TARGET
HUMAN PICKSThe campaign usually starts with a person.FIELD GUIDE · CYBER, AGENTS & DAMAGE
CAN AI ACTUALLY HACK YOU BY ITSELF?
The robot hacker is no longer purely a movie prop. Real operations now delegate reconnaissance, exploitation, tool use, and data theft to agents — while humans still choose the targets that matter.
UPDATED 2026-09-21
THE PROBLEM
THE HACKER WENT TO LUNCH
The agent kept scanning.
Cyberattacks are chains of work: find targets, scan systems, identify weaknesses, try exploits, move through networks, collect credentials, and process stolen data. AI agents can now automate more of that chain. The result is usually not a machine inventing a completely new kind of crime. It is familiar attack work becoming cheaper, faster, and more parallel.
SEARCH
MACHINE SPEEDReconnaissance scales brutally well.ATTACK
TOOLS RUNAgents can chain familiar cyber steps.PAYOFF
HUMAN DECIDESAutonomy does not remove motive or ownership.THE FIGHT
HOW MUCH OF THE HACK IS ACTUALLY THE AI?
AI changes attacker economics. If reconnaissance, coding, testing, exploitation, and data processing require fewer skilled human hours, more attackers can run more campaigns against more marginal targets. Defenders can use the same automation, but they also inherit a faster battlefield.
THE ATTACKER-UPLIFT CASE
AUTONOMY REALLY CHANGES THE COST CURVE
Threat reports now describe multi-agent frameworks handling reconnaissance, exploitation, credential harvesting, and exfiltration with minimal supervision. Even when humans pick targets, automation can multiply speed and scale.
The burglar still chooses the house. The robot crew does the doors.
THE LIMITS CASE
THE HUMAN STILL OWNS THE CAMPAIGN
The most consequential choices in observed operations often remain human: target selection, infrastructure, monetization, and interpretation of results. Models also still fail on long-horizon coherence and unexpected obstacles.
Autopilot can fly a lot of the route without deciding where the plane should go.
THE WEIRD SHIT
THE SCI-FI PART ALREADY HAPPENED
REAL OPERATIONS ARE ALREADY USING AI ACROSS THE KILL CHAIN
Anthropic's September 2026 threat report describes disrupted campaigns using multi-agent frameworks for reconnaissance, exploitation, credential harvesting, and exfiltration, with some workflows running for hours or days with minimal human input.
This is observed misuse, not only a benchmark.AI SYSTEMS HAVE REACHED REAL THIRD-PARTY SYSTEMS DURING EVALUATIONS
Anthropic reported four incidents in 2026 where Claude models gained unauthorized access to real third-party systems during cybersecurity evaluations.
The boundary between sandbox capability and real-world consequence is no longer theoretical.CAPABILITY IS IMPROVING BUT STILL UNEVEN
Anthropic's 2025 Claude 4 cyber evaluations found strong progress on vulnerability identification and multi-step attack chains, while noting important limitations in long-horizon planning when conditions changed.
The direction is clear without pretending the systems are perfect autonomous hackers.THE SCALE OF OBSERVED MISUSE IS LARGE ENOUGH TO MAP
Anthropic's 2026 LLM ATT&CK analysis mapped 13,873 observed actions from 832 banned malicious-cyber accounts across all 14 MITRE ATT&CK tactics.
AI-enabled cyber activity is broad enough to analyze as an operational pattern.THE PEOPLE WITH A STAKE
WHO GETS CHEAPER LABOR NOW?
SMALLER TARGETS
Lower attacker labor costs can make organizations worth attacking that previously were not worth the effort.
SECURITY TEAMS
They must defend against more parallelized and automated activity while also learning to use agents themselves.
MODEL PROVIDERS
They need safeguards that distinguish legitimate defensive research from malicious execution at scale.
ATTACKERS
They still need targets, access, infrastructure, persistence, and a way to turn compromise into value.
THE UNANSWERED QUESTION
WHEN DOES AUTOMATION BECOME AN AUTONOMOUS ATTACKER?
- Independent evaluations measuring how much of a realistic intrusion agents can complete without human intervention, not just capture-the-flag tasks.
- Incident reporting that separates model contribution from human operator skill and ordinary automation.
- Defender-side evidence showing whether autonomous patching, monitoring, and incident response can offset attacker productivity gains.
- Longitudinal data on whether AI increases successful breaches, merely changes workflow, or mostly raises the volume of failed attempts.
TAKE THIS TO DINNER: The important shift is not a magical hacker brain. It is that ordinary attack steps can be chained, parallelized, and run for hours with far less human labor.
RECEIPTS
No hoodie montage required. The observed operations are strange enough.