AI-Assisted Cyber Attacks Are Lowering the Technical Barrier for Hackers
AI is helping cyber threat actors perform tasks that once required significant expertise, including reconnaissance, tool development, exploitation support, and stolen-data analysis. AI use across all 14 MITRE ATT&CK tactics, suggesting businesses may face attacks that are faster, more scalable, and less dependent on highly skilled operators.
Unlike earlier discussions that focused mainly on AI-generated phishing or fake content, evidence published in 2026 suggests AI is moving deeper into the operational workflows of attackers. AI does not necessarily create entirely new attack techniques. Its greater value to threat actors lies in reducing research time, automating repetitive tasks, adapting to specific environments, and connecting multiple stages of an intrusion into a more continuous workflow.
For businesses, the most important change is not simply an increase in attack volume. Capabilities that once required experienced specialists and larger teams are becoming more accessible to smaller and less sophisticated threat actors.

How is AI changing the way hackers operate?
AI is reducing the amount of time, labor, and specialized knowledge required to execute certain cyber operations. In its September 2026 threat intelligence report, Anthropic said the gap in tooling and expertise that traditionally separated advanced campaigns from lower-resourced operators is narrowing.
Anthropic previously analyzed 832 accounts suspended for malicious cyber activity between March 2025 and March 2026. The identified activity involved AI across all 14 MITRE ATT&CK tactics and 482 sub-techniques, ranging from early-stage information gathering to actions carried out after initial compromise.
Notably, the percentage of actors Anthropic assessed as posing a medium-or-higher level of risk increased from 33% during the first half of the research period to 56% during the second half. These figures do not represent all global cybercrime, but they indicate that within Anthropic’s observed dataset, AI was increasingly involved in more sophisticated malicious activity.
AI-enabled change | Impact on attack operations |
Faster reconnaissance | Attackers can summarize information about targets and technologies more quickly |
Tool and code assistance | Reduces the need to build every script or tool from scratch |
Environment analysis | Helps interpret configurations, accounts, services, and data inside compromised systems |
Multi-stage automation | Can connect reconnaissance, exploitation, and data processing into a workflow |
Adaptive execution | Supports changes to tools or approaches in response to detection or failure |
Why do sophisticated attacks no longer always indicate highly skilled hackers?
For years, the complexity of an intrusion was often treated as an indicator of the threat actor’s technical capability. AI is making that assumption less reliable.
Publicly available offensive AI frameworks may further lower the barrier to entry. Anthropic highlighted frameworks such as PentAGI, which can provide the scaffolding needed to automate multiple stages of the cyber kill chain. As these tools become easier to access, an operator may no longer need deep expertise in every technical stage of an attack.
This does not mean human expertise is becoming irrelevant. Target selection, initial access decisions, broader strategy, and assessment of results still commonly involve human control. However, AI can compensate for knowledge gaps and allow one operator to manage more targets simultaneously.
Which attack techniques can AI amplify the most?
AI currently provides the greatest operational value in tasks that are repetitive, data-intensive, or require rapid adaptation to a target environment.
Key areas include:
Reconnaissance: collecting and summarizing information about organizations, employees, infrastructure, and exposed services.
Social Engineering: generating emails, messages, call scripts, or impersonation content tailored to specific targets.
Tool Development: assisting with the creation, modification, and debugging of scripts or offensive tools.
Exploitation Support: analyzing software flaws, configurations, and potential exploitation conditions.
Post-exploitation: reviewing accounts, permissions, data stores, and system relationships after compromise.
Data Processing: sorting large volumes of stolen information to identify valuable or sensitive content.
Phishing remains especially significant. ENISA said phishing accounted for approximately 60% of observed initial-access methods in the incidents analyzed for its Threat Landscape 2025 report. The agency also noted that large language models are being used to produce more convincing phishing content.
However, focusing only on phishing risks underestimating the broader shift. Anthropic’s research suggests that the impact of AI is spreading across several stages of the cyber kill chain rather than remaining confined to social engineering.
How could Vietnamese businesses be affected?
One of the biggest risks for businesses is that the time between the emergence of a weakness and its discovery or exploitation may continue to shrink.
If AI allows attackers to scan large numbers of internet-facing assets, quickly understand the underlying technology, and adapt scripts to individual environments, unpatched websites, VPN gateways, cloud services, APIs, email systems, and business applications may be tested more aggressively than before.
For Vietnamese organizations, the legal environment has also changed. Cybersecurity Law No. 116/2025/QH15 took effect on July 1, 2026. In parallel, Artificial Intelligence Law No. 134/2025/QH15 took effect on March 1, 2026 and establishes principles for the safe and responsible development, deployment, and use of AI.
The AI law also prohibits the misuse or unauthorized takeover of AI systems for illegal activities, as well as the use of data in violation of regulations governing data, personal data, intellectual property, and cybersecurity.
For organizations deploying internal AI agents, copilots, or automated systems with access to internal data and APIs, the challenge therefore works in both directions. Businesses must defend themselves against attackers using AI while also controlling how their own AI systems access data, applications, credentials, and privileged functions.
IPSIP Việt Nam has separately analyzed the governance requirements surrounding enterprise AI adoption in Vietnam, particularly the need to control access rights, sensitive data, and human oversight when AI systems are authorized to perform automated actions. IPSIP Vietnam analysis on AI governance for Vietnamese enterprises.
What should businesses do as cyber attacks become more automated?
Defending against AI-enabled attacks does not mean every organization needs to purchase a single “AI Security” product. The first priority remains reducing attack surface, strengthening identity controls, and shortening detection and response times.
Priority action checklist:
Maintain an accurate inventory of internet-facing assets, cloud systems, VPN gateways, APIs, and remote-access services.
Establish a risk-based Vulnerability Management and patching process.
Require MFA for privileged accounts, cloud platforms, email, and remote access.
Apply Least Privilege to reduce unnecessary permissions.
Collect logs from endpoints, firewalls, identity systems, cloud services, and critical applications.
Monitor abnormal logins, token creation, privilege changes, and unusual data access.
Test backup restoration rather than checking only whether backup jobs completed.
Train employees to recognize phishing, deepfakes, BEC, and other social engineering techniques.
Restrict execution privileges for internal AI agents and secure API keys.
Update Incident Response playbooks for situations where attackers can operate at machine-assisted speed.
Regular vulnerability assessment becomes more important when attackers can use AI to understand systems that were previously considered obscure or difficult to analyze. Organizations can also review how IPSIP approaches vulnerability discovery and remediation prioritization across websites, applications, and infrastructure through its Vulnerability Assessment service.
What does the IPSIP Vietnam's expert perspective suggest?
Threat actors can use AI to accelerate reconnaissance, social engineering, scripting, system analysis, exploitation support, and post-compromise data processing. Some workflows can increasingly be coordinated by agent or multi-agent frameworks with less direct human intervention.
AI is changing the economics of cyber attacks. Tasks that previously required teams of skilled specialists can increasingly be assisted or partially automated, allowing threat actors to operate faster and at larger scale.
For Vietnamese businesses, the priority should be maintaining visibility over digital assets, shortening vulnerability remediation cycles, improving monitoring, and standardizing incident response. In an environment where attackers can move faster with AI assistance, detection speed and decision-making capability will become increasingly important defensive advantages.
Refernces
ENISA - ENISA Threat Landscape 2025
Government of Vietnam - Law No. 116/2025/QH15 on Cybersecurity
Government of Vietnam - Law No. 134/2025/QH15 on Artificial Intelligence












Comments