The Threat Is Not AI. It’s the Economics.

Cyber Risk

Blog Post AI in the hands of threat actors

Every week, AI and cybersecurity make headlines together. Most of what you read is either hype or panic. What actually matters for your risk posture is something quieter and far more consequential.

At Citalid, we track threat actor behavior across sectors, geographies, and attack typologies. When we decided to publish our February 2026 report “AI in the Hands of Cyber Threat Actors“, written by our Head of CTI Operations, Quentin Siennicka, the goal was not to add to the noise but to replace it with signal.

What Quentin Siennicka found, after synthesizing data from dozens of documented intrusion sets and adversary campaigns, was this: AI doesn’t change what attackers want to achieve. It changes how cheaply, how quickly, and how credibly they can pursue those objectives.

That single insight has significant implications for how organizations should think about risk and where Citalid’s proprietary CTI data leads us to focus.

Not Rupture. Amplification.

The public discourse on AI-enabled threats tends to oscillate between two poles: dismissal (“nothing has really changed”) and catastrophism (“AI will automate cyberattacks”). Both miss what is actually happening on the ground.

Explore how Citalid maps and tracks the threat actors targeting your sector

EXPLORE THREAT EXPOSURE

The more precise framing, supported by our own threat intelligence and corroborated by reporting from Google’s Threat Intelligence Group, Microsoft, and CrowdStrike, is amplification. AI is not creating a new category of adversary. It is making existing adversaries faster, more fluent, and more scalable.

Speed

Drafting lures, translating them, summarizing a target’s public footprint — tasks that once took time now take minutes. Attack preparation compresses.

Credibility

The traditional weak signals — grammar errors, awkward phrasing, cultural mismatches — are eroding. AI-polished content is harder to dismiss on first contact.

Scale

More actors can now produce higher-quality outputs, more often, with less effort. The floor lowers. Volume grows. The threat surface widens.

The consequence for risk professionals is not a new threat taxonomy; it is a recalibration of probability. The same attack types you’ve been tracking are now more likely to succeed, more likely to reach your organization, and harder to catch before impact.

What we are seeing is not some spectacular new AI-native operation. It is the fact that more actors can now produce higher-quality outputs, more often, with less effort.

What Our Data Actually Shows

One of the most cited statistics in AI-threat discourse is Mandiant’s finding that AI-related capability acquisition appeared in only 0.2% of their 2024 investigations. This figure is frequently used to argue the threat is overblown.

Our read is different. Low observability is not the same as low relevance. In a number of documented cases including Chinese-aligned intrusion set UTA0388, tracked by Volexity, the signal of AI use didn’t come from a clean technical marker. It came from behavioral inconsistency: multilingual campaigns running simultaneously across English, German, French, Chinese, and Japanese, with fluency that would historically have required dedicated human linguistic capacity.

The question the report asks is not “how often do we see AI?” It is: “what does the AI make possible that wasn’t operationally viable before?” For UTA0388, the answer was geographic and linguistic reach, achieved at scale, without the traditional bottleneck of recruiting native speakers.

This is how Citalid approaches AI-threat intelligence: not by counting AI indicators, but by understanding what operational effects AI enables and mapping those effects to your specific sector and risk profile.

The Risk Is in the Process, Not the Technology

A consistent theme across the cases we analyzed is that the most consequential AI-enabled attacks did not succeed because of technological sophistication. They succeeded because they exploited a process gap.

The Hong Kong case — in which a finance employee was persuaded during a video call to authorize HK$200 million in transfers to a state-linked threat actor — is the clearest example. There was no malware. No account compromise. Just a deepfake video call, a high-trust workflow, and no second-confirmation process designed for that scenario.

In social engineering scenarios where AI raises the credibility threshold, defenders who focus exclusively on detecting the AI signal will consistently arrive too late. The more durable defense is process architecture: controls that activate regardless of how convincing the interaction appears. AI exploited a process gap, not a perception gap.

This framing — process over perception — runs through our strategic CTI recommendations. It is also how we help clients move from threat awareness to actionable risk posture: by translating observable adversary behavior into organizational exposure, and organizational exposure into specific control priorities.

From Intelligence to Risk Quantification

Most cyber risk quantification models work from historical loss data and generic threat assumptions. At Citalid, CTI is natively embedded in our risk models because attack probability isn’t static, and context changes everything. Who is targeting your sector, with what techniques, and with what operational constraints: that’s what should drive your risk numbers.

The near-term picture is clear from our data: the primary pressure will be on frequency before severity. More phishing, more social engineering, more fraud at scale; driven by the accessibility of AI-assisted content generation and lure refinement. For insurers and risk managers, probability assumptions that haven’t been revisited in the last 12 months are likely now understated.

The emerging picture (12 to 18 months out) involves something more structural: AI systems themselves becoming targets. Prompt injection vulnerabilities like EchoLeak in Microsoft 365 Copilot, model poisoning attacks requiring as few as 250 malicious documents, shadow AI creating unmapped exposure across enterprise environments. These are not theoretical risks. They are already documented. Governance is simply lagging behind.

Conclusion

AI does not make cyber risk unmanageable.

It does make a reactive approach more expensive. Organizations that wait for a clean AI indicator such as a detectable deepfake, an obvious lure, a flagged anomaly will increasingly find themselves responding to something that already worked.

The more useful posture is a familiar one: understand who is likely to target you, what they are trying to achieve, and where your actual exposure sits. AI changes the speed and accessibility of attacks. It does not change the logic of risk management. Knowing where to look, and where to concentrate your cybersecurity effort, remains the most durable advantage a security team can have.

More content

Related content