Cybercriminals deploy automated AI agents to execute complex hacking attacks in under ten hours, bypassing traditional security setups.
Cybersecurity researchers have issued an urgent warning after discovering that digital criminals are now using fully automated artificial intelligence agents to carry out complex, real world network attacks.
In past years, high level computer hacks required skilled human hackers to manually scan target servers, look for weak software entry points, write custom code, and steal private passwords over several days or weeks.
However, modern cybercriminals are now handing these complex tasks over to smart computer programs that can plan, execute, and adjust their own hacking steps automatically.
By assigning specialized artificial intelligence software to handle different stages of an intrusion, bad actors are compressing traditional multi week cyberattacks into less than ten hours.
The alarming incident report was officially published by Palo Alto Networks’ security research team, Unit 42, on Thursday, September 3, 2026.
Security investigators detailed how a ransomware group deployed an interconnected network of autonomous artificial intelligence agents to breach a target enterprise.
Once the human operator gave the initial command, the automated programs worked together in real time to map internal company servers, scrape secret software passwords, hijack cloud management tools, and steal master administrative credentials.
To mock the victim company after completing the breach, the attacker used a specialized documentation agent to auto-generate and leave behind an 80 page security report listing all exploited vulnerabilities.
The main reason cybercriminals are turning to artificial intelligence agents is that these smart tools can test thousands of potential security flaws simultaneously at machine speed.
Human defenders relying on manual checks simply cannot react fast enough when automated programs are searching for open computer doors around the clock.
By utilizing automated agents that adjust their tactics automatically when blocked, attackers can breach corporate file networks, hide inside normal traffic patterns, and offload their processing costs directly onto the victim’s cloud computing infrastructure.
Explaining how bad actors left the tactical execution of the complex network intrusion entirely to smart computer software, cybersecurity researchers at Unit 42 reported that “the attacker left tactical execution to AI agents that monitored, evaluated, acted, and re-planned in real time, increasing speed throughout the attack chain”.
See Also: Hackers Use Fake Image Free QR Codes Made of Code Tables to Trap Phone Users
Detailing how autonomous software tools compressed complex hacking methods into a fraction of the usual timeframe, Unit 42 security analysts added that the threat actor “compressed weeks of methodical intrusion tradecraft” into less than ten hours.
Warning that corporate security teams must adopt automated defense tools to match the speed of modern artificial intelligence threats, Unit 42 security experts emphasized that “defenders need automated responses that can revoke access and isolate cloud accounts quickly”.
By exposing how cybercriminals deploy artificial intelligence agents to automate network breaches, cybersecurity experts are helping businesses strengthen their digital walls.
Updating software patches quickly, revoking unused system permissions, and using automated security tools ensures that company databases, private employee files, and cloud networks remain safe from high-speed digital thieves.

