AI Models Become Persistent Attack Operators

Commercial AI is no longer just helping attackers write prompts or code. It is being wired into live intrusion workflows as a repeatable operator, so blocking one account or one prompt often does not stop the campaign once the attacker has durable access. Check Point says the shift showed up across criminal, ransomware, and espionage cases during March and April 2026. One documented case involved 1,088 attacker prompts, 5,317 AI-executed commands, and 34 sessions against nine Mexican government agencies. The report also ties persistence to leaked .env tokens and similar standing access, which can survive provider attempts to revoke a single account. The practical risk moves to token and delegation control. If an AI assistant or coding tool can act on connected systems, the important question is who still holds access after the model session ends or the provider intervenes.

Part of the PlainSec briefing for 2026-05-27

Sources