The attacker stopped being a person
In November 2025, Anthropic disrupted the first documented espionage campaign run by software rather than by people. A state-linked group pointed an agent at roughly thirty organisations: technology companies, banks, chemical manufacturers, government agencies.
The agent did the reconnaissance. It found the vulnerabilities, wrote the exploit code, harvested the credentials, sorted what it took and moved on. Its operators stepped in for perhaps ten to twenty percent of the work, mostly to approve the next move. The rest ran unattended.
That was the proof it could be done. It is now simply how it is done. Roughly one in eight reported AI-related breaches already involves an agent acting without a person directing it.
Every assumption underneath your security programme was written for an attacker who has to sleep, gets bored, and can only be in one place at a time. None of those are true any more.