AI-Powered Cyberattacks Just Got Smarter. Agentic AI Is Why.

Author: Ami DePierro | Co-Founder, 2 Dog DigitalĀ 

Ami DePierro is Co-Founder of 2 Dog Digital and a former US Marine Intelligence Analyst who brings analytical precision to cybersecurity strategy for small and mid-sized businesses across the Raleigh/Triangle area. Digit is the voice. Ami is the author.

Table of Contents
    Add a header to begin generating the table of contents

    The attack started before anyone sat down at a keyboard. An autonomous AI agent found your CFO’s name on LinkedIn, pulled your email format from a breach database, cross-referenced an overdue invoice from a public court filing, and sent a personalized wire transfer request before your IT team finished their morning coffee. Nobody picked your business. The AI did. It ran while the attacker slept. That is what AI-powered cyberattacks look like right now. Not a future problem. This week’s problem.

    There is a version of AI-powered cyberattacks most people are still thinking about. A hacker uses AI to write a better phishing email. Faster, more convincing, still requires someone to aim it. That version exists. It is also not the one you need to worry about most anymore.

    Agentic AI is different in kind. These are AI systems that receive a goal and pursue it through a sequence of decisions without a human directing each step. Security researchers started documenting offensive use of these capabilities in late 2023. By 2025, threat intelligence firms including CrowdStrike and Mandiant are tracking active campaigns where AI agents handle reconnaissance, generate targeted content, adapt to failed attempts, and move laterally through networks. Autonomously. From start to finish.

    The IBM Cost of a Data Breach Report 2025 put the average breach cost at $4.88 million globally. SMBs experienced four times more confirmed breaches than large organizations in 2025, according to the Verizon Data Breach Investigations Report

    This post covers what agentic AI actually does during an attack, who it targets first, and what a working defense looks like. Specific steps. Not ‘consider your posture.’

    1. What Agentic AI Is and Why This Is Different

    Most people hear ‘AI cyberattack’ and picture a smarter phishing email. That is still a real problem. It is also the old problem. The new problem is an AI system that does not stop at writing the email.

    Agentic AI refers to systems that pursue goals through multiple steps without human approval at each stage. You give it an objective – ‘compromise this organization’s email environment’ -and it plans, executes, monitors results, and adjusts. Without someone watching. The attacker reviews the outcome. The AI handles the work.

    What that removes is the bottleneck. Historically, attackers had to choose between volume and quality. Broad phishing campaigns were obvious because they were generic. Targeted attacks were convincing but slow. One person, one well-researched target, a lot of manual effort. Agentic AI collapses that tradeoff. Hundreds of highly personalized autonomous cyberattacks can run simultaneously, each one drawing on scraped LinkedIn data, public filings, and breach databases to look exactly like a real email from a real person in a real situation.

    Palo Alto Networks released research in early 2025 documenting AI agents automating credential theft at a scale that previously required a large, organized criminal operation. Small targets are being hit by attacks that used to require targeting a Fortune 500.

    🐾  Digit’s Rule 8: Urgency in an email is a weapon. Slow down.

    The agentic AI attack chain is specifically built to manufacture urgency. It knows your CFO’s name. It knows the invoice is overdue because it found that in a public court filing. It writes an email that reads like it came from a real person who needs something by 4 p.m. The urgency is not incidental. The urgency is the attack.

    2. How AI-Powered Cyberattacks Actually Run

    Here is the chain. It moves faster than most IT teams respond to a ticket.

    Stage 1: Reconnaissance

    The AI agent scrapes public data. LinkedIn, company websites, press releases, breach databases, social media. It builds a full target profile. Names, roles, vendors, software stack if it can infer it. This used to take a skilled human analyst hours. It now takes the agent minutes.

    Stage 2: Attack Vector Selection

    Based on the profile, the agent picks the most likely approach. For most SMBs, that is business email compromise or AI-driven phishing attacks, because those exploit people, not technology. Your firewall has no say in whether an employee believes a message is real.

    Stage 3: Content Generation and Delivery

    Personalized message. Correct tone. Accurate context. Sent from a spoofed or lookalike domain. The quality is not ‘good enough to fool someone who is not paying attention.’ The quality is indistinguishable from an internal email to anyone moving at normal business speed.

    Stage 4: Adaptation

    If the first attempt fails, the agent tries a different vector. Different sender. Different context. Different emotional hook. It does not get discouraged. It does not get tired. It iterates on your people until something lands.

    Stage 5: Execution

    Credential theft, wire transfer fraud, ransomware deployment, or data exfiltration depending on the objective. By the time the attacker reviews results, the work is done.

    The FBI’s Internet Crime Complaint Center reported $2.9 billion in losses from business email compromise in 2023. Autonomous cyberattacks are pushing that number in one direction.

    Old Attack Model Agentic AI Attack Model
    Human picks target manually AI scans thousands of targets simultaneously
    Generic phishing templates Personalized to the individual recipient
    Manual follow-through required Autonomous from reconnaissance to execution
    Volume limited by human capacity Volume limited only by compute
    Sophisticated attacks need a large criminal org One operator can run enterprise-scale campaigns

    3. Who Agentic AI Goes After First

    Here is the part that does not make it into enough budget conversations: agentic AI does not prioritize large targets. It prioritizes easy ones.

    Large enterprises have security operations centers, 24/7 threat detection, incident response retainers, and mature access control frameworks. Attacking one of those takes real effort. An SMB with no security monitoring, reused passwords, and an ex-employee’s login still active from eight months ago? That takes a nudge.

    🐾 Digit’sRule 6: Your IT team can’t protect a door you didn’t tell them existed.

    Shadow IT is a force multiplier here. If your team is running a SaaS tool that nobody in IT knows about, that tool has credentials attached to it. Those credentials are either secured or they are not. IT does not know to check. The AI agent finds the exposure in breach databases before you do.

    Every IT manager in the room already knows this is a problem. The question is whether anyone with a budget agrees before the incident report lands.

    The attack surface for a 25-person company is not meaningfully smaller than a 2,500-person company. You have email. You have cloud storage. You have a banking relationship. You have vendor connections. You have employees who are human and will occasionally click something they should not. Cybercriminals using AI can now run targeted, research-backed attacks against any business on their list. The limiting factor used to be the attacker’s time. It is not anymore.

    Sectors seeing elevated AI cyber threats right now include professional services, healthcare, financial services, and regional municipalities. Businesses in the Raleigh/Triangle area and across North Carolina are not in a protected geography. Agentic AI does not know your zip code.

    4. What Defending Against AI Cyber Threats Actually Looks Like

    No single control defeats an autonomous cyberattack. Anyone who tells you otherwise is selling something specific. What you need is a set of controls that makes your environment expensive enough to attack that the agent moves to the next target. You do not need to be impenetrable. You need to be harder than the business two doors down. Most SMBs are not there yet.

    Multi-Factor Authentication on Every Account. No Exceptions.

    If an agent steals a password and cannot use it without a second factor, the credential is dead. MFA is the most proven single control against credential theft. It is not complicated to implement. The reason it is not universally deployed is inertia, not cost. Fix the inertia. You have been meaning to do this for six months. It takes forty minutes. Do it today.

    🐾Digit’s Rule 5: Multi-factor authentication is not optional. Neither is locking the front door

    Security Awareness Training That Actually Covers AI-Driven Phishing Attacks

    Your employees are the attack surface that agentic AI is optimized to exploit. A wire transfer request that reads exactly like something your CFO would send is not a technology problem. It is a training problem. Phishing simulations, real examples, regular reinforcement. The NIST Cybersecurity Framework lists this as a core component. Follow that guidance.

    Threat Detection and Security Monitoring

    You need to know when something unusual is happening in your environment. That means log collection, real alerts, and someone who gets paged when an account logs in from an unusual location at 3 a.m. If you do not have that, you will find out about the breach the same way most SMBs do: the bank calls you.

    Access Control Audit. Run It Now.

    Who has access to what. Include former employees. Especially former employees.

    🐾  Digit’s Rule 12: An ex-employee’s login still works until someone makes it stop working.

    A Written Incident Response Plan That Has Actually Been Tested

    Not a 40-page document nobody reads. A single page with names, numbers, and steps. Who do you call, in what order, and what do you do in the first thirty minutes. CISA provides free incident response planning resources. Use them. Then run a tabletop exercise so you know whether the plan works before you need it to.

    Autonomous cyberattacks adapt in real time. A static, untested security posture does not keep up. The defenses need to be monitored and updated. Set-it-and-forget-it is not a security strategy. It is a schedule for a very bad quarter.

    5. Conclusion: The Threat Moved. Your Response Needs To Also.

    AI-powered cyberattacks are not a future problem. They are running right now, autonomously, targeting businesses that have not updated their threat model in the last two years. The attack changed. The volume changed. The personalization changed. The defenses that need to be in place have not fundamentally changed, but a lot of businesses still have not put them there.

    The short version:

    • Agentic AI removes the human bottleneck from attacks. Volume and personalization now run together. Your employees will receive targeted, research-backed phishing attempts at a scale that was not operationally possible two years ago.
    • Small businesses are the preferred target. Not overlooked. Preferred. Easy doors get kicked in first.
    • MFA, security monitoring, access control audits, and awareness training are not advanced controls. They are the baseline. Most businesses that get hit did not have them in place.
    • Autonomous cyberattacks adapt. Your defenses need to be monitored and updated. Tested backups, reviewed access lists, trained employees. These degrade if nobody tends to them.

    Digit has watched too many post-breach conversations where every gap that contributed to the breach was known before it happened. Known, noted, and deferred because something else felt more urgent. The average ransomware recovery costs more than most SMBs clear in a quarter. That is not a scare tactic. That is what the FBI Cyber Division keeps publishing, year after year.

    If any of this sounds like your current setup, 2 Dog Digital does a no-charge vulnerability assessment. You will learn something either way. The time to do it is before the incident report, not the morning after.

    Ready to find out where you actually stand? Contact 2 Dog Digital for a free cybersecurity assessment. We will tell you what you have, what you are missing, and what it takes to get there.

    2 Dog Digital — Raleigh, NCĀ  |Ā  2dogdigital.com

    Frequently Asked Questions

    Agentic AI pursues a goal through multiple steps without human direction at each stage. Regular AI responds to a prompt. Agentic AI executes a plan, monitors results, and adjusts without anyone watching. In a cyberattack, that means reconnaissance, personalized phishing, credential theft, and lateral movement can all run on autopilot.

    They set an objective and let the AI handle the work. The agent researches the target, generates personalized attack content, delivers it, monitors what failed, tries a different angle, and reports back when the job is done. What used to require a skilled human operator now runs at scale without one.

    Largely, yes. A human attacker sets the goal and reviews results. The AI agent handles execution. This removes the bottleneck that used to cap how many targets an attacker could pursue simultaneously. The attacker can sleep. The AI does not.

    Yes. SMBs in the Raleigh/Triangle area are not in a protected geography. Agentic AI does not target by size; it targets by vulnerability. A business with no security monitoring, weak access controls, and untrained staff is a high-priority target regardless of what it earns. Easy doors get kicked in first.

    Start with MFA on every account, a current access control audit including former employees, endpoint monitoring with real alerting, and security awareness training that covers AI-driven phishing. These are not advanced controls. They are the baseline. The businesses that get hit usually knew these gaps existed.