Security & Risk7 minNewsroom

Unit 42 Documents Ransomware Attack Conducted by AI Agents: 10 Hours for What Used to Take Two Weeks

Sala escura de SOC com relatório impresso de 80 páginas sobre teclado iluminado por luminária quente, ticket vermelho de incidente ao lado.

A report by Palo Alto Networks published on September 2 describes an invasion in which tactical execution was delegated to autonomous agents, including an 80-page report left for the victim.

Unit 42, the incident response arm of Palo Alto Networks, published the Global Incident Response Report 2026 on September 2, featuring a case that shifts the timing of the conversation about corporate cyber risk. A human ransomware operator, the sole actor in the chain, compressed what the firm estimates would typically take about two weeks for a traditional human team into less than 10 hours. The difference was not a novel zero-day exploit or elite tradecraft: it was the delegation of tactical execution to autonomous agents supported by cutting-edge models.


The reconstruction of the incident is the most uncomfortable part of the report. The attacker entered through the public surface by compromising an exposed API endpoint. Once inside, an automated reconnaissance agent was triggered, mapping the internal microservices. Sub-agents scraped code repositories for hard-coded tokens, captured service passwords, accessed the secret management system, and obtained administrative credentials with root rights. In the end, the adversary delivered to the company an 80-page dossier containing the security audit that the attack itself produced as a byproduct.


The excerpt that has circulated most among response teams is the reading of the incident responders from Unit 42: 'what made the attack stand out was the operational efficiency assisted by AI, without the need for a novel zero-day exploit or super elite tradecraft', because 'the attacker delegated tactical execution to AI agents that monitored, assessed, acted, and replanned in real-time, increasing speed throughout the entire attack chain.' This statement is important because it shifts the axis of defense: the frontier is no longer the sophistication of the adversary, but the speed with which they chain ordinary steps.


The Numbers Framing the Case


The report synthesizes over 750 incident response engagements across more than 50 countries between October 2024 and September 2025. Within this dataset, the standout segment is the top 25% of the fastest: in 2025, these intruders reached exfiltration in 72 minutes, compared to 285 minutes the previous year. The 74% drop in exfiltration time for leading intrusions is the aggregated data that Unit 42 uses to support its thesis that AI is compressing the attack cycle, and this context is what gives meaning to this emblematic incident.


Where Time Compression Hurts Most


The speed gain has asymmetrical impact by geography. In U.S. banks, the average escalation time between detection and the activation of the third-party SOC is measured in minutes, and the OCC regulatory playbook mandates notification within 36 hours: a whole chain executed in 72 minutes undermines the very premise of the playbook. In Germany and the rest of the European Union, NIS2 imposes initial notification within 24 hours for essential entities, and the BSI had already been signaling to banks that 'agentic threat activity' would become part of the mandatory reporting indicators. An incident that ends in exfiltration before lunchtime leaves no room for the internal approval process that most European banks still practice.


Offshore consulting centers add an extra layer. PwC's Acceleration Centers in India and the Philippines, Capgemini hubs in Poland, and TCS centers serving global clients operate in shifts with handoff, creating known windows of latency. If the attacker fits their chain into the gap between shifts, the response arrives late by organizational design, not tool failure.


What Unit 42 Does Not Say and Matters


The report avoids naming the cutting-edge model used by the attacker, even after having spoken with the incident negotiators. This is a defensible editorial omission (to avoid negative marketing for a specific vendor) but problematic for the CISO: without the name, there’s no way to calibrate the commercial response. OpenAI, by classifying Astra as 'Critical' also on September 2, chose the opposite, to publish enough detail for institutional buyers to decide whether to accept or reject the tool. The absence of standardization among vendors and across response reports is the next front in regulatory disputes.


Where the Reading Needs to Be Skeptical


Part of the productivity leap observed by Unit 42 may be a sampling effect: incidents involving agentic AI tend to be precisely those that call responders into the hall and become case studies, while slower attacks fall outside the year-end report. It is prudent to await a cross-reference with Verizon’s DBIR and Mandiant’s M-Trends before treating '10 hours' as the new baseline. Still, the direction of the signal is consistent with two years of aggregated data, and no board can afford to wait for more evidence to begin adjusting response SLAs.

The week's analysis, by email

One weekly edition with what matters to people who decide. No ads, no sponsorship.

One-click cancellation, at any time.

Security & Risk