Skip to content
IdentitéTrust starts here
English
EnglishEspañolPortuguês
Contact

AI-Powered Cyberattacks Are Here: Why Identity Security Must Evolve as Fast as the Attackers

Eusebio CoterilloEusebio Coterillo ·
Editorial illustration for AI-Powered Cyberattacks Are Here: Why Identity Security Must Evolve as Fast as the Attackers.

For years, much of the cybersecurity discussion around artificial intelligence focused on what attackers might eventually do with AI.

That conversation is changing.

Attackers are already using generative AI inside real-world intrusions—not simply to write phishing emails or generate malicious code, but to perform reconnaissance, troubleshoot failed commands, harvest credentials, navigate unfamiliar networks, identify valuable systems, and decide what to attack next. A recent eSecurity Planet report, drawing on research from Gambit Security, documents three separate threat actors using AI across different stages of active cyber operations.

That distinction matters.

AI is no longer merely helping criminals create better content.

It is beginning to help them make better decisions.

And that should change how enterprises think about identity, authentication, access control, segmentation, and incident response.

AI Is Becoming an Attack Assistant

One of the most important conclusions from the eSecurity Planet article is that AI is functioning as an operational force multiplier for attackers.

The technology isn't necessarily inventing completely new cyberattack techniques. Instead, it is helping criminals execute familiar techniques faster, troubleshoot problems more effectively, understand environments they have never seen before, and identify the systems that matter most.

That's potentially more consequential than another AI-generated phishing email.

A skilled attacker traditionally needed considerable knowledge and experience to enter an unfamiliar network and determine:

Now an AI assistant can help answer some of those questions.

The result is not necessarily a new attack.

It is a faster, more capable attacker.

The Gentlemen Case: AI Helps an Attacker Understand the Victim

The first case discussed by eSecurity Planet involved a suspected affiliate of The Gentlemen ransomware-as-a-service operation.

Researchers observed the attacker using Claude Code during intrusions affecting multiple organizations across different industries and countries. The AI assisted with reconnaissance, exploitation commands, scripting, firewall modifications, system analysis, and lateral movement.

Perhaps the most revealing part of the research was what happened once the attacker entered an environment they did not initially understand.

The attacker used AI to analyze network-enumeration output, determine where stolen credentials provided administrative access, and identify potentially valuable systems such as domain controllers, file servers, databases, and backup infrastructure.

According to the researchers quoted by eSecurity Planet, the attacker even asked the AI which databases mattered most, and the model helped identify those the victim organization could least afford to lose.

That should get the attention of every CISO.

An attacker no longer needs to understand your business before entering your network.

AI can potentially help them learn it after they arrive.

Why Stolen Identity Becomes Even More Dangerous

This is where AI-powered attacks intersect directly with identity security.

The Gentlemen affiliate reportedly obtained domain credentials and VPN access before using AI to assist with reconnaissance and lateral movement.

Think about what that means strategically.

Once an attacker acquires a legitimate identity, AI can help determine:

A compromised credential was already dangerous.

An AI-assisted attacker can potentially make that stolen identity more valuable because they can exploit its privileges more efficiently.

The identity itself becomes the launching point.

Zerofot: AI-Assisted Credential Theft at Scale

Editorial concept illustrating AI-Powered Cyberattacks Are Here: Why Identity Security Must Evolve as Fast as the Attackers

The second case in the report is even more directly connected to identity.

A threat actor known as Zerofot reportedly used OpenAI Codex and Claude Code to develop and operate a scanner and credential-harvesting tool that searched exposed systems for sensitive files and configuration information.

Between April and May 2026, the operation collected 2,975 validated credentials and keys from 1,742 victim hosts, according to the article. Those included SSH private keys, AWS access keys, Google Gemini keys, OpenAI keys, GitHub tokens, and Anthropic credentials.

That number is important.

But what's more important is what those credentials represent.

A stolen AWS key isn't merely a string of characters.

It's an identity.

A GitHub token represents authorization.

An SSH private key may provide trusted access.

An AI API key may provide access to models, information, or expensive infrastructure.

In modern enterprise environments, credentials are access paths.

And AI can increasingly help attackers discover, validate, organize, and exploit those paths at scale.

AI Is Also Running the Attacker's Infrastructure

Another interesting element of the Zerofot operation is that AI apparently wasn't limited to writing malicious code.

Claude Code was reportedly used to assist with operational and DevOps-type tasks including proxy management, network routing, firewall configuration, infrastructure management, and troubleshooting.

That suggests AI can lower barriers beyond hacking expertise.

Attackers traditionally needed skills across multiple disciplines:

AI can potentially provide assistance across many of them.

That's a meaningful change.

Cybercriminal operations can become more scalable even when the human operator doesn't possess world-class expertise in every technical discipline.

RAGE: AI Moves Inside the Attack Framework

Archipelago visual connecting RAGE: AI Moves Inside the Attack Framework, The Real Change Is Speed, Passwords Become an Even Bigger Liability in an AI-Assisted At, Passwordless Authentication Removes One Valuable Attack Target

The third case described by eSecurity Planet involves RAGE, a custom Python exploitation framework.

Researchers found evidence that AI-generated code was used in its development, and the framework reportedly incorporated a DeepSeek-backed AI Orchestrator directly into the attack platform itself.

The framework targeted internet-facing technologies including Redis, Elasticsearch, Docker, Tomcat, Jenkins, Hadoop YARN, Confluence, and others, and was designed for vulnerability exploitation, credential harvesting, and cryptocurrency-mining deployment.

This represents another step in the evolution.

AI isn't simply a separate chatbot sitting beside an attacker.

It can become part of the attack tooling itself.

That makes AI-assisted cybercrime less like:

"Ask AI to write me a script."

and increasingly like:

"Embed AI into the attack workflow."

The Real Change Is Speed

This may be the most important conclusion in the entire article.

eSecurity Planet argues that the larger shift is the compression of attacker workflows. AI can help interpret unfamiliar environments, troubleshoot problems, prioritize high-value targets, and maintain infrastructure—tasks that traditionally required more time and expertise.

Cybersecurity teams often think in terms of attacker dwell time.

AI could shorten those windows.

And if attackers are moving faster, enterprise security cannot depend on the assumption:

"We'll catch them after they get inside."

The better strategy is to make the initial identity compromise significantly harder—and limit what any compromised identity can accomplish afterward.

Passwords Become an Even Bigger Liability in an AI-Assisted Attack Environment

Passwords were already vulnerable before attackers began using AI operationally.

They can be phished, stolen, reused, exposed in breaches, captured by malware, or harvested from improperly secured systems.

AI doesn't make those vulnerabilities disappear.

It makes exploiting them potentially faster and more scalable.

An attacker who obtains one employee's credentials can potentially use AI to help determine where that identity provides access and what systems are worth targeting.

That's why organizations should reconsider an authentication architecture centered around reusable passwords.

The question shouldn't simply be:

"How strong is our password policy?"

It should be:

"Why are we continuing to rely on credentials that attackers can steal and reuse?"

Passwordless Authentication Removes One Valuable Attack Target

Petals visual connecting Passwordless Authentication Removes One Valuable Attack Target, But Identity Security Cannot Stop at the User, Full Duplex Authentication®: Both Parties Must Establish Trust, Authentication Intent Becomes More Important Too

Passwordless authentication changes that part of the equation.

Instead of asking the employee to enter a reusable password, authentication can involve a trusted device combined with an approved biometric or other authentication mechanism.

For the attacker, that removes something extremely valuable:

The reusable password.

A conventional phishing page cannot collect a password that the user never has to type.

A credential database cannot expose an everyday password that no longer serves as the foundation of authentication.

Passwordless authentication doesn't eliminate every cybersecurity threat.

But removing reusable password dependency can eliminate a large category of identity attack opportunities.

But Identity Security Cannot Stop at the User

AI-powered attackers aren't only getting better at exploiting people.

They can also help attackers create more convincing digital impersonation.

So authentication should no longer revolve exclusively around one question:

"Is this the legitimate user?"

Organizations also need to address:

"Is this the legitimate destination?"

That's where Identité's patented Full Duplex Authentication® changes the trust model.

Full Duplex Authentication®: Both Parties Must Establish Trust

Traditional authentication primarily requires the user to authenticate to the service.

Full Duplex Authentication® establishes mutual authentication.

The user must establish legitimacy.

The legitimate application or website must establish legitimacy as well.

That's increasingly important because an AI-assisted attacker may create an extremely convincing imitation of a legitimate destination.

The logo may be perfect.

The colors may be perfect.

The language may be perfect.

The domain may appear legitimate at first glance.

But appearance is not identity.

A fraudulent destination cannot simply copy its way through the legitimate application's side of Full Duplex Authentication®.

In an era where AI can dramatically improve digital impersonation, that's a meaningful distinction.

Authentication Intent Becomes More Important Too

Article-specific explanatory visual for Authentication Intent Becomes More Important Too

AI-assisted social engineering also makes simple approval-based MFA increasingly problematic.

An attacker with stolen credentials might attempt repeated push notifications or coordinate the request with a convincing social-engineering message.

That's why Identité's authentication experience can go beyond an unexplained:

Approve / Deny

prompt.

The user can be explicitly asked:

"Did you request this authentication session?"

On the same authentication screen, Identité can also display an image and three-digit number associated with the authentication interaction.

That moves the security decision from simple approval toward confirmation of intent.

The difference matters.

An attacker wants the user to think:

"Tap Approve."

A better authentication process encourages:

"Did I actually initiate this?"

The Five Trust Questions AI-Era Authentication Should Answer

Modern enterprise authentication increasingly needs to answer five interconnected questions:

That final question ties authentication back to the recommendations in the eSecurity Planet article.

The report specifically recommends MFA, least privilege, credential protection and rotation, network segmentation, monitoring of suspicious identity activity, reduction of internet-facing exposure, and tested incident-response procedures.

AI-powered attacks aren't solved by one product.

They require layered security.

But identity sits at the center of many of those layers.

Least Privilege Becomes More Important When AI Helps Attackers Navigate

If AI can help attackers identify high-value systems after compromising an identity, then excessive privilege becomes even more dangerous.

A user should only have access to what they actually need.

An administrator shouldn't automatically have unrestricted access everywhere.

Machine identities and service accounts deserve the same scrutiny.

Because once an attacker gets access, we should assume they will increasingly have tools capable of helping them understand how to exploit it.

AI amplifies the consequences of excessive privilege.

Monitor Identity Activity—Not Just Malware

Editorial scene illustrating Monitor Identity Activity—Not Just Malware

The eSecurity Planet article recommends monitoring suspicious identity and credential activity, including unusual access-key creation, role assumption, secrets retrieval, privilege escalation, and abnormal authentication attempts.

That's exactly the right direction.

Modern attacks may use legitimate credentials.

There may be no obvious malware event during the initial access.

Instead, security teams need to recognize:

Decentralized Biometrics Can Protect Identity Without Creating Another Centralized Prize

Biometrics can strengthen passwordless authentication, but organizations should carefully evaluate where biometric information resides.

Identité uses a decentralized architecture in which biometric verification occurs on the user's trusted device.

The biometric does not need to be sent to Identité or stored in a centralized Identité biometric repository for matching.

The user's biometric data stays on the user's device.

That's important in an AI-driven threat environment because attackers are becoming better at finding valuable concentrations of information.

Why create another centralized repository of sensitive identity data if authentication doesn't require one?

PasswordFree®: SaaS Authentication for the AI Era

Ribbon visual connecting PasswordFree®: SaaS Authentication for the AI Era, NoPass™: Enterprise Authentication With Greater Control, AI Security Isn't Just About Protecting AI, The Identité Perspective

Identité's PasswordFree® is our SaaS passwordless authentication solution.

It is designed around capabilities including passwordless authentication, patented Full Duplex Authentication®, mutual authentication, trusted-device authentication, decentralized biometric verification, authentication intent, contextual verification, Emergency PIN Authentication, Secure Backup & Restore, and compatible third-party authentication options.

The objective is not simply to replace a password.

It's to make stolen identity substantially harder for an attacker to acquire and reuse.

NoPass™: Enterprise Authentication With Greater Control

For enterprises requiring deeper integration and infrastructure control, Identité offers NoPass™, our PaaS solution powered by patented Full Duplex Authentication®.

NoPass™ can be deployed on premises or in the cloud and supports enterprise environments involving Microsoft Active Directory, Microsoft Entra ID, Microsoft 365 / Office 365, and Microsoft Azure.

This deployment flexibility can be especially important for financial institutions, healthcare organizations, government agencies, and other enterprises that want greater control over authentication infrastructure and sensitive information.

For organizations such as banks that prefer not to place client or authentication information in public cloud environments, NoPass™ can be deployed on premises.

AI Security Isn't Just About Protecting AI

There's another important lesson here.

When people hear AI security, they often think:

How do we secure the AI model?

That's important.

But AI-powered cyberattacks reveal a different side of the equation:

How do we protect everything else from attackers using AI?

AI isn't only creating a new asset category to defend.

It's giving attackers better tools for attacking the assets we already have.

The Identité Perspective

The most concerning part of the eSecurity Planet article isn't that AI can generate malicious code.

We've known that possibility for some time.

The more consequential development is that AI is beginning to operate inside the attack lifecycle.

Organizations therefore need to make identity compromise harder at the beginning and limit attacker options afterward.

With Identité, the biometric can help establish:

"I am the authorized user."

The trusted device participates in establishing:

"This is the authorized device."

Contextual authentication asks:

"Did I initiate this authentication session?"

The image and three-digit number provide additional context.

And patented Full Duplex Authentication® addresses:

"Is this the legitimate destination?"

Combine that with least privilege, segmentation, credential protection, behavioral monitoring, Zero Trust, and tested incident response, and organizations can create multiple barriers between an attacker and the systems that matter most.

AI isn't necessarily inventing an entirely new cyberattack.

It's making the attacker faster, more adaptable, and potentially more effective.

Cybersecurity needs to respond accordingly.

Because when attackers can use AI to determine the fastest path to what matters most, enterprises cannot afford to make identity the easiest path in.