< Back to situations

We’ll email you as it develops, and you can follow the whole thread from day one.

[SITUATION] · [ACTIVE]

2 clusters · 5 sources · 14 days · First seen · Last updated

Categories: TECHNOLOGY

AI insider threats in enterprises

Entities: Model Context Protocol · Verizon · ShinyHunters · Amtrak · Shadow AI

Overview

Early in July 2026, security analysts warned that autonomous AI agents integrated into business workflows were creating a new form of insider risk. Because these agents operate with valid identities and full system privileges, their actions appear authorized and can be chained across many benign‑looking steps. Traditional tools that monitor discrete, human‑paced events often miss these “slow‑burn” attacks, prompting a shift toward continuous Agent Behavior Analytics that evaluate entire sessions for malicious intent.

By the end of July, the threat landscape had expanded. The Verizon 2026 Data Breach Investigations Report showed that 60 % of insider data misuse now originates from productivity‑driven AI adoption rather than deliberate sabotage. “Shadow AI” and autonomous agents built on protocols such as the Model Context Protocol can access admin‑level resources, evade logging, and undermine forensic attribution. Criminal groups have begun exploiting the data exfiltrated by these AI‑mediated breaches for extortion, sending ransom demands that reference high‑profile leaks (e.g., the ShinyHunters breach and an Amtrak data set). The evolution reflects a move from covert insider leakage to overt monetisation of stolen information.

Together, the snapshots illustrate how enterprise security teams must now treat AI agents as user equivalents, applying behavioral analytics and contextual policies to detect and prevent both stealthy data theft and its subsequent extortion use.

Timeline

  1. 1 day ago

    [TECHNOLOGY] 2 sources
    AI‑driven insider leaks boost data‑breach extortion scams

    AI‑driven insider leaks and a ShinyHunters breach are fueling extortion scams, with 60% of misuse now linked to productivity‑driven AI use, per Verizon 2026 report.

  2. 15 days ago

    [TECHNOLOGY] 3 sources
    AI agents create new insider risk for enterprises

    AI agents, trusted with real system access, pose insider risks that evade traditional detection; contextual policies in Omnigent can stop multi‑step “slow‑burn” attacks.

Sources

appgate.com · databricks.com · ilcorrieredellasicurezza.it · statisticsbyjim.com · telefonino.net