Cyber criminals are no longer just using AI chatbots to write a better phishing email. According to Check Point Research鈥檚 newly published , artificial intelligence has moved into the driving seat of real cyberattacks; planning intrusions, writing malware and even making operational decisions with little human input.
The security firm鈥檚 second annual AI Security Report, based on incident data and original case studies gathered over the past year, argues that the industry has crossed a threshold. A year ago, Check Point described AI mainly as a 鈥渇orce multiplier鈥 that made existing hacking techniques faster and cheaper. Now, the company says, AI is directly running parts of the attack chain itself.
听
Breaches Run Largely On Autopilot
听
The report鈥檚 most striking case study concerns a breach of nine Mexican government agencies between December 2025 and February 2026, which exposed roughly 400 million records covering tax, civil registry, vehicle, patient and electoral data.
Researchers say a single attacker typed just 1,088 instructions, which an AI coding assistant turned into 5,317 executed commands across 34 sessions, using Claude Code to explore and break into networks and GPT-4.1 to analyse stolen data.
Notably, when the AI initially refused to assist with the attack, the attacker simply pasted hacking instructions into a configuration file that coding assistants automatically trust at the start of every session, permanently bypassing the safety rules without ever needing a fresh jailbreak prompt. Check Point says this trick is now being sold as a ready-made kit on criminal forums.
A similar pattern showed up in a separate case Anthropic disclosed in November 2025, in which a Chinese state-linked espionage campaign reportedly used Claude Code to handle 80鈥90% of the tactical work, reconnaissance, exploitation, credential theft and lateral movement, across roughly 30 targeted organisations.
听
Malware Built In Days Not Months
听
AI is also reshaping malware development. Check Point Research鈥檚 own investigation into 鈥淰oidLink,鈥 a sophisticated Linux command-and-control framework, initially assumed it had been built by a multi-person team over several months. It later emerged the roughly 88,000 lines of code had been written by a single developer in under a week, using a commercial AI coding tool.
Similar AI-assisted malware has now been linked to groups including Pakistan-based Transparent Tribe, Russian-linked 鈥淕REYVIBE,鈥 and North Korea鈥檚 KONNI group, the report says.
听
Criminals Are Also A Target
听
The flip side, according to the report, is that AI tools themselves have become a fresh attack surface. Because language models process instructions and untrusted content (web pages, documents, emails) as one continuous stream of text, attackers can smuggle in hidden commands, a technique known as prompt injection.
Check Point鈥檚 researchers found roughly 15,300 such hidden payloads planted across a scan of 1.2 billion URLs, with most buried in parts of a webpage a human would never see.
The report also flags weaknesses in the 鈥渁gentic supply chain鈥, the plug-ins, configuration files and MCP servers that AI coding tools trust automatically. Check Point鈥檚 own researchers discovered vulnerabilities in Claude Code that could let attackers run commands the instant a poisoned project was opened and found that roughly 1 in 13 of a sample of exposed developer configuration files contained live login credentials.
More from Cybersecurity
- Sweet Security Brings Autonomous Protection To The AI Enterprise With New Blocking Capabilities
- Hackers Could Hijack Your Car Using Bluetooth 鈥 What Happens Once They鈥檙e In?
- Fake Claude Desktop Ads Hit 29 Organisations With Data-Stealing Malware
- How AI Slop Is Forcing GitHub To Close Its Doors
- Are Home Routers Europe鈥檚 Most Dangerous Cyber Vulnerability?
- Why Are Businesses Still Paying Ransoms If Hackers Keep Demanding More?
- Can Software Developers Still Trust Their Own Vulnerability Scanners?
- What Does The New European Cyber Evaluation Plan Mean For Software Vendors?
Deepfakes And A Broken Identity System
听
Elsewhere, the report warns that voice, video and document verification can no longer be trusted as proof of identity. It cites a North Korean-linked scheme using AI-generated resumes and deepfaked identity documents to get operatives hired as remote IT workers inside Western companies, an operation the US Treasury says has funnelled close to $800 million towards weapons programmes.
In a controlled study cited in the report, even people trained to spot AI-generated faces only identified fakes about 41% of the time; ordinary viewers managed just 30%.
听
Data Leakage Climbing Steadily
听
On the corporate side, Check Point鈥檚 telemetry shows the average organisation now uses about ten different AI applications a month, and that the share of 鈥渉igh-risk鈥 prompts, those containing sensitive corporate, personal or regulated data sent to external AI tools, doubled from 2% to 4% of all prompts over the past year.
听
What Businesses Should Do
听
Fred Streefland, Check Point鈥檚 Global Field CISO, argues in the report that security leaders need to treat AI risk as a permanent, evolving part of running a business rather than a box to tick once during adoption. His recommendations include treating AI as a 鈥渓ive attacker鈥 when stress-testing defences, gaining visibility into how AI tools and agents are actually being used across the organisation, and applying real-time monitoring to catch sensitive data before it reaches external AI services.
The report lands as AI coding agents and assistants become increasingly embedded not just in software development, but, per announcements from Microsoft and Nvidia cited in the report, directly into consumer operating systems and hardware later this year, a shift Check Point says will only widen the attack surface it has been tracking.
