NewsLayer.com
NewsLayer PulseLIVEBTC$77,796+1.28%ETH$2,400+0.33%SOL$100.55+1.61%XRP$1.37+2.91%DOGE$0.0831+2.70%ADA$0.2067+6.17%Total Cap$2.74T+0.42%Layer Index48 Neutral

AI agents carried out every step of this ransomware attack – then left the victim an 80-page security audit

A human ransomware crook used frontier AI models to breach an enterprise network in less than 10 hours, an intrusion Unit 42 says would normally take human operators around two weeks.

The Register

Publisher

Sep 2, 2026 at 6:28 PM UTC · Updated 11 小时前 · 2 分钟阅读

AI agents carried out every step of this ransomware attack – then left the victim an 80-page security audit
Image via The Register

Key Signal

<10 hours AI-assisted breach time

Last Updated

11 小时前

翻译中…

security

AI agents carried out every step of this ransomware attack – then left the victim an 80-page security audit 

Adding insult to injury

A human ransomware crook used frontier AI models to breach an enterprise network in less than 10 hours, an intrusion Unit 42 says would normally take human operators around two weeks.

The human attacker then told negotiators that they used frontier models and agentic attack frameworks with AI agents carrying out each step in the intrusion, including leaving an 80-page security audit for the victim company.

“What made the attack stand out was AI-assisted operational efficiency, without the need for a novel zero-day or super elite tradecraft,” Unit 42 incident responders said in a Wednesday report. “The attacker left tactical execution to AI agents that monitored, evaluated, acted and re-planned in real time, increasing speed throughout the attack chain.”

The security shop did not immediately answer The Register’s questions about the intrusion, including which models and frameworks the attacker used.

Breaking down the attack

In a first step, the human attacker employed AI agents to perform reconnaissance, then gained access by breaching a public API endpoint to tunnel into the enterprise network.