AI is helping attackers work faster at tasks such as reconnaissance, social engineering and malware development—but current reporting does not show that it has displaced familiar ways into organizations. In Mandiant’s investigations of targeted attacks during 2025, exploits were the most common initial infection vector; Microsoft likewise reports that many threats targeted known security gaps. For defenders, the priority is still to close those gaps, protect identities and prepare to contain and recover from incidents, while adding controls for AI-specific risks.
Does AI make cyberattacks faster?
It can make parts of an operation more efficient. Google Cloud’s M-Trends 2026 says threat actors increasingly use AI for productivity, including reconnaissance, social engineering and malware development. Microsoft describes AI-assisted phishing and multi-stage attack chains in its Digital Defense Report 2025. These accounts support a change in operational speed and scale, not a claim that AI has replaced established attack methods.
AI is also used by defenders. Microsoft puts the dual-use point plainly: “Both adversaries and defenders are using AI to make their operations more effective and efficient, rendering the technology a cybersecurity risk and tool at once.” The practical question is therefore not simply whether an attacker used AI, but whether the organization has left an exploitable weakness, an exposed identity, or an inadequate response process.
Are hackers using AI to break into systems?
AI can assist work around an intrusion, but the available reports do not establish that it independently caused most breaches. Mandiant says that in its 2025 investigations, “the vast majority of successful intrusions still stem from fundamental human and systemic failures,” rather than breaches being the direct result of AI. That conclusion applies to Mandiant’s investigated cases, not every incident worldwide.
Free tools Windows power users keep installed
One-click scans. No signup required.
#1 Best Overall
- POWERFUL SECURITY KEY: The Security Key C NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
- WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key C NFC secures 100 of your favorite accounts, including email, password managers, and more.
- FAST & CONVENIENT LOGIN: Plug in your Security Key C NFC via USB-C and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
- TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
- BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
The initial-access figures in M-Trends 2026 illustrate why conventional defenses remain relevant. In Mandiant Consulting’s targeted-attack investigations from January 1 through December 31, 2025, exploits accounted for 32% of initial infection vectors and were the most common. Voice phishing accounted for 11%, making it the second most common in that dataset; email phishing accounted for 6%. These are proportions of vectors observed in that investigation set, not global attack rates.
Microsoft’s report describes a separate body of observations. It says most threats in its reporting targeted known security gaps, including web assets and remote services. It also reports that 97% of identity attacks in Microsoft’s observed dataset were password-spray attacks. That figure is about identity attacks seen by Microsoft, not 97% of cyberattacks overall. The two vendors’ statistics should not be combined: their datasets and scopes differ.
Rank #2
- POWERFUL SECURITY KEY: The YubiKey 5 NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
- WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5 NFC secures 100+ of your favorite accounts, including email, password managers, and more
- FAST & CONVENIENT LOGIN: Plug in your YubiKey 5 NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
- MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
- PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts
Do basic cybersecurity practices still work against AI-assisted attacks?
Yes. Baseline controls address the same weaknesses attackers can exploit whether or not they use AI: unpatched software, weak or exposed credentials, insufficient monitoring, and poor recovery readiness. NIST notes that “Some cybersecurity risks related to AI systems are common (or identical) to cybersecurity risks across software development and deployment.” Its AI security and resilience guidance identifies confidentiality, integrity, availability, and the security of supporting software and hardware as shared concerns.
Close known exposure
Maintain an inventory of internet-facing assets and critical services, prioritize known exploitable vulnerabilities, and reduce the time between identifying a vulnerability and applying a fix. Include remote access services and web applications in the review; attackers need not invent a new technique when an old weakness remains reachable.
Rank #3
- POWERFUL SECURITY KEY: The YubiKey 5C NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
- WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5C NFC secures 100+ of your favorite accounts, including email, password managers, and more
- FAST & CONVENIENT LOGIN: Plug in your YubiKey 5C NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
- MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
- PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts
Protect identity and resist social engineering
Use unique, strong passwords and phishing-resistant multifactor authentication (MFA) where supported. Microsoft says phishing-resistant MFA can stop over 99% of identity-based attacks; this is Microsoft’s efficacy claim, not a guarantee against every account compromise or attack type. For individuals considering a FIDO2-compatible hardware security key, check that the specific account and devices support the standard before buying or enrolling a key.
For organizations, make authentication controls resilient to credential phishing and interactive voice scams. Verify unusual requests to change access or transfer money through a second, independently trusted channel rather than relying on caller identity or urgency.
Rank #4
- POWERFUL SECURITY KEY: The Security Key NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
- WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key NFC secures 100 of your favorite accounts, including email, password managers, and more.
- FAST & CONVENIENT LOGIN: Plug in your Security Key NFC via USB-A and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
- TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
- BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
Monitor, contain and recover
Monitor identity behavior and infrastructure continuously enough to investigate suspicious sign-ins and activity promptly. Keep incident-response responsibilities clear, and ensure backups and the identity and infrastructure systems needed for recovery are protected and usable. Track practical measures such as MFA coverage, patch latency and incident-response time; Microsoft explicitly recommends monitoring these kinds of indicators.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.What changes when an organization uses AI systems?
Baseline security remains necessary, but it does not cover every AI-specific attack surface. NIST identifies risks including evasion, model extraction, membership inference and availability attacks, and notes that existing frameworks do not fully address AI-specific abuses. Its AI 100-2 E2025 provides a taxonomy of adversarial machine-learning methods, lifecycle stages, attacker objectives and capabilities, and mitigations. NIST published it in March 2025; its publication record notes a correction and a page error with potential updates, so it should be treated as technical guidance rather than an immutable standard.
Organizations deploying AI should inventory the models and connected components they use, including inputs, outputs, training data, permissions and tools that can take actions. Test where untrusted inputs could manipulate behavior or expose information, limit permissions to what each system needs, and monitor actions and outputs. Treat the AI component as part of the software and data lifecycle, while separately assessing threats that arise from model behavior or access.
What should a business fix first?
- Review exposure: identify internet-facing applications, remote services, identities and AI components, and assign owners.
- Patch known exploitable weaknesses: prioritize exposed assets and track how long fixes take to deploy.
- Strengthen authentication: expand MFA coverage, favor phishing-resistant methods where supported, and establish independent verification for high-risk requests.
- Improve detection and response: monitor identity and infrastructure activity, define escalation paths, and measure time to investigate and contain incidents.
- Prove recovery: protect and test backups and the systems required to restore identity and operations.
- Assess AI-specific exposure: document models, data flows, permissions and connected tools; test for misuse, unauthorized actions and availability risks.
This order reflects the continuing importance of known gaps and identity attacks in the cited reporting, alongside the additional attack surfaces introduced by AI. It is a practical synthesis, not a product ranking or a guarantee that any single control will prevent an intrusion.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.




