AI-Run Cyberattacks Have Moved From the Lab to Real Companies

For the past two years, autonomous AI attacks were mostly a research topic. September 2026 changed that. Within a few days of each other, Microsoft and Cisco Talos published detailed reports on attacks in which AI systems, rather than human operators, appear to drive the step-by-step decisions. Then on 1 October, Microsoft's annual Digital Defense Report said its threat intelligence teams had seen AI move from assisting human attackers towards directing attacks. Taken together, these reports mark the point where AI-orchestrated intrusion stopped being hypothetical for ordinary businesses.
A seven-minute wipe in the cloud. On 25 September, Microsoft Security Research described activity by a group it tracks as Storm-3168. Microsoft links it to JADEPUFFER, the operation that cloud security firm Sysdig reported in July as the first documented agentic ransomware campaign. In one affected Azure environment in early June, the attacker used two compromised service principals, the non-human identities that applications use to reach cloud resources. One spent about 15 and a half hours mapping the environment with more than 300 successful read operations. The other then ran a destructive sequence lasting about seven minutes, including more than 100 storage account deletion attempts, and deleted a Key Vault, a Function App and an App Service plan. Microsoft says the credentials had been exposed in a public GitHub issue and remained reachable through the edit history after the original disclosure was removed.
What limited the damage. Microsoft notes that Azure resource locks and storage-level deletion protection blocked the deletion of a few storage accounts, even though the attacker held broad administrative rights. Attempts to delete SQL databases failed only because the attacker used an unsupported API version. These are small details, but they show that independent safeguards set up in advance still work when an attacker moves faster than any human team can respond. Microsoft describes the activity as part of a broader shift towards AI-orchestrated attacks that coordinate complex operations across cloud environments with greater speed and scale.

Leaked credentials for non-human identities, such as service accounts and API keys, were the way in for the Azure attack Microsoft described.
Malware that asks a committee of chatbots. On 22 September, Cisco Talos described CLOSEDQUORUM, a Windows implant that hands its tactical decisions to commercial large language models. According to Talos, the malware sends information about the infected machine to up to four AI model providers, has each vote on the next step from a fixed menu of actions such as stealing credentials, persisting or moving, and runs the winning choice on a randomised cycle of five to fifteen minutes without a human issuing commands. Talos is careful about the limits of what it knows: the sample it analysed contained placeholder API keys, and use against real victims has not been confirmed. It looks more like a template that criminals can customise than a finished campaign.
The wider picture. Microsoft's 2026 report puts numbers on the pressure. It says the median time from a vulnerability becoming known to being weaponised has fallen well below 24 hours, while many enterprises still take 30 to 60 days to fix critical internet-facing flaws. Nearly 40,000 vulnerabilities were published in the first half of 2026 alone. Microsoft also reports that in one controlled evaluation, a frontier AI system strung together 32 stages of an attack. None of this means every attack is now run by AI. It does mean the gap between a flaw being disclosed and being exploited is shrinking faster than most patch cycles.
Why mid-sized companies are exposed. The entry points in these cases are not exotic. Storm-3168 got in with leaked cloud credentials. JADEPUFFER's original campaign, according to Sysdig, came in through a known vulnerability in Langflow, an open-source tool for building AI applications, that had already been patched in 2025. CLOSEDQUORUM goes after stored passwords and cryptocurrency wallets. AI does not invent new doors. It walks through existing ones faster, more persistently and at lower cost to the attacker. Mid-sized firms with fast-growing cloud estates, many service accounts and AI tooling set up quickly by small teams are exactly the environments where an old secret or an unpatched internal tool can sit unnoticed.

Independent safeguards such as deletion locks and protected backups held up even when the attacker had broad administrative access.
What to do now. Treat non-human identities with the same care as staff accounts: keep an inventory of every service principal, API key and agent credential, give each only the access it needs, and rotate anything that has ever been exposed, because deleting the post does not revoke the key. Put deletion locks and immutable backups on production storage and recovery resources, so that one compromised admin identity cannot erase everything. Shorten patch times for internet-facing systems and for AI development tools, and alert on unusual patterns such as bursts of deletions or a single machine calling several AI services. Finally, rehearse the seven-minute scenario. If your team would only find out the next morning, parts of the response need to be automated too.
Kavya Chaudhary
Technology writer and researcher with expertise in emerging technologies, digital transformation, and business strategy. Passionate about breaking down complex concepts for readers.