Category
AIA criminal hooked an AI up to the internet, gave it one instruction, and walked away. The machine went looking for victims by itself. Here is what an autonomous AI attack means for your business, and the one number in the report that should get your attention.
See Where Your Business Stands →
A plain-English computer security scan. No card needed to see your results.
The problem: Until now, an autonomous AI attack was a thing researchers warned about. Last month it stopped being a warning. A real criminal built one, pointed it at the open internet, and let it pick its own victims out of a crowd of more than 460. Nobody sat at the keyboard.
The straight answer: This particular machine came up short, and I will show you exactly where it failed. But the researchers who took it apart used one word that matters more than the failure: narrow. You cannot slow the machines down. What you can control is whether the doors on your business are shut before the next one gets a little better.
Hey folks! For two years I have been telling you the same thing about AI. It is oversold as the thing that will save you and badly undersold as the thing that will come after you. Last month the security team at Palo Alto Networks handed me the proof, and I want to walk you through it slowly, because the details matter more than the headline.
Here is what they found. A crook working out of China took DeepSeek, a Chinese AI you can use for pennies, and wired it into an off-the-shelf program that lets an AI type commands into a computer the way a person would. Then he did the part that makes this different from every other hacking story you have read. He gave it a starting instruction and walked away.
The machine went to work on its own. It used an internet search tool to hunt for computers sitting exposed online. It went out and collected its own break-in code from a public code-sharing site. It picked which weakness to try. It ran the attempt, saw the result, and decided what to do next. The whole thing took its orders through a chat channel, so the operator could check in whenever he felt like it, the way you would glance at a text message.
Across the campaign, this operation swung at more than 460 targets. And the researchers recovered one session from May where the human gave a single task at the start and then contributed nothing at all. The machine did the rest.
They even captured what the AI wrote to itself as it worked. At one point it noted a weakness it liked with something close to enthusiasm, flagging that a particular flaw rated at the top of the danger scale “looks extremely promising.” At another point it hit a wall and reasoned its way around it: those targets need something I do not have, so go search for bigger ones. That is not a script running. That is something choosing.
Source: Unit 42, Palo Alto Networks, “AI-Enabled Autonomous Cyberattack Campaign,” July 30, 2026.
Now here is where I have to be straight with you, because a lot of writers are going to get this story wrong this month.
The autonomous AI attack failed.
I mean that literally. Every break-in the machine attempted entirely on its own came up empty. The attacks in that campaign that actually worked were the ones where the human sat down and did it by hand, the old-fashioned way. If you want the honest headline, it is this: the robot lost, and the guy won.
So why am I writing about it? Because of the sentence the researchers used to describe the result. They said autonomous attack cycles are operationally viable, and the margin of failure was narrow.
Narrow. Sit with that word for a second.
These are not people who exaggerate for clicks. They are the ones who take this stuff apart for a living, and their considered assessment was not “this does not work.” It was “this nearly worked.” The machine did not fail because the idea is impossible. It failed the way a first attempt fails, on details that get patched up in the next version.
Here is the whole shift in one sentence. For thirty years, the thing protecting a business your size was not your firewall. It was arithmetic. A skilled crook only had so many hours in a day, and there were always easier targets than you. That math is what kept most small businesses safe without them ever knowing it. An autonomous AI attack deletes the arithmetic. A machine does not get tired, does not get bored, and never once decides your business is too small to bother with. It does not decide anything. It just goes down the list.
And notice how cheap the whole setup was. The AI is inexpensive. The program that let it drive a computer is public. The tool it used to find exposed machines is a website. There was no secret laboratory here. One person with a chat app assembled this out of parts anybody can get.
That is the part I want you to hold onto. The hosers do not need to be brilliant anymore. They need to be persistent enough to try again with a slightly better model. And better models ship every few months.
None of this matters as a technology story. It matters as a business story, so let me tell it that way. When an automated attack finds one open door at your company, here is what is on the table.
Your cash, and the days you cannot open. Ransomware, which is software that locks up your files and holds them for money, does not just cost you the ransom. It costs you every day you cannot invoice, cannot ship, and cannot serve a customer while you dig out. I have watched businesses survive the payment and nearly go under from the downtime.
Your customers’ trust. The names, cards, and account details your customers handed you are exactly what these tools go hunting for. Lose them once, and the cleanup is not the hard part. The hard part is every customer quietly deciding whether they still want to hand you anything.
Your ability to prove you were careful. When an insurer or a big customer asks what you were doing to protect this, a shrug is an expensive answer. Being able to show that somebody was watching is worth nearly as much as the watching itself.
Here is what makes an automated attack different from the kind you are used to worrying about. There is no phone call and no suspicious email for anyone to catch. Nobody on your team gets a chance to be the hero who spotted it. The machine finds a door that was already open, walks through, and the first you hear about it is the aftermath.
That is why the fight is not about being clever in the moment. It is about the doors being shut before anything comes down the road.
My own father fell for a phishing email. That is a fake message built to trick you into handing over a password or your money. More than three decades in this field, and it still reached the person I most wanted to protect. The hosers got into his computer from far away and started hunting for his financial papers. My step-mother noticed something was wrong and called me. I stopped them before they reached his bank logins. We were lucky. We caught it in time. A day slower and it would have been a very different phone call.
That is what an unwatched door feels like when it is your family, and it is why I do this the way I do. More than 35 years at this, since 1991. FBI InfraGard trainer. Not one client I manage has ever been hit by ransomware. That is not luck. It is a real person watching the doors instead of assuming a tool has it covered. The criminals get to point an AI at the internet now. It is not right that they get to be the only ones with something tireless in their corner.
Fair question, and I would rather you ask it than nod along. Here is my answer. Look at what the machine failed at. It did not fail to find targets. It found plenty. It did not fail to pick a weakness. It picked good ones. It failed on the last step, turning a known hole into a working break-in, and only on some of them. Everything up to that final step already works today, at machine speed, for pennies.
And here is the uncomfortable part. Every target it found was found because that computer was sitting out where anybody could see it. The machine did not need to be brilliant to build the list. It just had to look. So the useful question is not whether this generation of the tool can finish the job. It is whether your business is on the list it builds. That one you can actually do something about this week.
1. Find out what of yours is visible from the internet. That is the whole first half of an autonomous AI attack, and it is the half you can take off the board. Anything that answers from the outside world, a camera system, an old server, a remote access box a vendor set up years ago, is on somebody’s list right now. Most owners have never seen that list for their own business.
2. Turn on real two-step login everywhere it matters. Email, banking, payroll, and your main business apps. Skip the text-message codes and use an app like Duo. Automated attacks live on stolen and guessed passwords, and a second step stops most of them cold.
3. Put a guard at the front gate. For a business, Cisco Umbrella or OpenDNS keeps your computers from ever reaching a known-bad site, so an attack has a much harder time phoning home even if something slips in. It is one of the cheapest, highest-value moves there is.
Let me ask you a few plain questions, and just answer them in your head. You did not go into business to keep up with hackers, did you? You assumed the tools you already pay for had this covered. You are a careful owner, the kind who reads a piece like this all the way down instead of skimming the headline. And you also just read that one person with a cheap AI and a chat app built something that went hunting across 460 businesses by itself, and came closer than anybody wants to admit.
Hold those last two together for a second. Careful owner. Machine already out there building lists. Both true at once, and that is an uncomfortable place to sit.
That discomfort is not evidence you did something wrong. It is the gap between the careful owner you actually are and a set of doors that quietly went unwatched while you were busy running the place. The gap opened because the attack side changed faster than anybody told you, and because watching for this stopped being a part-time job somewhere along the way.
Here is the thing about that gap. There are only two ways to close it. You can tell yourself it is probably fine, and carry the same quiet itch into the next story like this one, and the one after that. Or you can spend a few minutes, find out exactly where your business actually stands, and put the question to bed. One of those roads ends the worry. The other just reschedules it. Acting is not the scary option here. Acting is the thing that makes the worry stop.
The attacks run themselves now. Your defense should not depend on somebody remembering to log in. The next move is not to learn more about AI. It is to find out where your own doors stand, and you do not have to do it alone.
Book a call, on us. We scan your computers and fix the single most important thing first. You will not pay a dime, and you decide what happens next.
Not one client we manage has ever been hit by ransomware. That is not luck. That is someone actually watching the doors.
You run your business. We keep it running.
Book My Scan →
A few minutes with a real person, straight talk on where your business stands. No pressure.
Want this kind of plain-English security news every week? Sign up for Craig’s Insider Notes at CraigPeterson.com.
#AutonomousAIAttack #AICyberattacks #SmallBusinessCybersecurity #Ransomware #ForwardToSafety
Join thousands of security professionals who receive Craig Peterson's Insider Show Notes and cybersecurity updates.
Join 10,000+ cybersecurity professionals
Tagged with: