Sophos Reports AI Agents Expand Enterprise Attack Surface
Sophos released its AI Security 2026 Report on July 22, warning that attackers are using AI to compress development and testing cycles from weeks to days while targeting enterprise AI identities, OAuth tokens, agents and APIs. Sophos says the STAC6994 campaign used about 12 AI agents to produce nearly 80 modules and more than 70 evasion techniques. The findings are vendor threat intelligence, not a universal incident rate.
Sophos says AI is shortening attack-development cycles
Sophos released its AI Security 2026 Report on July 22, arguing that attackers are using AI to compress development, testing and iteration from weeks to days. The company says the immediate change is speed rather than a completely new class of attack: adversaries still need initial access, lateral movement and a way to exfiltrate data.
The report identifies enterprise AI identities, OAuth tokens, agents, APIs and development tools as high-value targets. It also highlights AI-assisted social engineering, deepfakes, malware-development workflows and attacks on AI infrastructure and software supply chains.
These findings are based on Sophos X-Ops casework, SophosLabs analysis, Counter Threat Unit intelligence, AI research and endpoint and network observations across the company's customer base. They should be read as vendor threat intelligence, not as a universal measurement of every enterprise environment.
The STAC6994 case
Sophos describes a campaign tracked as STAC6994 in which a threat actor operated a software-development environment inside a customer's network. The company says the actor used roughly 12 AI agents to write and test attacks against endpoint products from Sophos, CrowdStrike and Microsoft Defender.
According to Sophos, the operation produced nearly 80 modules and more than 70 evasion techniques, turning work that could take a human weeks into a few days. Independent analysis from Purple Shield Security adds an important limitation: the activity was human-directed, and the toolkit's own documentation overstated some success claims. Sophos found that the available test data did not support claims of near-universal evasion.
The evidence therefore supports a narrower conclusion than "autonomous AI defeated endpoint security." AI accelerated a structured research-and-test cycle, while people directed the work and the reported bypass performance was not uniformly reliable.
What enterprise teams should examine
AI agents can introduce non-human identities with access to APIs, secrets, developer tools and internal data. Security reviews can treat those identities like other privileged service accounts by checking:
- •Least-privilege scopes for tools, data and delegated OAuth access.
- •Short-lived credentials and tested revocation procedures.
- •Telemetry that distinguishes expected automation from anomalous agent activity.
- •Supply-chain controls for models, plugins, MCP servers and development tools.
- •Incident-response timing that accounts for faster attacker iteration.
The report does not show that every AI agent is compromised or that traditional controls are obsolete. It does show why agent credentials and tool access belong inside the same identity, monitoring and response programs used for other production systems.
Key Points
- 1Sophos says AI is compressing attacker development and testing cycles from weeks to days rather than creating entirely new attack stages.
- 2The STAC6994 campaign reportedly used about 12 AI agents to build nearly 80 modules and more than 70 evasion techniques.
- 3The campaign was human-directed, and Sophos found that some internally generated success claims were not supported by the test data.
Scoring Rationale
The report provides a documented example of AI-assisted attacker development and identifies agent credentials and AI infrastructure as an expanding security boundary. Its conclusions are vendor threat intelligence and should not be generalized into universal incident rates.
Sources
Primary source and supporting public references used for this report.
Practice interview problems based on real data
1,625 SQL & Python problems across 15 industry datasets — the exact type of data you work with.
Try 250 free problems

