AI-driven cyber attacks target MFA and autonomous toolchains worldwide
Security researchers warn that attackers are merging credential theft, AI‑generated social engineering and toolchain hijacking into a single assault on AI‑enabled infrastructure. By bypassing legacy multi‑factor authentication (MFA) and injecting malicious "skills" or plugins into the Model Context Protocol (MCP), threat actors can turn autonomous AI agents into high‑privilege execution engines, enabling lateral movement and software‑supply‑chain poisoning.
Kaspersky’s 2026 global study shows 43 % of organizations believe hackers are already using AI to boost attack effectiveness, and 21 % think criminals are ahead in the technology race. AI‑driven phishing, automated code generation and evasive payloads have surged across sectors, with the hospitality, financial and entertainment industries reporting large‑scale campaigns that leverage AI‑generated content and rapid reconnaissance.
Defenders are urged to adopt integrated AI‑powered security platforms rather than isolated tools, and to harden identity frameworks against AI‑automated session hijacking. Continuous monitoring of agentic workflows and the AI software supply chain is seen as essential to mitigate the emerging systemic risk.