging in” one. And malicious agentic frameworks are behind a lot of this activity.

“In 2026, cybercrime has reached a point of total convergence,” said Flashpoint CEO Josh Lefkowitz, “where the silos that once separated malware, identity, and infrastructure have consolidated into a single, high-velocity threat engine. Agentic AI is rapidly transforming from human-led campaigns to machine-speed operations.”

This capability to use AI to orchestrate autonomous attack chains is worrying, as it “dramatically lowers the cost of experimentation,” according to the Flashpoint analysis. Not to mention the speed of exploitation.

First you have automated reconnaissance, phishing campaigns and credential testing. Next the rotation of infrastructure to avoid detection and takedown. And the speed of attacks is critical, as threat actors learn from failure, evolve and strike again. AI is helping. A lot.

Yet another worrying agentic AI security report

Another new report, this time the annual HYPR State of Passwordless Identity Assurance analysis, reveals that security professionals are noticing the switch, with both generative and agentic AI threats overtaking stolen credentials as their primary concern.

“Automated agents are on track to leak more passwords than people this year,” the report stated. Although 65% of attacks are detected within hours of execution, AI automation enables data theft before humans can respond.

“In 2026, automated agents will leak more passwords than people, shifting identity risk from human-scale errors to industrial-scale machine automation,” Bojan Simic, the HYPR CEO warned.

“We must move past point-in-time security and make identity verification a permanent part of how we manage every employee, from onboarding to offboarding.”

And, to ram the point home further, a new wave of AI-powered browser extensions has silently breached over 20,000 enterprise environments, Microsoft has said. Something that highlights how cybercrimes are adapting to AI adoption.

“As AI assistants become embedded in browsers and productivity platforms, they also create new pathways for attackers to access sensitive information,” said Shane Barney, CISO at Keeper Security.

The literal bottom line – read it!

The bottom line, not just for the type of generative AI-inspired extension attacks, but the more sophisticated and complete attack chain agentic AI-driven ones, is simple, Flashpoint’s Lefkowitz concluded:

“As attackers automate exploitation of identity, vulnerabilities, and ransomware, defenders who rely on fragmented visibility will fall behind. To keep pace, organisations must ground their decisions in primary-source intelligence that is drawn from adversarial environments, so that decision-makers can get ahead of this accelerating threat cycle.”

About The Author

Avatar photo
Davey Winder

With four decades of experience, Davey is one of the UK's most respected cybersecurity writers and a contributing editor to PC Pro magazine. He is also a senior contributor at Forbes. You can find him at TechFinitive covering all things cybersecurity.

Read more from this author.

We take journalism seriously. To learn more on why you should trust us, head to our editorial guidelines page or meet our team.