Sending Logs, Alerts, and Telemetry Through a Data Diode

Find Out How
We utilize artificial intelligence for site translations, and while we strive for accuracy, they may not always be 100% precise. Your understanding is appreciated.

Made to Evade: AI’s Industrialization of Cyberattacks

What security leaders need to rethink when attackers can test, adapt, and scale faster than traditional defense cycles.
By David Mitchell, VP, Products
Share this Post

Key takeaways

  • AI changed the economics of attacks. Building a campaign that once required a funded team is now within reach of a single operator.
  • Attackers can now test, adapt, and rotate tactics faster than many defense cycles are built to respond.
  • Humans are no longer the only target. The AI systems reading email on their behalf have become an attack surface of their own.
  • Defense now means layered controls that improve continuously, with AI and machine learning accelerating how fast they learn.

The threat is now relentless and at scale

Most security leaders already know AI is changing cyber risk. The harder question is what that change means operationally. Is AI making attacks smarter? Sometimes. But more importantly, it lowers the cost of experimentation, and it compresses the time between idea, payload, delivery, and iteration. That changes the economics of the attack.

It’s what we’re already observing in the market, and hearing from our customers, partners and think tanks. According to The Five Eyes, an intelligence alliance comprising the US, UK, Canada, Australia and New Zeeland, "frontier AI models are anticipated to exceed current industry expectations, fundamentally transforming both offensive and defensive cyber capabilities. The timeline is not years, it is months."

If you believe this is a distant-future concern, here are a few recent stats that indicate we’re heading fast in that direction:

  • 82.6% of phishing emails now contain AI in some form (KnowBe4).
  • AI can produce a convincing phishing email in five minutes, compared to 16 hours of human effort (IBM X-Force).
  • fully AI-automated phishing emails have a 54% click-through rate compared to 12% for traditional campaigns (independent research).
  • the average eCrime breakout time has fallen to 29 minutes, with the fastest observed case at 27 seconds. In one documented intrusion, data exfiltration began four minutes after initial access (CrowdStrike's 2026 Global Threat Report)

These statistics describe a landscape moving faster than most security governance is built to handle, and this is before frontier AI models reach wider accessibility. So, what should security leaders be looking at differently? The answer starts with understanding how AI has changed the economics of the attack itself.

Cyberattacks at industrial scale

Before AI, running an efficient campaign against one well-defended organization was a significant investment, requiring time, people and infrastructure.

Today, a capable operator can compress each phase of the attack dramatically. Reconnaissance that used to take days now can be completed in hours or minutes. Phishing lures required research and effort but now only take a prompt. Payload testing that needed a staging environment and significant iteration time has accelerated by orders of magnitude.

With AI and machine learning turbocharging the arsenal, the threat landscape became the attacker’s playground. Microsoft documented hackers rotating delivery methods monthly throughout the quarter, testing which formats bypassed email defenses most effectively:

  • HTML attachments was the most common method to deliver CAPTCHA-gated phishing (37% in January) but was dethroned by SVG files in February after a 49% spike.
  • In March, PDF attachments more than quadrupled, and DOC/DOCX payloads grew nearly five-fold.
  • QR codes embedded in PDFs became the fastest-growing vector, accounting for 70% of QR-based phishing delivery across the quarter.

A control calibrated to catch HTML in January offered very little guidance about what would arrive in March. That is not a detection failure. It is a structural consequence of defending against an attacker who can test, measure, and rotate faster than a signature can be written.

Before AI, personalization had a prohibitive cost. Now, that cost is close to zero.

Email attacks no longer target the user exclusively

The inbox used to be designed around one primary reader: the employee. That is changing. AI assistants can now summarize, classify, and act on email content at speed. So, the question becomes: are organizations inspecting content before a human reads it and before a machine processes it?

Microsoft's own benchmarking data shows Defender removes an average of 70.8% of malicious email post-delivery, meaning after it has already reached the inbox. During that dwell time:

  • A user can open an attachment, forward a message, or click a link.
  • An AI assistant can summarize the content.
  • A copilot can process embedded instructions.

In June 2025, researchers disclosed EchoLeak, a zero-click vulnerability in Microsoft 365 Copilot with a CVSS score of 9.3 out of 10 in severity. The attack worked as follows: an attacker sent a specially crafted email containing hidden instructions. When the recipient asked their Copilot to summarize their inbox, the AI read the hidden instruction, interpreted it as a command, and silently exfiltrated sensitive documents to an external server. The human used the AI assistant exactly as it was designed to be used.

This changes the threat model for email in a way that most security architectures have not yet accounted for. The AI reads without the skepticism, the contextual awareness, or the instinct that a human might have. It also reads at scale, with access to broader data, with permissions inherited from the user, and sometimes with the ability to take actions that extend well beyond reading.

There is a second dimension to this security challenge. Research into AI agent memory has documented that a crafted document processed by an AI agent can plant instructions into the agent's persistent memory, instructions that survive indefinitely and trigger silently on future interactions that have nothing to do with the original file. This is a level above prompt injection, and it’s called memory poisoning.

Organizations running AI copilots, coding assistants, and agentic workflows on top of their email infrastructure have added a second, largely unsecured layer to a surface they were already struggling to defend. Most have not adjusted their email security posture to account for it.

Adaptive defense in the shadow of AI

For years, many security programs improved in cycles: annual reviews, quarterly tuning, periodic tabletop exercises, and scheduled policy updates. That cadence still has value. But it was not designed for attacks that can morph with speed and scale.

The answer is adaptive defense: security layers that learn as the threat learns, that improve from each blocked attempt, each false positive, and each incident review. Frontier AI models, used defensively, can help compress the time between signal and action, surface patterns that human analysts cannot process at the speed required, and evolve controls closer to the pace at which attacks are changing.

That adaptation also has to account for the new reader inside the inbox. An employee can be coached toward skepticism, while an AI assistant acts on whatever it processes in the absence of guardrails. Messages and attachments have to be treated as untrusted and neutralized before any reader touches them, whether that reader is a person or a machine.

AI defense has to be practical, playing to its strengths: faster triage, earlier identification of suspicious files, better correlation across signals, and reduced time between threat and adaptation.

The organizations that will succeed are those that can treat every incident as intelligence rather than a closed ticket. Waiting for compliance frameworks to catch up is not a valid defense strategy. The attackers are already learning from every attempt, and defenders have started to do the same, using AI and machine learning to inspect, detect and sanitize emails.

For critical infrastructure specifically, there is an additional responsibility that regulation alone cannot define. As digitalization accelerates, the attack surface of these organizations grows with it. Security strategy cannot be built around regulatory minimums.

The Five Eyes joint statement puts it plainly: "Cyber risk can no longer be treated as a purely technical issue. This is a core business risk and leadership responsibility." And on the question of urgency: "Leaders who act now will reduce exposure, strengthen resilience, and build confidence with customers, partners, and investors. Those who delay will face growing and avoidable risk."

A more resilient posture starts with layered defenses at the boundary, AI-assisted adaptation in the operating model, and the expectation that continuous improvement has to become a standard practice. It's whether your defenses are evolving quickly enough to keep pace.

This matters most where the stakes are highest, in critical infrastructure and the air-gapped networks at its core, and that is where the next article begins.

This blog is part 2 of “Made to Evade” series.

Stay Up-to-Date With OPSWAT!

Sign up today to receive the latest company updates, stories, event info, and more.