AI Did Not Change the Attack

AI Did Not Change the Attack
AI Attack Hype
Loading the Elevenlabs Text to Speech AudioNative Player...

“AI is compressing the cyber kill chain” is a warning that now appears throughout the security industry. The claim is that attackers can use AI to perform reconnaissance, discover vulnerabilities, create convincing impersonations, and execute attacks so quickly that existing defenses can no longer keep pace. The fear is not simply that attackers will become more capable. It is that AI has changed the nature of an attack so completely that defending against it now requires an equally autonomous AI system.

The current conversation treats AI-assisted attacks as though they represent a fundamentally new kind of cyberattack. Attackers supposedly operate at machine speed, collapse the kill chain, bypass traditional controls, and therefore require defenders to deploy their own autonomous AI systems.

That framing confuses the tool performing the work with the mechanics of the attack. AI improves speed, quality, scale, and manpower efficiency. It does not change what an attack must accomplish inside the target environment.

The answer is therefore not automatically “AI fighting AI.” Before introducing a new defensive model, we should examine how attackers are actually using AI and determine whether the attacks themselves have changed.

What AI Is Actually Improving

Claims about a compressed kill chain become easier to evaluate when we stop treating “AI attack” as a single category and look at what attackers are actually using AI to improve. Two applications capture the practical concern: fraud-as-a-service, which improves attacks against human trust, and AI-assisted vulnerability discovery, which expands the technical attack surface.

Fraud-as-a-service helps criminals make impersonation more convincing and easier to scale. It can improve phishing experiences, reproduce trusted websites, interpret communications from compromised accounts, identify financial relationships, and create fraudulent invoices or payment requests that resemble legitimate business activity. The technology reduces the inconsistencies that once helped a person recognize the attack.

AI-assisted vulnerability discovery applies the same improvement in capability to software. It can help find zero-day vulnerabilities, analyze released patches, evaluate known weaknesses, and produce exploits more quickly. Instead of making a fraudulent interaction harder for a person to recognize, it creates or identifies an entry point the defender may not yet know exists.

These attacks target different weaknesses, but they leave defenders with the same engineering problem. A convincing impersonation may no longer contain the human tells associated with fraud, while a zero-day cannot be identified through a signature that does not yet exist. In both cases, the malicious element may be difficult to detect directly. The next question is whether the delivery, behavior, and effects surrounding it can be made equally invisible.

Fraud-as-a-Service: When the Familiar Tells Disappear

Fraud-as-a-service gives us the first practical way to test whether AI has changed the attack or improved its execution. The improvement is easy to recognize because the fraudulent material looks more like the legitimate business activity it is designed to replace. The attacker succeeds by removing the inconsistencies that once caused a person to pause.

An invoice used to create suspicion when its presentation differed from what the recipient normally received. A supplier that always submitted an Excel file might suddenly send a PDF, or familiar payment instructions might appear in an unfamiliar format. Those differences did not prove fraud, but they gave the recipient a reason to scrutinize the request. AI allows the attacker to study previous transactions and reproduce the expected format while changing only the information needed to redirect the payment.

A compromised business email account gives the attacker the context required to improve that imitation. The mailbox reveals how the organization communicates, which suppliers submit invoices, and who participates in approving payments. AI can process that history and help the attacker enter an existing conversation with a message and document that fit the relationship. The fraudulent request no longer needs to overcome the recipient’s expectations because it was constructed from those expectations.

The disappearance of these human tells does not make the activity surrounding the request legitimate. Before the invoice arrives, the attacker must access the identity, interact with the mailbox, and locate the relevant correspondence. That activity creates its own history. A user who consistently signs in from a Mac may suddenly produce a Linux session, or a connection from the expected geography may arrive through a cloud provider that the user has never used.

This is where electronic scrutiny replaces visual scrutiny. The system does not decide that every Linux session or cloud provider is malicious. It determines whether the activity represents a meaningful change in the way that particular identity normally operates. The comparison belongs to the user’s own history because behavior that is ordinary for one person may be highly unusual for another.

The attacker can reproduce what is visible inside the compromised mailbox, but the mailbox does not contain a complete model of the victim’s environment. Infrastructure selected to hide one inconsistency may create another. A realistic internal message may still be preceded by abnormal account access, and a perfectly reproduced invoice may introduce payment details that do not belong to the established supplier relationship. The more convincingly the attacker imitates the artifact, the more important the surrounding context becomes.

Fraud-as-a-service improves impersonation, but it does not change the mechanics of fraud. The defender does not need to prove that AI produced the message. The defender needs a deterministic process that can recognize when the identity, communication, and transaction no longer fit their established history. That same principle becomes more important with zero-days, where the malicious payload may be something the defender has never seen before.

Zero-Days: Detecting What Surrounds the Unknown

We have looked at how fraud-as-a-service uses AI to remove the familiar signs of impersonation and why detection must expand beyond the message itself. We can now apply that same reasoning to the second way attackers are using AI: discovering and exploiting zero-day vulnerabilities. In fraud, AI makes a malicious communication look familiar. With zero-days, AI helps produce an unfamiliar attack that the defender does not yet know how to identify.

AI changes the scale and timing of vulnerability discovery. It can help attackers examine more software, analyze the differences introduced by a patch, and turn a weakness into a working exploit with less human effort. This creates more potential entry points and reduces the time between discovering a vulnerability and using it against an exposed system.

The traditional zero-day problem remains the same. A defender cannot build a reliable signature for an exploit that has not yet been identified. If detection depends entirely on recognizing the payload, an unknown payload has an obvious advantage. The inability to identify the exploit itself, however, does not make the entire attack invisible.

The payload must still be delivered through an interaction the target can process. That interaction has a source, a structure, and a relationship to the way the application normally communicates. An attacker may need to present content in an unusual form to reach the vulnerable code. The request may differ in size, encoding, or behavior from the requests the application typically receives. These differences do not identify the zero-day, but they can identify that the application is being asked to process something abnormal.

Not every exploit will reveal itself during delivery. A carefully designed payload may arrive through a request that appears consistent with the application’s normal function. In that case, detection moves to the effect of successful exploitation. The system may initiate a connection it has never made before or execute an action that does not belong to its established behavior. The exploit was unknown, but the resulting change is still measurable.

This is the same defensive principle we applied to fraud-as-a-service. When the malicious element cannot be recognized directly, detection must evaluate the behavior surrounding it. AI may help an attacker discover more zero-days and exploit them sooner, but it does not remove the need to deliver the payload or the changes created when the payload succeeds.

The zero-day itself is therefore only one part of the detection problem. The larger task is to establish how the application normally receives information and behaves, then recognize when those patterns change. That brings both fraud and zero-day exploitation to the same conclusion: AI increases the quality and scale of the attack, while effective defense still depends on deterministic processes that identify meaningful abnormalities.

Better Attacks Require Better Fundamentals

We have looked at two ways AI is improving offensive operations. Fraud-as-a-service makes impersonation more convincing by removing the inconsistencies people once used to recognize a fraudulent message. AI-assisted vulnerability discovery increases the number of technical entry points and reduces the time between finding a weakness and exploiting it. These improvements affect different targets, but they lead to the same question about whether AI has changed the way organizations must defend themselves.

The answer is less dramatic than the hype surrounding the compressed kill chain. AI improves the quality, scale, and speed of an attack, but it does not remove the activity required to carry that attack into an environment. A fraudulent message still depends on an identity, infrastructure, and delivery process. A zero-day payload still has to reach a vulnerable system and produce an effect. The malicious element may become harder to recognize directly, but the behavior surrounding it remains available for analysis.

AI can reproduce the information available to it. It can imitate the language in a compromised mailbox, the appearance of an invoice, or the structure of a public-facing service. What it cannot perfectly reproduce is the context it does not possess. It does not know how a particular person normally uses technology, how an application usually communicates, or how information moves through the organization.

Even when an attacker gains access to part of that history, the view remains incomplete. Learning more requires additional observation and interaction, which create more activity for the defender to evaluate. The attacker can improve the imitation, but every difference between what it knows and how the environment actually operates creates the possibility of detection.

Organizations do not need to invent an entirely new form of security to address this change. They need to perform the fundamentals with greater depth and at greater scale. Behavioral analytics must establish how identities, applications, and communications normally operate so that meaningful changes can be recognized. AI can help defenders process that evidence, but it should support deterministic security processes that remain explainable and repeatable.

The kill chain has not disappeared. The time and labor between its stages have been reduced. AI can imitate what it knows, but it cannot perfectly imitate what it cannot see. The job of defense is to understand the organization’s own behavior well enough to recognize the difference.