The ascent of autonomous attacks and the race to contain them | Daily Reports Online
Cyber risk is now a board room issue, and we have seen clear examples of this in the UK. The 2025 Jaguar Land Rover attack left the carmaker with a £485m loss, swallowing up the £398m profit it had generated just 12 months before.
Production lines were halted for more than a month as the company shut down parts of its network, showing how quickly a cyber incident can affect business performance, operational continuity and the wider supply chain.
Virtual Chief Information Security Officer at Thrive.
Now, businesses are facing a fresh type of threat made possible by AI – the autonomous attack. Attackers can already automate parts of target research, initial access and malware development, with any manual effort shrinking rapidly.
Latest Videos FromTechRadar
Simultaneously, the trust layer people rely on is eroding with the spread of AI-generated content and deepfakes. It’s a race to tackle the autonomous attack, but how do organizations formulate an effective response?
AI in a cyber-attacker’s armory
AI-driven automated technologies are strengthening a cyber-attacker’s armory. Prior to leveraging AI tools, bad actors often had to commit time and resources to researching a target company before planning an attack.
Timing was critical, and a perpetrator had to manually coordinate and initiate an attack at a specific time and could simply forget. AI doesn’t – and the rise of attack-as-a-service tools is making it possible to successfully breach organizations quickly and accurately.
Guardrails are starting to be put up around established generative AI tools, such as ChatGPT and Claude, in an effort to prevent this kind of misuse. But hackers are finding workarounds.
Rather than relying on readily available large language models (LLMs), they are deploying their own small language models (SLMs) on local devices, often on something as basic as a Raspberry Pi computer. From there, they can escalate attacks while hiding in the shadows.
The threat to businesses of all sizes
The rise of automated attacks also means that businesses of all sizes are likely to be identified by automated technology as having exploitable vulnerabilities. Small and medium-sized businesses would previously have been off the radar as attacks relied on a bad actor’s knowledge of their existence.
However, AI can now scan and process vast numbers of organizations at speed, potentially leaving smaller firms, which are less likely to have robust cyber controls in place, more exposed. And even more so among smaller businesses, defenses are typically more fragmented and less organized than AI-driven attacks.
In other words, with AI by their side, attackers can coordinate and scale far better and much more quickly than most businesses can defend.
Autonomous attacks also make third-party and supply chain risk much harder to manage. Business networks can create access to data, systems or operational processes. When attackers can automate reconnaissance and scale attacks across thousands of organizations, weaker suppliers may become an attractive route into larger businesses.
This is a particular concern because third-party risk management has often relied on annual questionnaires, point-in-time assessments and contractual assurances, but these approaches are no longer enough on their own. A supplier may have recently exposed a service, suffered a breach, changed its access privileges or failed to patch a critical vulnerability.
Businesses therefore need to move towards continuous, automated monitoring of supplier security posture.
Regulations such as NIS2 have also increased the focus on supply chain security for organizations operating in, or selling into, the EU. There is also a growing expectation from ICO and the FCA that boards can demonstrate cyber resilience.
Automation and the rise of specific attack types
Jadepuffer illustrates how AI is beginning to transform established attack types. Disclosed by Sysdig in July 2026, it was assessed as the first documented end-to-end LLM-driven extortion operation, with an AI agent conducting reconnaissance, harvesting credentials, moving between systems, destroying data and adapting when individual actions failed.
While none of the techniques were especially new in isolation, the significance was the way the AI connected them into a complete, adaptive attack.
Social engineering techniques, such as bad actors posing as trusted individuals, are becoming much more convincing in their approach. Fluent, grammatically correct messages and the professional tone and style of CEO communications can now be fully replicated on emails, SMS and even WhatsApp.
AI can even manage the entire conversation thread, including dynamically adapting responses to a target’s replies, with it possible to run simultaneous, tailored campaigns.
Vendor email compromise, where criminals impersonate suppliers, intercept genuine payment conversations or use compromised vendor accounts to request changes to bank details, directly links social engineering to third-party risk.
Taking a step back, the initial harvesting process of personal data for social engineering attacks can be streamlined. AI can automatically scrape data from public sources such as Companies House and social media to quickly provide the names of specific people, their roles and relationships.
When trust and identity come under attack
Even on video conferencing calls, it’s becoming increasingly difficult to tell if the person you’re speaking to is real due to the increasing accuracy of deepfakes. As an example, it’s often now necessary to ask a suspected deepfake to do something it wasn’t programmed to do, such as raise a hand, to check if the person in question is real. But even that test is gradually being circumvented by new technology.
Organizations need stronger out-of-band verification protocols for high-value or unusual requests. A pre-agreed code word via a separate channel might be needed to ensure trust and security.
This is why identity and access management should be treated as a critical control. Organizations need to know who has access to what, whether that access is still needed, which accounts are privileged and how quickly unusual behavior can be detected.
Fighting AI with AI
AI-driven autonomous attacks might be heightening the risk, but AI can also be used defensively. A good example of this is to run an automated risk analysis of an organization and highlight where security tools and the basics, such as malware protection, are out of date or missing.
With those fundamentals in place, AI can then underpin continuous monitoring of the critical systems, rather than periodic checks. Businesses should be identifying and focusing on protecting the “crown jewels” – that might be the top 10 most critical assets, such as payroll or a banking system, and target AI-led efforts on protecting them.
Joined-up visibility is then crucial. Businesses need to know who has access to those critical assets, the endpoint and network activity related to them and gain the ability to correlate any incidents quickly so the response to an AI-driven attack can be as swift as possible.
A combination of AI-powered technology, backed by human expertise, can provide proactive threat hunting to actively search for, investigate and remediate dangers, even if they are autonomous in origin.
Organizations aren’t powerless in the fight
The rise of autonomous attacks marks a new phase in cyber risk. For many businesses, particularly smaller ones, the challenge is preparing for attacks that can move much faster than traditional defenses. But organizations aren’t powerless in the fight.
Effective responses start with getting the basics right, from access controls to visibility across critical assets, to moving from periodic checks to continuous monitoring and faster detection with AI.
However, technology alone won’t be enough. Human expertise can interpret risk and make informed decisions under pressure to ensure resilience, even as the AI-driven autonomy threat moves to the next level.
We’ve featured the best firewall software.
This article was produced as part of TechRadar Pro Perspectives, our channel to feature the best and brightest minds in the technology industry today.
The views expressed here are those of the author and are not necessarily those of TechRadarPro or Future plc. If you are interested in contributing find out more here:







