Start your day with intelligence. Get The OODA Daily Pulse.

Home > Briefs > Cyber > An AI-Assisted Cyber Attack: Inside a Unit 42 Investigation

An AI-Assisted Cyber Attack: Inside a Unit 42 Investigation

Unit 42 responded to an incident where a human attacker used frontier AI to breach an enterprise network autonomously as part of a ransom attack. The agents breached the company’s security layers in a methodical manner, each targeting a different layer of defense to achieve a shared goal. The impact was at the scale of a coordinated effort from multiple red teams, which would normally take human operators around two weeks. The threat actor told us in negotiations that they leveraged frontier AI models and attack-specific agentic AI frameworks. By shifting execution to an automated loop, the attacker compressed weeks of methodical intrusion tradecraft (using more than 50 MITRE ATT&CK techniques) into less than 10 hours. After they gained initial access, the attacker used agents to map the internal architecture, raid source repositories and seize root credentials. The agents also triggered unauthorized continuous integration/continuous delivery (CI/CD) builds and claimed master keys to the victim’s cloud AI infrastructure.

Full report : Using autonomous AI agents, an attacker breached an enterprise network in a matter of hours.