
AI is no longer the intern in cybercrime; it is the operations chief running the playbook end to end.
Story Snapshot
- Attackers are chaining AI across every stage of intrusions, shrinking time-to-hit.
- Average weekly attacks per organization hit 1,968 in 2025, up 70% since 2023.
- Convincing social engineering now scales with fewer tells and faster pivots.
- Skeptics concede AI still needs humans at key steps, but the gap is closing.
AI has moved from tool to teammate in the attacker’s kill chain
Check Point’s 2026 data shows attackers using artificial intelligence to speed reconnaissance, tailor lures, and guide decisions mid-attack. The result is more attempts, less downtime, and quicker compromises. The report logs a 70% rise in weekly attacks per organization since 2023, reaching 1,968 in 2025, and ties the surge to automation and artificial intelligence in operations. Their research arm describes faster targeting, accelerated malware building, and social engineering with fewer obvious red flags that defenses catch.
Artificial intelligence agents now stitch together actions, call tools, and trigger workflows. That makes a one-person crew feel like a small team. Check Point leaders warn this “agent class” can operate across systems once permissions and connectors exist, raising the floor for low-skill criminals. For defenders, this breaks the old rhythm. A phishing lure, a scan, and a breach no longer arrive as clear steps. They hit in parallel, so alert fatigue grows while dwell time shrinks.
Volume, speed, and camouflage are the new power trio
Attackers are using artificial intelligence to run many plays at once. They spin up lookalike domains while drafting emails tailored to job roles. They test passwords and harvest scraps from public sources, all in minutes. Check Point cites widespread exposure to risky prompts inside companies, with frequent high-risk cases, showing both sides are feeding these systems more data and intent than they realize. That data becomes fuel for sharper impersonation and smoother pretext shifts mid-call or mid-chat.
Social engineering now feels less like a hail mary and more like a chess engine. Voices, visuals, and writing styles line up so well that classic training cues fail. When a fake finance chief can talk fluidly about last quarter’s numbers and your naming style for vendors, “trust but verify” becomes “verify or pay.” Check Point emphasizes that detection signals in language and timing grow faint when artificial intelligence rewrites every sentence and rehearses the call flow.
Autonomy debate: how much human, how much machine?
Researchers at the Belfer Center found that artificial intelligence automation can underperform hand-built operations, with more errors, more noise, and greater risk of getting caught. Their experiments suggest automation can trade quality for speed, which smart defenders can exploit. Anthropic’s review of an artificial intelligence–assisted espionage run reported that humans still stepped in at several key points, indicating that full hands-off autonomy remains rare in complex campaigns. Those findings match a common-sense view: machines handle scale, humans handle judgment.
Check Point’s claims point the other way on trend lines. Their data shows that artificial intelligence now carries more stages of the attack and reduces time-to-compromise. They highlight agents that call tools and trigger actions without a person pressing send each time. Both sets of facts can be true. Today, many operations keep a human in the loop for tricky choices. But the loop is shrinking as models get better at planning, and as criminals wrap them in reliable scripts for common tasks.
What matters now for leaders: governance, not gadgets
Boards should treat artificial intelligence–driven threats as an operations risk, not only a tech risk. Mandate identity checks for money movement that no voice, video, or chat can bypass. Require dual approval for wire changes and vendor updates, even under time pressure. Move email and chat into protected modes that flag lookalike domains and role-based lure patterns. Reduce exposed machine accounts and rotate secrets faster. If the attacker runs faster, make the target surface smaller.
AI has crossed from assistant to operator, Check Point research warns: Check Point Research has published its second annual AI Security Report, documenting what it calls a decisive shift in how artificial intelligence is used in cyberattacks: AI is no… https://t.co/eqkQb5PYGP pic.twitter.com/zicmiaLs8m
— Shah Sheikh (@shah_sheikh) July 15, 2026
Security teams should adapt to speed. Shift from signature-heavy tools to behavior analytics. Hunt for chains of small actions that only artificial intelligence at scale would produce, like many near-perfect lures with micro-variations in minutes. Test internal use of artificial intelligence for prompt risk. Check Point reports a high rate of risky prompts inside companies, which means your own staff can leak context that fuels the next breach. Set safe-use rules and log it.
Bottom line: the center of gravity has moved
Artificial intelligence will not replace every human attacker this year. It has already replaced the attacker’s waiting time. The side that wins is the side that manages decisions, not headlines. The evidence shows attackers chaining artificial intelligence across the kill chain and pushing more attempts with better lures and faster moves. The counter-evidence shows humans still matter in hard calls. Plan for both truths. Cut friction for good choices. Add friction where money and keys can move.
Sources:
realcleardefense.com, checkpoint.com, sites.wp.odu.edu, cybersecurityinstitute.in



