AI ‘Machine Speed’ Cuts 2-Week Attack Down to 10 Hours

**AI-Driven Ransomware Attack Cuts Breach Timeline from Weeks to Hours**

A recent high-profile attack on an enterprise network has left security experts sounding the alarm about the alarming speed at which attackers can now orchestrate large-scale breaches. Using artificial intelligence (AI) agents, a human attacker was able to breach the network in under 10 hours, significantly reducing the typical two-week time span of similar attacks.

The incident, investigated by researchers from Palo Alto Networks’ Unit 42, saw an attacker use frontier AI agents to blast through security layers and compromise sensitive assets. The attack began with the threat actor breaching a public API endpoint to tunnel into the network and deploy an automated reconnaissance agent. From there, sub-agents combed enterprise code repositories to extract hard-coded tokens and service passwords, which were then used to infiltrate the secrets management system and obtain master administrative credentials.

The attackers’ use of AI agents allowed them to work in a coordinated manner, each targeting different layers of defense to achieve their goal. This level of automation not only increased speed but also made it more difficult for human security teams to detect and respond to the attack. As Rickard Carlsson, CEO of AI security firm Detectify, notes, “The shift here is orchestration. What Unit 42 is describing is a set of specialized agents working in parallel, sharing findings and adapting, while a human sets the objectives and makes the consequential calls.”

This level of sophistication has significant implications for organizations, which must now contend with the possibility of AI-driven attacks on their networks. Such attacks are becoming increasingly common, but what’s particularly concerning here is the operational efficiency achieved by the attacker using AI agents without the need for novel zero-day exploits or elite tradecraft.

In this attack, the use of LLM calls to multiple frontier AI agents, structured markdown files passed between agents and sessions, and custom scripts that were AI-generated to manage dynamic operations all contributed to the attackers’ success. The fact that the attacker was able to leave behind a detailed 80-page technical audit on the organization’s security posture only serves as further testament to their expertise.

The takeaway from this incident is clear: organizations must be prepared for the possibility of AI-driven attacks and have measures in place to detect and respond quickly. This includes implementing robust security controls, conducting regular penetration testing, and staying up-to-date with the latest threat intelligence. By doing so, they can reduce the risk of falling victim to such a coordinated and devastating attack.


Source: Dark Reading — 2026-09-03