Sophos Reports AI Agents Expand Enterprise Attack Surface
For practitioners, AI agents and their credentials create a security-review surface beyond model behavior: OAuth tokens, APIs, development tools, and machine identities can become initial-access or lateral-movement paths when governance is incomplete. Sophos released its 2026 AI Security Report warning that attackers are operationalizing AI to shorten attack workflows and are targeting ungoverned enterprise AI identities. According to Sophos, a campaign tracked as STAC6994 used about 12 AI agents to develop and test endpoint attacks, producing nearly 80 modules and more than 70 evasion techniques in days rather than weeks. The report also identifies AI-assisted social engineering, deepfakes, AI development infrastructure, and supply chains as areas of risk.
Faster attacks change defensive timing
For practitioners, the immediate security implication is not a wholly new attack category but a shorter interval between adversary development, testing, and deployment. Sophos reports that attackers are using AI as an operational force multiplier, placing more pressure on detection engineering, credential controls, and incident response processes that depend on manual investigation.
Sophos released its 2026 AI Security Report. The company reports that AI is compressing cyberattack workflows from weeks to days and that identity-based initial access is becoming more prominent than novel attack techniques. John Peterson, Sophos chief technology officer, said attackers still require initial access, lateral movement, and observable exfiltration channels, but that the timeline for development, testing, and iteration has changed.
AI identities and agent access
According to Sophos, enterprise AI identities, OAuth tokens, agents, APIs, and development tools are high-value targets. The report also identifies AI-assisted social engineering and deepfakes, underground-market activity, prompt engineering and jailbreaking, malware development workflows, and attacks on AI development infrastructure and supply chains.
Sophos describes one campaign, tracked as STAC6994, as a provable instance of active AI use in attacker operations. The threat actor operated a software-development operation within a customer network and used approximately 12 AI agents to write and test attacks against endpoint agents, including products from Sophos, CrowdStrike, and Microsoft Defender, the report states. Sophos reports that the operation produced nearly 80 modules and more than 70 evasion techniques, reducing work that could take a human weeks to a few days.
Controls worth examining
For practitioners, comparable AI deployments commonly increase the number of non-human identities that can call APIs, retrieve secrets, invoke tools, and access internal data. Security reviews can therefore treat agent credentials, delegated OAuth scopes, tool permissions, logging coverage, and revocation procedures as first-class controls alongside model-level safeguards.
Industry context
accelerated attacker iteration makes telemetry retention and response speed more consequential. Organizations using agents can test whether security teams can identify anomalous agent activity, distinguish authorized automation from credential misuse, and disable compromised tokens or service identities quickly. Sophos's findings also place development environments and model-adjacent supply chains within the security boundary, rather than limiting reviews to the production application.
Key Points
- 1Sophos reports attackers are using AI to compress development and evasion workflows, reducing defenders' time to detect and contain intrusions.
- 2Enterprise agents, OAuth tokens, APIs, and development tools expand the identity attack surface cited in Sophos's 2026 security report.
- 3For practitioners, similar agent deployments make least privilege, credential revocation, telemetry, and tool-permission reviews central operational security controls.
Scoring Rationale
The report provides concrete evidence of AI-assisted attacker operations and a substantial reduction in attack-development time. It is highly relevant to teams deploying agents and managing machine identities, though it is a vendor research report rather than a broadly adopted technical standard or vulnerability disclosure.
Sources
Primary source and supporting public references used for this report.
Practice interview problems based on real data
1,625 SQL & Python problems across 15 industry datasets — the exact type of data you work with.
Try 250 free problems


