How AI-driven attacks are pushing cybersecurity to the brink - IOL
Rapidly evolving agentic AI tools and mounting alert fatigue are overwhelming understaffed cybersecurity teams, sparking a unprecedented surge in automated cyber threats. Picture: Google Gemini
It would be a severe understatement to say that modern cybersecurity is facing the greatest threat in its history.
Cybercriminals are becoming increasingly adept at leveraging artificial intelligence to execute their nefarious goals at scale.
As Allan Juma, Lead Cybersecurity Engineer at ESET, highlights in his article "Making sense of SOC alert overwhelm in the age of AI", security teams are not failing because they are blind to incoming threats. Rather, they are suffocating under a mountain of irrelevant data while trying to isolate and respond to genuine attacks.
The numbers reflect a rapidly escalating crisis. According to IBM’s 2026 Cost of a Data Breach Report, AI-driven attacks surged 56% year-over-year, with one in four organisations falling victim to an AI-powered breach.
Compounding the problem, the Microsoft State of the SOC 2026 study reveals that 46% of security alerts are false positives, while a staggering 42% are never investigated at all. This operational strain arrives at the worst possible time: the 2025 ISC2 Cybersecurity Workforce Study reports that 59% of cybersecurity teams suffer from critical skills shortages—a massive 15% jump from the previous year.
Meanwhile, the threat vector itself is undergoing a fundamental transformation. Mick Amelishko, AI Advocate at Sumsub—an AI-powered trust infrastructure provider unifying identity verification, fraud prevention, transaction monitoring, and risk management to optimise compliance efficiency—recently detailed how agentic AI is evolving.
“The biggest shift moving into the 'agentic' way of working is agency,” Amelishko explained. “Last year, AI was merely an assistant—helping refine writing or offering basic recommendations. Now, AI can interact with the external world: it browses the live internet, connects with digital products, executes independent purchases, registers on websites, and can even transact directly with bank accounts if granted permission.”
The trajectory is undeniable: the requirement for human involvement in orchestrating cyberattacks is shrinking dramatically, even as the volume and velocity of automated threats multiply every day.